Privacy Policy
Effective August 13, 2026Jurisdiction: Texas, USAFacial recognition: opt-in registrationFace templates destroyed after 1 year inactive
Tag Your Photo LLC (“Company,” “we,” “our,” or “us”) respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our services — the Tag Your Photo mobile app, our websites, event photo galleries, and photo delivery by SMS or email.
1. Who This Policy Covers
Two different groups use Tag Your Photo, and the way we handle information differs for each:
- Operators — photo booth companies, event photographers, schools and venues who hold an account with us and run events using our app.
- Guests — people photographed at an event an Operator is running, who may then look up and receive their own photos.
For guest information captured at an event, the Operator running that event decides what is collected and why. We process that information on the Operator’s behalf as a service provider. The Operator is responsible for providing any notice and obtaining any consent required at the event itself, including for the facial recognition features described in Section 4.
2. Information We Collect
- Identifiers: name, phone number, email address
- Account information (Operators): email address and password, or a Sign in with Apple or Google identifier; company name and contact details
- Event details: event name, gallery selections, purchase history
- Photographs and videos taken at events, whether captured with a connected Canon, Sony or Nikon camera, with a phone or tablet camera, or uploaded
- Facial geometry (biometric identifiers) derived from those photographs — see Section 4
- AI-generated images created from event photos when an Operator or guest applies an AI photo style
- Payment details (processed by third-party providers such as Stripe and Apple; we do not store full card numbers)
- Technical data: device, camera and browser metadata, IP address, and usage analytics
2.1 Cookies and gallery analytics
We measure how event galleries are used so that an Operator can show their client what an event reached. That measurement is our own, it stays on our servers, and it is deliberately built not to identify anyone:
- A guest opening their own photo gallery is given no cookies at all. The personal gallery link already identifies you, so nothing needs to be stored on your device, and no third-party analytics runs on that page.
- Guest activity is measured only by our own first-party analytics. Each record stores a one-way hash — a scrambled value that cannot be reversed — instead of a name, phone number or email address. Analytics records never contain contact details, face templates or any other biometric information.
- On a public event gallery, where we do not know who you are, we set a first-party cookie named typa containing only a random identifier, so that reloading a page is not counted as a second visitor. A session cookie may also be set where a gallery is password protected.
- Third-party analytics. Google Analytics runs on our marketing and Operator pages — our home page, product and pricing pages, sign-in and the Operator dashboard. It does not run on guest photo galleries.
- What Operators see. An Operator sees totals and rates for their own events — how many photos were viewed, how many guests took part, how many photos were delivered. They cannot see a guest's browsing history, and analytics gives them no contact details they did not already have.
3. How We Use Information
- Capture, upload and store event photos and make them available in event galleries
- Match guests to the photos they appear in, so a guest can find their own pictures (see Section 4)
- Deliver photos and event notifications by SMS or email
- Generate AI-styled versions of photos when that feature is used (see Section 5)
- Print photos on site when an Operator uses the printing feature
- Process purchases, credits and subscriptions
- Communicate updates and support messages
- Improve our services, and maintain security and fraud prevention
- Comply with legal and regulatory requirements
4. Facial Recognition and Biometric Information
Tag Your Photo uses facial recognition so that a guest can find the photos they appear in without searching an entire event gallery. This section explains exactly what that involves.
- What we create. When a photo taken at an event is processed, our provider detects the faces in it and generates a face template — a mathematical representation of facial geometry — so that photographs of the same person can be grouped together. A face template is not a picture, and it cannot be turned back into one. Under some state laws a face template is a “biometric identifier.” At this stage the grouping carries no name or contact details: it is an unnamed identity used only to keep one person’s photos together within that event.
- What it is used for. Face templates are used for one purpose only: matching a person to the photographs of them taken at the same Operator’s events, so those photos can be shown or sent to them. They are not used to identify anyone outside that purpose.
- Where it is stored. Face templates are stored in an Amazon Rekognition face collection, hosted on Amazon Web Services in the United States. Each Operator’s collection is kept separate, so a face template created at one Operator’s event is never matched against another Operator’s events.
- What we do not do. We do not sell, lease, trade or otherwise profit from biometric information. We do not use it to identify strangers, to build advertising profiles, to track people between venues, or for any purpose other than matching guests to their own event photos. We do not share it with law enforcement except where we are legally compelled to.
4.1 How a guest registers — and consents
An unnamed face grouping only becomes your gallery when you register, and registering is how you give consent. There are two ways it happens, and both require you to choose it:
- You register yourself (preferred). You scan a QR code at the event with your own phone, or scan the QR code shown in the Operator’s app using your own phone’s camera. You then add your name and the phone number or email address you would like your photos sent to. Because you scan from your own device, you decide whether to take part at all.
- The Operator registers you, with your spoken consent. If you would rather the Operator do it for you, they can register you from the app on their device. They will only do this after explaining that facial recognition will be used to find your photos and receiving your verbal consent. If you do not want to take part, tell the Operator and they will not register you.
If you never register by either method, no name, phone number or email address is ever attached to your face grouping, and you are never sent anything.
4.2 Removing your face
Any guest can permanently remove their own face from the system at any time from their personal gallery link. We send a six-digit verification code by SMS or email to confirm it is really you, and on confirmation we delete the face template from the Amazon Rekognition collection along with the records linking you to photographs, so it stops matching any further photographs. You can also email support@tagyourphoto.net, and an Operator can remove faces from their own events at your request.
4.3 How long face templates are kept
We destroy a guest’s face template automatically once that guest has been inactive for one year. Activity means anything that shows the guest is still using the service — viewing their gallery, receiving photos, or being photographed at another of the same Operator’s events. One year after the last such activity, the face template is deleted from the Amazon Rekognition collection, together with the records linking that person to photographs. This happens without the guest having to ask. A guest can of course delete their face sooner at any time, as described in Section 4.2, and an Operator deleting an event or their account also removes the associated face templates.
The photographs themselves are not biometric information and are retained separately, as described in Section 7.
4.4 Consent at the event
The Operator running an event is responsible for giving notice and obtaining any consent that applies where the event takes place, before guests are photographed or their faces are matched.
4.5 State biometric privacy laws
Several states regulate face templates specifically. If you live in one of them you may have additional rights, including the right to refuse and the right to have your face template destroyed. The summaries below are general information, not legal advice, and the law that applies to you usually depends on where you live rather than where we are based.
- Illinois — Biometric Information Privacy Act (BIPA, 740 ILCS 14). Requires written notice of what is collected, why, and for how long, plus a signed release before a face template is created. Prohibits selling or profiting from biometric data. Requires a public retention schedule and destruction when the purpose is met or three years after your last interaction, whichever is sooner. Illinois residents can sue directly.
- Texas — Capture or Use of Biometric Identifier (CUBI, Tex. Bus. & Com. Code § 503.001). Requires notice and consent before a face template is captured for a commercial purpose, prohibits selling it, and requires destruction within a reasonable time and no later than one year after the purpose for collecting it ends. Enforced by the Texas Attorney General.
- Washington — RCW 19.375. Requires notice and consent before a biometric identifier is enrolled in a database for a commercial purpose, prohibits selling or leasing it, and requires that it not be kept longer than reasonably necessary. Enforced by the Attorney General.
- Colorado — Colorado Privacy Act, as amended (HB 24-1130). Treats biometric identifiers as sensitive data requiring your consent, and requires a published policy covering retention and destruction.
- Oregon — Oregon Consumer Privacy Act (SB 619). Treats biometric data as sensitive data that may not be processed without your opt-in consent.
- California — CCPA/CPRA. Treats biometric information as sensitive personal information, with rights to know, delete, correct, and limit how it is used.
- New York City — Biometric Identifier Information ordinance. Requires conspicuous notice at commercial establishments that collect biometric identifiers, and prohibits selling or sharing them.
To exercise any of these rights, use the removal option in your personal gallery link or contact support@tagyourphoto.net. We honour deletion requests regardless of which state you live in.
5. AI Photo Styles
Our AI photo styles turn a photograph into a stylized image — a cartoon, a coloring page, a themed portrait and so on — and can also generate a short animated video from a photograph. When either feature is used, the photograph is sent to a third-party AI provider (currently Google and OpenAI) to produce the new image or video, and the result is returned to the event gallery. Only the photographs you choose to apply a style to are sent, and the photograph sent may contain faces. Face templates are never sent to these providers.
6. Sharing of Information
We do not sell your personal information. We share information with service providers only as necessary to operate the service:
- Amazon Web Services — photo storage and delivery, email sending, and facial recognition (Amazon Rekognition). Face templates used for recognition are processed only by Amazon and are never shared with any other provider.
- Twilio — SMS delivery of photos and notifications
- Google and OpenAI — generating AI-styled images and video, when that feature is used. The photo you choose is sent to the provider for processing; it may contain faces.
- Google — website analytics (Google Analytics), and Sign in with Google
- Apple — in-app purchases and Sign in with Apple
- Stripe — subscription and payment processing
- Content delivery networks (Google Fonts, Cloudflare, jsDelivr, jQuery) — used to load fonts and scripts on our pages; these providers receive your IP address and browser type
- Operators — an Operator can see the photos and galleries for the events they run
We may also disclose information where required by law, or to protect our rights, safety, or the safety of others.
7. Data Retention
We retain event photographs, galleries and related records for as long as the Operator maintains the event and their account, or as required by law.
Face templates are destroyed automatically after one year of guest inactivity, as described in Section 4.3, and can be deleted sooner at any time by the guest or the Operator. You may request deletion of your other information at any time (see Sections 4.2 and 9).
8. Your Choices
- SMS Opt-Out: Reply STOP to cancel; HELP for help.
- Email Opt-Out: Use the unsubscribe link in our emails.
- Take part, or don’t: Facial recognition only identifies you if you register — by scanning a QR code with your own phone, or by asking an Operator to register you (see Section 4.1).
- Remove your face: Use the removal option in your personal gallery link, or email us. Face templates are also destroyed automatically after one year of inactivity.
- Data Access/Deletion: Contact support@tagyourphoto.net.
9. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, to opt out of its sale or sharing (we do not sell it), and to be free from discrimination for exercising those rights. To exercise any right, contact support@tagyourphoto.net. We will verify your request before acting on it.
10. Security
We implement reasonable safeguards to protect your information, including encrypted connections, access controls on our systems, and separation of each Operator’s data. No method of transmission or storage is 100% secure.
11. Children’s Privacy
Our services are sold to and operated by Operators, not by children, and we do not knowingly collect personal information directly from children under 13. Children may appear in photographs taken at events such as school functions and family parties. Where that happens, the Operator running the event is responsible for obtaining any parental notice or consent required, including for the facial recognition features in Section 4. A parent or guardian may contact support@tagyourphoto.net at any time to have a child’s photographs and face template removed, and we will act on that request.
12. Changes to This Policy
We may update this Privacy Policy; updates will appear here with a new effective date.
13. Contact Us
Tag Your Photo LLC
Website: https://tagyourphoto.net
Email: support@tagyourphoto.net