PRIVACY
Privacy Notice
What we store about hosts, events, guests and photos, and why.
Controller and roles
OurFilm is operated by Buják László e.v., registered office 1039 Budapest, Juhász Gyula utca 2., 8. em. 75., registration number 61847981 (Egyéni Vállalkozók Nyilvántartása (EVNY)), tax number 91762351-1-41. Contact: support@ourfilm.app.
OurFilm is controller for host accounts, contracts, service security, support and its own analytics. Stripe and Link are independent controllers for payment, tax, invoicing, fraud prevention and transaction support. Where data-protection law applies to an event, the host normally decides why event photos are used and OurFilm stores and displays that content on the host’s behalf.
Data we handle
For hosts: email address, user and event identifiers, event name and settings, login and session data. For guests: display name, a random session identifier, shot usage and identifiers connecting the guest to the event and photos. Guests do not need an account or email address.
For photos: the processed JPEG, capture time, file and image dimensions, format and processing state. Processing removes EXIF metadata, including GPS location. For payments: Stripe session and transaction identifiers, event association, amount, currency and status; OurFilm never receives card numbers.
For usage and error diagnostics: the result, error category, timestamp and duration of predefined actions such as opening the guest page, joining, opening the camera, pressing the shutter, processing and uploading a photo; network and page-visibility state; file and image size; format indicators; the technical class and code location of errors; and random event and capture identifiers. PostHog may attach default technical data such as browser and operating-system type and version, device type, screen and viewport size, and a masked page path without its query. We do not send names, email addresses, event names, event links, error messages, image files or photo content to PostHog. A network address may be processed technically during transmission and cookieless measurement, but we do not use it for location tracking or persistent user identification.
Purposes and legal bases
Host accounts, events and orders are processed to perform the contract (GDPR Art. 6(1)(b)); records required by tax, accounting or law are processed under legal obligations (Art. 6(1)(c)). Security, session protection, quota enforcement, troubleshooting, abuse prevention, preventing lost uploads and improving the product, including Vercel’s cookie-free traffic measurement and PostHog’s technical events, rely on legitimate interests (Art. 6(1)(f)). We do not use this data for advertising, personalised marketing, profiling or automated decision-making. You may object to legitimate-interest analytics and can also block it with browser or network filtering.
The host is responsible for an appropriate legal basis and event notice for photos and people shown in them where applicable. OurFilm does not use event photos for advertising, facial recognition or profiling.
Access and sharing
Event links contain a long random identifier, event pages are not indexed, and which photos are shown is decided server-side. Photo files sit at unguessable, unlistable addresses that do not expire, so anyone who obtains a photo’s exact address can open it later. Anyone can forward a link. The host can access, download and hide every photo. Guests see revealed photos only where the host permits it. Authorised personnel access content only where needed for operations, security or a report.
We use Supabase for database and file storage, Vercel for hosting and cookie-free analytics, PostHog, Inc. for cookie-free product analytics and error diagnostics, Resend for login, legal and album-ready emails, and Stripe Payments Europe, Limited/Link, LLC for payment on English events. Hungarian events are sold directly by OurFilm: Stripe processes the payment and Billingo Technologies Zrt. issues the invoice, which is also reported to the Hungarian tax authority as the law requires. PostHog project data is stored in Frankfurt, Germany. PostHog, Inc. and some of its subprocessors may perform support, security or network processing outside the EEA. Providers may process data outside the EEA using an adequacy decision, the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses.
Retention
During the pilot, event data, guest display names, sessions and photos remain until the host deletes the event; there is no automatic expiry. Active copies are deleted with the event, while backup copies expire under provider backup cycles and are not ordinarily restored.
Host account data remains until account deletion; claims-related records remain for the applicable limitation period; OurFilm accounting records are retained for eight years where Hungarian law requires it. Stripe/Link retain their own data under their notices and legal obligations.
Usage and error-diagnostic events stored in PostHog are currently retained for no more than 12 months and may be deleted earlier when they are no longer needed for troubleshooting or product improvement.
Cookies and local storage
Joining sets one strictly necessary, event-specific httpOnly session cookie for up to one year. Supabase Auth uses strictly necessary session cookies for hosts. Before account creation, an event draft stays in the browser’s localStorage for up to seven days. We do not use advertising cookies. Vercel Web Analytics measures aggregate page views without cookies. Our PostHog configuration does not set PostHog cookies or write to browser localStorage or sessionStorage. PostHog nevertheless receives individual technical events from which aggregate reports and error diagnostics are produced, and those events may be pseudonymous data. We do not send image files, photo content, guest display names or email addresses to PostHog.
Your rights
Depending on the processing, you may request access, correction, deletion, restriction or portability, and object to legitimate-interest processing. Send requests to support@ourfilm.app; we normally respond within one month and may ask for the event link or exact photo so we can identify the data without collecting unnecessary information.
For a photo of you, contacting the host is often the fastest route. You may also contact us. You can complain to your local EEA supervisory authority or the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), and seek a judicial remedy. Requests concerning Stripe or Link’s independent processing may also need to be sent directly to them.
Security, children and changes
We use HTTPS, server-side authorisation and database access controls to decide which photos are shown; photo files are stored at unguessable, unlistable addresses. Raw guest session identifiers remain in httpOnly cookies and only hashes are stored in the database. We assess and document personal-data incidents and notify authorities or affected people where the GDPR requires it.
Hosts must be adults. Photos may include children; hosts and photographers should take particular care, and a parent or guardian may request that a photo be hidden or removed. Material changes are published here with a new update date and, where appropriate, notified to existing hosts.
Last updated: 5 September 2026