Privacy policy

Last updated: September 2026

evnt.cam is a service of MarvinJWendt, based in Germany. This policy explains what personal data we process when you use our website and our service, why, and on what basis. We handle personal data in accordance with the General Data Protection Regulation (GDPR) and German data protection law.

1. Controller

The controller for the processing described here is MarvinJWendt. The full postal address and contact details are in our imprint. For privacy matters, write to us through our support page.

2. What we process

  • Account data. Your email address, your name, a hash of your password, your language, and the timestamps of your account. You give us these when you register.
  • Event data. The name, description, date and settings of the events you create, and their cover and colour.
  • Photos. The photos uploaded to an event by you or your guests, together with their size, type, dimensions and upload time. A photo may show people; whoever uploads it is responsible for having their consent, as our terms set out.
  • Reports. When a photo is reported we store the reason, an optional note, and a one-way hash of the reporter's IP address and browser identification. The hash exists only to limit abuse of the report function; it is never shown to anyone and cannot be turned back into an address.
  • Technical data. Our hosting provider processes the usual connection data, such as IP address, browser identification and request time, to deliver the site and keep it secure.

Guests need no account. We do not ask a guest for a name, an email address or any other identifier, and we do not track which photo came from which guest.

  • To provide the service you asked for: performance of a contract, Art. 6(1)(b) GDPR. This covers your account, your events, the photos and the emails the service has to send you.
  • To keep the service secure and to prevent abuse: our legitimate interest, Art. 6(1)(f) GDPR. This covers bot protection, rate limiting and the handling of reports.
  • To meet legal obligations where they apply: Art. 6(1)(c) GDPR.

We do not use your data for advertising, profiling or automated decision-making, and we do not sell it.

4. Who processes it for us

We use a small number of providers, each bound by a data processing agreement:

  • Database: Neon, on servers in Frankfurt, Germany. Account data and event data live here.
  • Website and photo storage: Vercel. The site runs on Vercel, and photos are stored in Vercel Blob and delivered through a global content delivery network, which uses Amazon Web Services in the background. A photo is therefore cached on servers outside the EU when someone opens it from there.
  • Bot protection: Vercel BotID, part of the Vercel platform. It examines signals from your browser on registration, sign-in, upload and report requests to tell people from automated traffic.
  • Web analytics: Vercel Web Analytics, part of the Vercel platform. It counts page views and tells us which pages are opened, from which country and on what kind of device. It sets no cookie and stores nothing in your browser; visits are told apart by a hash of the request that is discarded at the end of the day, so no visitor can be followed across days or across sites. This is our legitimate interest in knowing whether the service works, Art. 6(1)(f) GDPR.
  • Email: Resend. We send only transactional email: the verification link, a password reset link, a notice when your event ends, and a warning before the photos are deleted. A report about a photo notifies our administrators, not the host. We send no newsletters.

5. Cookies and browser storage

We set only technical cookies: the cookie that keeps you signed in, and a cookie that remembers your language. We use no tracking, advertising or third-party cookies. The web analytics described above work without a cookie and without any storage in your browser. Because the cookies we do set are strictly necessary for a service you asked for, evnt.cam needs no cookie banner.

Your browser also stores the last gallery it opened, so that the page of a single photo can offer a way back to it. That page is never told which event its photo belongs to, and we keep no record of what your browser remembered.

6. How long we keep it

  • Photos are deleted when the event's retention period ends, which depends on the event's plan and is shown in the app. They are also deleted at once when the host deletes the photo or the event.
  • Event data stays until the host deletes the event, or the account.
  • Account data stays until you delete your account. Deleting your account starts a job that deletes every event you created, every photo in those events, the files behind them, and finally the account itself.

7. Your rights

Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to receive it in a portable form, and to object to processing based on our legitimate interest. You also have the right to complain to a supervisory authority.

Much of this you can do yourself: your account screen changes your name and language and deletes your account, and your event screens delete individual photos or a whole event. For anything else, write to us through the support page.

8. Security

Passwords are stored only as cryptographic hashes. Traffic between your device and our servers is encrypted with TLS. Access to the production systems is limited to the people who operate the service.

9. Changes to this policy

We may update this policy when our practices or the law change. The current version is always on this page, and the date at the top says when it last changed.