Last updated: June 25, 2026
Privacy Policy
This Privacy Policy explains how Flash ("we", "us", or "our") collects, uses, and protects your information when you use our disposable camera web application at https://flashcam.app.
1. Information We Collect
Information you provide
—Account information: email address and display name when you sign up
—Event data: event name, date, venue, and settings you configure
—Guest information: nickname and language preference when joining an event
—Payment information: processed securely by Stripe — we never store card details
—Brand/logo: optional PNG logo if you enable white-label branding
Information collected automatically
—Photos you take through the app camera
—Device type (iOS, Android, desktop) for display optimization
—Basic usage data: which features are used, event activity
Information we do NOT collect
—We do not collect your precise GPS location
—We do not access your device photo library
—We do not track you across other websites or apps
—We do not sell your data to third parties
2. How We Use Your Information
—To operate the Flash app and provide the camera and gallery features
—To authenticate your account and keep it secure
—To process payments via Stripe
—To send transactional emails (account confirmation, payment receipts)
—To improve the app based on usage patterns
—To respond to support requests
3. Photo Storage
Photos taken through Flash are uploaded to and stored on Supabase (a PostgreSQL-based cloud platform) in Canada. Photos belong to the event host and their guests. Photos are:
—Stored securely in a private cloud bucket
—Only accessible to event participants via the unique event join code
—Retained as long as the event exists in our system
—Permanently deleted when the host deletes their event
We do not analyze, scan, or use your photos for training AI models.
4. Data Sharing
We share your data only with:
—Supabase — database and file storage (Canada)
—Stripe — payment processing (your card data never touches our servers)
—Vercel — app hosting and deployment
We do not sell, rent, or share your personal information with any advertising networks or data brokers.
5. Cookies & Local Storage
Flash uses:
—Authentication cookies managed by Supabase to keep you signed in
—Browser localStorage to remember your guest session within an event (event ID, guest ID)
We do not use advertising cookies or third-party tracking cookies.
6. Data Retention
—Host accounts: retained until you delete your account
—Events and photos: retained until the host deletes the event
—Guest data: retained for the duration of the event
—Payment records: retained for 7 years as required by Canadian tax law
7. Your Rights
You have the right to:
—Access the personal data we hold about you
—Correct inaccurate data
—Delete your account and all associated data
—Export your event photos before deleting
—Withdraw consent at any time
To exercise any of these rights, email us at privacy@flash-roan.vercel.app
8. Children's Privacy
Flash is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it immediately.
9. Security
We protect your data using:
—HTTPS encryption for all data in transit
—Row-level security policies on our database
—Secure authentication via Supabase Auth
—Encrypted storage of payment-related metadata
10. Canadian Privacy Law (PIPEDA)
Flash is based in Canada and complies with the Personal Information Protection and Electronic Documents Act (PIPEDA). We collect only the minimum personal information necessary to provide our service.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email before any significant changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact Us
For privacy questions or data requests: