Privacy Policy
Last updated: 28 July 2026
This Privacy Policy explains how SendFrame, operated by Gunnar Selm, Elisenstr. 8, 86159 Augsburg, Germany("we", "us"), collects and uses data when you create an account, run an event, or view a shared stream as a guest. Contact: hello@sendframe.io.
1. What we collect
- Account data: email address and authentication data (via Supabase Auth, including Google OAuth if you choose it).
- Event data: event name, settings (access mode, watermark, curation preference), and uploaded photos.
- Guest data: if the event organizer enables email capture, a guest's email address is collected before they can download a photo. Guests otherwise interact with a stream without creating an account.
- Billing data: payment and billing details are collected and processed directly by Paddle, our merchant of record — we do not receive or store card numbers. We receive transaction confirmations and the resulting credit balance.
- Technical data: standard server logs (IP address, timestamps, request metadata) for security and abuse prevention.
2. Where data is stored
Uploaded photos are stored on our hosting infrastructure (Hostinger, EU). Account and event data is stored via Supabase, in an EU-region project. Payment data is stored by Paddle under its own privacy policy.
3. Automatic deletion
Photos and stream metadata are deleted automatically once a stream's display window expires. This is a core part of the service, not an optional setting — SendFrame is designed to minimize how long event photo data exists.
4. How we use data
- To operate the account, event lifecycle, and live stream you configure.
- To process payments and maintain your credit balance (via Paddle).
- To send transactional email (e.g. account confirmation) via our email provider.
- To detect abuse and keep the service secure.
We do not sell personal data, and we do not use guest or account data for advertising.
5. Sub-processors
- Supabase — authentication and database (EU region).
- Hostinger — application hosting and photo storage (EU).
- Paddle.com Market Ltd — payment processing, billing, tax/VAT, merchant of record.
- Brevo — transactional email delivery.
6. Your rights
If you are in the EU/EEA, you have the right to access, correct, or delete your personal data, and to object to or restrict certain processing, under GDPR. Account data and events can be deleted directly from the dashboard; for any other request, contact hello@sendframe.io.
7. Cookies
We use strictly necessary cookies for authentication (Supabase session) and, on passcode-protected streams, a short-lived session cookie for gate access. We do not use advertising or tracking cookies.
8. Changes
We may update this policy from time to time; the "last updated" date above will reflect that.