Privacy policy

Last updated 22 September 2026

What we collect, who else sees it, and how long we keep it. You're trusting us with photographs of your friends and family, so this page tries to be specific rather than reassuring.

The short version

We don't track you. There are no analytics, no advertising pixels, and no third-party scripts watching what you do. We set one cookie, and it only exists to keep you signed in. We don't sell anything about you to anyone, ever.

What we collect from hosts

  • Your email address and a display name — so you can sign in, and so we can send you the things you need.
  • Your password, hashed. We store a one-way hash, never the password itself. We genuinely cannot see it.
  • Your event details — the name you gave it and the date, plus the QR link that goes with it.
  • A record that you paid — a reference to the Stripe checkout, what it bought, and when. Not your card number.

What we collect from guests

Almost nothing, because guests never make an account. When someone scans a QR code and sends a photo, we store the photo along with its size, dimensions, file type and the time it arrived.

To stop one person filling a whole album, we need to count how many photos a phone has sent. We do that with a random ID that stays in that phone's own browser storage. It isn't a name, an email or an account, it isn't shared with anyone, and clearing the browser's data erases it.

Cookies

One, called session. It's set when you sign in, it can't be read by JavaScript, and it does nothing but keep you signed in. Guests taking photos are never given a cookie at all. That's why there's no cookie banner on this site — there's nothing to consent to.

Who else touches your data

Five companies, each doing one job, and none of them get anything they don't need:

  • Railway — runs the site, the database and the storage your photos live in. Servers are in the United States.
  • Stripe — takes the payment. Your card details go straight to them and never touch our servers.
  • Resend — delivers the handful of emails we send: confirm your address, reset your password, and the warning before your gallery comes down.
  • Unsplash — the example photographs on our home page load from them, which means they see the IP address of anyone visiting that page. No other page loads anything from them, and your own photos are never sent anywhere near them.
  • Sentry — tells us when something breaks on our servers, so we find out before you do. It runs only on our side: nothing is added to your phone or browser, and it's set not to collect IP addresses. What it receives is the error and where in our code it happened.

Who can see your photos

Your gallery is private to your account. Photos aren't public, aren't indexed by search engines, and aren't browsable by anyone who doesn't have your QR link or your login. When a photo is displayed, it's served through a signed link that expires after an hour rather than a permanent public address.

We don't look through your galleries. The exception is if someone reports abusive content and we have to act on it.

How long we keep things

  • Photos: one year after your event, then they're deleted. We warn you by email before that happens.
  • Your account: until you ask us to delete it.
  • Payment records: kept as long as tax and accounting rules require.

What you can ask us to do

Email [email protected]and we'll do any of these: tell you what we hold about you, correct something that's wrong, delete your account and everything in it, or send you a copy of your data. You don't need to cite a regulation at us — just ask.

Children

Cricky Creationsisn't meant for children, and we don't knowingly create accounts for anyone under 13. Children may well appear in photographs taken at a wedding — those belong to the host's gallery and are covered by everything above.

Changes

If this policy changes, the date at the top changes with it. If we ever start collecting something new, we'll say so here before we start.