Privacy Policy
Last updated: June 25, 2026

Privacy Policy

This Privacy Policy explains how Flash ("we", "us", or "our") collects, uses, and protects your information when you use our disposable camera web application at https://flashcam.app.

1. Information We Collect

Information you provide
Account information: email address and display name when you sign up
Event data: event name, date, venue, and settings you configure
Guest information: nickname and language preference when joining an event
Payment information: processed securely by Stripe — we never store card details
Brand/logo: optional PNG logo if you enable white-label branding
Information collected automatically
Photos you take through the app camera
Device type (iOS, Android, desktop) for display optimization
Basic usage data: which features are used, event activity
Information we do NOT collect
We do not collect your precise GPS location
We do not access your device photo library
We do not track you across other websites or apps
We do not sell your data to third parties

2. How We Use Your Information

To operate the Flash app and provide the camera and gallery features
To authenticate your account and keep it secure
To process payments via Stripe
To send transactional emails (account confirmation, payment receipts)
To improve the app based on usage patterns
To respond to support requests

3. Photo Storage

Photos taken through Flash are uploaded to and stored on Supabase (a PostgreSQL-based cloud platform) in Canada. Photos belong to the event host and their guests. Photos are:

Stored securely in a private cloud bucket
Only accessible to event participants via the unique event join code
Retained as long as the event exists in our system
Permanently deleted when the host deletes their event

We do not analyze, scan, or use your photos for training AI models.

4. Data Sharing

We share your data only with:

Supabase — database and file storage (Canada)
Stripe — payment processing (your card data never touches our servers)
Vercel — app hosting and deployment

We do not sell, rent, or share your personal information with any advertising networks or data brokers.

5. Cookies & Local Storage

Flash uses:

Authentication cookies managed by Supabase to keep you signed in
Browser localStorage to remember your guest session within an event (event ID, guest ID)

We do not use advertising cookies or third-party tracking cookies.

6. Data Retention

Host accounts: retained until you delete your account
Events and photos: retained until the host deletes the event
Guest data: retained for the duration of the event
Payment records: retained for 7 years as required by Canadian tax law

7. Your Rights

You have the right to:

Access the personal data we hold about you
Correct inaccurate data
Delete your account and all associated data
Export your event photos before deleting
Withdraw consent at any time

To exercise any of these rights, email us at privacy@flash-roan.vercel.app

8. Children's Privacy

Flash is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it immediately.

9. Security

We protect your data using:

HTTPS encryption for all data in transit
Row-level security policies on our database
Secure authentication via Supabase Auth
Encrypted storage of payment-related metadata

10. Canadian Privacy Law (PIPEDA)

Flash is based in Canada and complies with the Personal Information Protection and Electronic Documents Act (PIPEDA). We collect only the minimum personal information necessary to provide our service.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email before any significant changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact Us

For privacy questions or data requests:

Email: privacy@flash-roan.vercel.app
Website: https://flashcam.app
By using Flash, you agree to this Privacy Policy.
View Terms of Service →