Last updated: 8 August 2026
This is a plain-language starting template for POPIA (Protection of Personal Information Act) compliance, not a substitute for advice from a qualified attorney. Have it reviewed before relying on it commercially.
From you (the event organiser): your name, email, phone number, and payment confirmation from our payment processor (we never see your card details).
From your guests: whatever they choose to submit through your event's upload, voice note or guestbook forms — typically a name, optionally an email, and the photo/video/audio/message content itself, along with the IP address the submission came from (used only for abuse prevention).
To run the service you've signed up for: creating and hosting your event, moderating and displaying guest submissions the way you've configured, processing payment, sending you transactional emails (receipts, password resets, reminders), and keeping the platform secure.
When a guest submits a photo, video, voice note or message, they are shown what will happen to it (moderated and potentially displayed in your gallery and slideshow) before submitting. As the event organiser, you control moderation — nothing guests submit is published without your approval unless you've turned moderation off.
Your event's guest content is kept for as long as your event is active, plus any retention period you configure in your event's Privacy & Data settings (measured from when your gallery closes). You can shorten this at any time, or request immediate deletion — a short grace window applies so an accidental request can be cancelled before anything is removed. Once deletion runs, guest photos, videos, voice notes, messages and their associated files are permanently removed from our storage.
If a guest wants to exercise these rights directly, they should contact the event organiser, who controls the data.
We share the minimum necessary data with: our payment processor (PayFast, for payment only), our email delivery provider (to send transactional email), and our hosting/storage infrastructure. We do not sell personal information, and we do not share guest content with anyone outside your own event's organisers.
Passwords are hashed, not stored in plain text. We support optional two-factor authentication, lock accounts after repeated failed logins, and log security-relevant events. Payment card details never touch our servers.
We use a single essential session cookie to keep you logged in. We don't use tracking or advertising cookies.
Questions about this policy, or a request relating to your personal information, can be sent via your account's support contact. You also have the right to lodge a complaint with South Africa's Information Regulator if you believe your information has been mishandled.