Photogala.

Privacy Policy

Last updated: April 5, 2026

1. Overview

This Privacy Policy describes how Photogala ("we," "our," or "us") collects, uses, and protects your personal information when you use our photo sharing and event management platform.

2. Data Controller

The data controller responsible for your personal data is:

Peter Wassermair
Rödham 20
4922 Geiersberg
Austria

Email: [email protected]

VAT ID: ATU77393036

3. Information We Collect

We collect the following types of information:

  • Account information: Email address, name, and password when you create an account
  • Photos and media: Images and videos you upload to our platform
  • Usage data: Information about how you interact with our platform
  • IP addresses and browser information for security and analytics purposes
  • Payment information: Processed securely through Paddle (we do not store payment details)
4. How We Use Your Information

We use your information to:

  • Provide and maintain our photo sharing service
  • Manage your account and authenticate users
  • Provide customer support and respond to inquiries
  • Improve our platform and develop new features
  • Ensure platform security and prevent abuse
  • Generate usage statistics and analytics (anonymized when possible)
5. Information Sharing

We do not sell your personal information. We may share your information in the following circumstances:

  • With other users in events you join (photos and participation data)
  • With service providers who help us operate our platform (cloud storage, payment processing)
  • When required by law or to protect our rights and users
  • In connection with a business transaction (merger, acquisition, etc.)
6. Third-Party Services

We use the following third-party services:

  • Paddle: For payment processing (subject to Paddle's privacy policy)
  • Cloud storage providers: For storing photos and media
  • Analytics services: To understand platform usage and improve our service
  • OpenStreetMap & CARTO: For displaying location-based photo galleries on interactive maps (subject to OpenStreetMap's terms and CARTO's terms)
  • Google reCAPTCHA: We use Google reCAPTCHA to protect against automated attacks during registration, login, and guest event access. This includes background risk checks for suspicious attempts. reCAPTCHA may process your IP address and browser information for bot detection. This data is processed by Google according to their privacy policy (https://policies.google.com/privacy).
7. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure.

8. Data Retention

We retain your personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. You may delete your account and associated data at any time through your account settings.

9. Your Rights

Depending on your location, you may have the following rights:

  • Access to your personal information
  • Correction of inaccurate information
  • Deletion of your personal information
  • Data portability
  • Object to processing of your information

To exercise these rights, please contact us at [email protected]

10. Cookies and Tracking

We use cookies and similar tracking technologies to provide and improve our service. These include essential cookies for authentication, preference cookies for user settings, analytics cookies to understand how our platform is used, and with your consent, marketing cookies from advertising platforms (Google, Meta, TikTok, and Microsoft) for conversion tracking.

11. Advertising and Conversion Tracking

With your consent, we use tracking technologies from advertising platforms to measure the effectiveness of our marketing campaigns and improve our services. This includes:

  • Google Ads (gtag.js): Conversion tracking and enhanced conversions to measure ad performance on Google Search, YouTube, and the Google Display Network. Google may use cookies and process hashed user data (email) for attribution. Subject to Google's Privacy Policy (https://policies.google.com/privacy)
  • Meta (Facebook/Instagram) Pixel and Conversions API: Conversion tracking to measure ad performance on Facebook and Instagram. Meta processes hashed user data (email, IP address, browser information) and may set cookies (_fbp, _fbc) for attribution. Subject to Meta's Privacy Policy (https://www.facebook.com/privacy/policy/)
  • TikTok Pixel and Events API: Conversion tracking to measure ad performance on TikTok. TikTok processes hashed user data (email, IP address, browser information) for attribution. Subject to TikTok's Privacy Policy (https://www.tiktok.com/legal/privacy-policy)
  • Microsoft Advertising (Bing Ads) UET Tag and Conversions API: Conversion tracking to measure ad performance on Bing, Microsoft Edge, and the Microsoft Audience Network. Microsoft may use cookies and process hashed user data (email) for attribution. Subject to Microsoft's Privacy Statement (https://privacy.microsoft.com/privacystatement)

In the European Economic Area (EEA) and United Kingdom, these tracking technologies are only activated after you provide explicit consent via our cookie banner. You can withdraw your consent at any time through the cookie settings. Outside the EEA/UK, tracking may be active by default in accordance with local laws, and you can opt out at any time.

12. Children's Privacy

Our service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will delete such information promptly.

13. International Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

15. US State Privacy Rights

If you are a resident of California or another US state with applicable privacy legislation, you may have the following additional rights regarding your personal information:

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources, our purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of personal information we have collected from you, subject to certain legal exceptions.
  • Right to Correct: You may request correction of inaccurate personal information we maintain about you.
  • Right to Opt-Out: You may opt out of the "sale" or "sharing" of your personal information, if applicable. We do not sell personal information in the traditional sense, but certain data sharing for advertising purposes may constitute a "sale" under some state laws.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, please contact us at [email protected]. We will verify your identity before processing your request and respond within the timeframes required by applicable law.

We do not sell personal information as defined under the California Consumer Privacy Act (CCPA). For more information about how we use cookies and tracking technologies, please see our Cookie Settings.

16. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Peter Wassermair
Email: [email protected]
Address: Peter Wassermair, Rödham 20, 4922 Geiersberg, Austria Rödham 20, 4922 Geiersberg, Austria