Privacy

How PicBunch handles data: working draft.

This page maps the product behaviour that a final privacy notice needs to explain. It is deliberately incomplete where the operator and legal decisions have not been confirmed.

Data the product currently handles

  • Host account details and event settings.
  • Guest display names when entered, uploaded photos, and the metadata needed to receive and show them.
  • Technical records needed to secure, operate, and diagnose the service.

Event access and sharing

Anyone with an event link can reach that event, and a host may add a passcode. Links can be forwarded. The final notice and in-product copy must explain this clearly without describing an event as secret or access-proof.

Facts still required

  • The legal operator, business address, privacy contact, and applicable jurisdictions.
  • Purposes and legal bases, data locations, service providers, transfer safeguards, and security disclosures.
  • Retention periods, backup expiry, rights-request handling, age rules, and complaint routes.
  • The approved analytics configuration and any consent control required before analytics is enabled.

Marketing-site analytics

The marketing site only loads its configured analytics when the deployment explicitly enables it. That technical switch does not replace a privacy decision or any consent the launch markets require.