Legal
Privacy policy
Learn what information Golden Hour collects, how it’s used and shared, and how to manage or request deletion of your data.
Effective 26 September 2026
1. Who is responsible
The operator listed under Contact operates Golden Hour. An event host decides when to share the event QR code or link, whether a shared gallery is available, and how long event media is scheduled to be kept. The host may have its own privacy duties to event participants.
2. Data we collect
We collect only data used to operate an account, event, gallery, or requested support process:
- Account data: name, email address, optional phone number, password hash, and optional Google account ID.
- Security data: session identifiers, one-time-code records, IP address, browser or device information, and sign-in history.
- Event data: event name, date, venue, settings, participant details, and join activity.
- Media: uploaded photos, captions, dimensions, file type, size, capture time when available, and archived metadata from legacy uploads, which can include an original filename, video, or audio details.
- Event cover: a host-selected image shown on the event join page.
- Face-matching data, after explicit participant consent: guided selfie images, detected face regions, quality information, and numerical face templates used to compare event photographs.
- Activity data: uploads, matching decisions, reports, downloads, delivery status, consent choices, deletion requests, and audit records.
- Purchase and support data: order, invoice, payment-status, refund, complaint, and correspondence details supplied outside or through the service.
Please do not upload data that is unnecessary for the event. Golden Hour does not ask for a date of birth, government identifier, contacts list, or advertising profile.
3. Why we use data
- To create accounts, authenticate users, prevent abuse, and keep the service secure.
- To create and administer events, receive uploads, process media, and build private galleries.
- To match photographs using facial recognition, with manual correction when needed.
- To deliver gallery links, respond to reports and support requests, process purchases, and handle refunds.
- To comply with law, enforce the Terms, investigate incidents, and protect users and the service.
4. Face matching
Every event uses facial recognition to find enrolled participants. The service compares a participant's face template with faces detected in event photographs. Results can be wrong, so participants and the event host can review, confirm, reject, or report matches.
Processing can create a numerical embedding for each detectable face in an uploaded photograph so it can be compared with enrolled templates. This can include a bystander, child, or other depicted person who has no account or template. Those detected-face records remain attached to the photograph until the media is reprocessed or deleted.
Face enrolment is required before opening the participant experience. The enrolment screen asks for express consent before selfies are uploaded. A participant can withdraw face consent and request deletion from the event privacy centre, but must enrol again to reopen participant surfaces. A ready account-level template may be reused only after consent is granted for that event. Golden Hour does not use participant media to train a general-purpose AI model.
5. Children
A person under 18 must not create or manage an account independently. A parent or legal guardian must create and manage the account, approve participation, and decide whether any photo or face-matching data is provided. Event hosts must obtain any additional permission required for photographing children or sharing event access. Contact us immediately if a child created an account without guardian involvement.
6. Who receives data
- The account that hosts the event.
- Other participants in the same event when its host shares the event gallery. The host then makes every photo in the event visible to everyone who joins, including photos participants add, except photos the host hides or that are removed after a report.
- Microsoft Azure for hosting, PostgreSQL, private media storage, logs, and email delivery.
- Google only when Google sign-in is enabled and deliberately used.
- Razorpay for one-time event-plan payments. We send the initiating account’s name and email, event name and identifier, plan, amount and order reference. Razorpay handles payment credentials; we retain payment status and references.
- Professional advisers, regulators, law enforcement, or a buyer of the business where lawfully required.
We do not sell personal data, run behavioural advertising, or provide event media to data brokers. Service providers may process data in other locations under their contractual and legal safeguards. The current primary application, database, and media-storage deployment is configured in Microsoft Azure's Central India region.
7. Cookies, local storage, and analytics
Golden Hour currently uses necessary authentication cookies, a short-lived sign-in state cookie when Google sign-in is used, local storage for theme preference, and temporary session storage for an unfinished event draft or photo upload. The current product contains no advertising cookies, analytics tracker, tracking pixel, or third-party embedded content. See the cookie policy.
8. Retention
For completed or archived events, original photos and generated copies older than the host's retention period are scheduled for deletion. This schedule does not remove all account, selfie or face-template data. The automated event-media schedule does not currently remove every consent, transaction, security, complaint, notification, or audit record. Those records may therefore have different retention periods while they remain necessary for the service, dispute handling, fraud prevention, backup integrity, or law. Short-lived sign-in codes expire quickly, although security records may be retained longer.
The privacy centres show available deletion controls. Deletion from backups and operational logs may occur on a later protected rotation. We will not keep personal data merely because it may be useful someday.
9. Your choices and rights
Subject to applicable law, a person can:
- Review and correct account or participant information.
- Turn off notification channels.
- Report a photo in a shared event gallery. A photo reported for missing consent or inappropriate content is hidden from every gallery straight away while the host reviews it.
- Withdraw face-matching consent and delete a face template.
- Request access to or deletion of personal data and raise a grievance.
- Nominate another person to exercise applicable data rights where the law permits.
Use the in-product privacy controls or contact the Grievance Officer. Include the account email and event name, but never send a password or one-time code. We aim to acknowledge grievances within 48 hours and resolve them within one month unless a shorter period applies.
10. Security
We use access controls, hashed credentials and tokens, private storage, time-limited media links, audit records, and encrypted network connections. No system is completely secure. Please report suspected unauthorized access to the Grievance Officer without including sensitive credentials.
11. Changes to this policy
We may update this policy when the product or law changes. Material changes will be highlighted before they apply, and fresh consent will be requested where required.
12. Contact
[LEGAL BUSINESS OR PROPRIETOR NAME]Trading as Golden Hour
[FULL POSTAL ADDRESS, INDIA]
Customer support: [CUSTOMER SUPPORT EMAIL]
Grievance Officer: [GRIEVANCE OFFICER NAME]
Email: [GRIEVANCE EMAIL]
Phone: [GRIEVANCE PHONE NUMBER]