Privacy Policy
Last updated: August 23, 2025
This Privacy Policy explains how PhotoSpots collects, uses, and protects personal data — including when you join the waitlist or use our mobile application.
Who is the controller?
The data controller is PhotoSpots (personal project by Paweł Pamuła). For any privacy questions, email pawelpamula003@gmail.com.
What data we collect
- Email address — when you join the waitlist to receive updates.
- Account data (app) — email, username, profile/avatar if you create an account.
- User content — spots you add (location, description, photos). Content may be public in the app.
- Approximate location — only if you choose to include it when creating a spot.
- Technical data — basic usage analytics via PostHog and standard server logs for security.
Why we process your data
- Provide the service (waitlist, account, saving and displaying spots).
- Send product updates if you join the waitlist.
- Maintain security and prevent abuse.
- Improve the product and user experience (aggregated analytics).
Legal bases (GDPR)
- Consent — for waitlist emails and optional analytics where required.
- Contract — processing necessary to provide the app features you request.
- Legitimate interests — security, preventing abuse, product improvement.
Processors & recipients
- Supabase — authentication, database, and storage.
- Cloudinary — hosting and optimization of user photos.
- PostHog — privacy-friendly analytics for website/app usage.
- We do not sell your personal data. Processors act on our behalf under data processing agreements.
Data retention
We keep personal data only as long as needed to provide the service or until you request deletion. Waitlist emails are kept until you unsubscribe or request removal. Account data and user content can be deleted when you delete your account (subject to backup/archival timelines).
Your rights
- Access your data and receive a copy.
- Rectify inaccurate data.
- Delete your data (“right to be forgotten”).
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent at any time (e.g., unsubscribe from emails).
- Lodge a complaint with your supervisory authority.
- To exercise your rights, email pawelpamula003@gmail.com.
International transfers
Some providers may store data outside your country. Where applicable, we rely on appropriate safeguards (e.g., standard contractual clauses).
Security
We use reasonable technical and organizational measures to protect your data. No system is 100% secure, but we work to minimize risk (e.g., access controls, least privilege, encrypted transport).
Children
PhotoSpots is not directed to children under 16. If you believe a child provided us data, contact us to remove it.
Changes to this policy
We may update this policy from time to time. We will post changes here and update the date above.
Questions? Email pawelpamula003@gmail.com.