Privacy Policy

Last updated: [DATE] — Effective: [DATE]

1. Who we are

[COMPANY NAME], registered in [COUNTRY], operating under the brand name “Lenso”. Contact: privacy@lenso.media.

2. What data we collect

  • Event hosts: email address, name, payment information (processed by Lemon Squeezy — we do not store card data).
  • Event guests: photos, videos, and text posts submitted through event QR codes. We do not collect names or emails from guests unless voluntarily provided.
  • Technical data: IP address, browser type, and usage analytics (via Plausible Analytics — privacy-preserving, no cookies).

3. Legal basis (GDPR)

  • Contract performance (Art. 6(1)(b)) — for providing the service to hosts.
  • Consent (Art. 6(1)(a)) — guests provide explicit consent before uploading.
  • Legitimate interests (Art. 6(1)(f)) — service improvement and fraud prevention.

4. Data storage and location

All data is stored in the European Union (Frankfurt, Germany) via Supabase (database) and Cloudflare R2 (media files, WEUR region). We do not transfer personal data outside the EEA.

5. Data retention

Guest media (photos, videos) are automatically deleted after the retention period selected by the event host (7–365 days). Guest consent records are retained for 3 years for legal compliance. Host account data is retained until account deletion.

6. Your rights (GDPR)

  • Access (Art. 15) — request a copy of your data.
  • Rectification (Art. 16) — correct inaccurate data.
  • Erasure (Art. 17) — delete your account or individual uploads via the delete link provided after upload.
  • Portability (Art. 20) — export your data.
  • Object (Art. 21) — object to processing.

To exercise any right, contact privacy@lenso.media.

7. Third-party processors

  • Supabase — database hosting (EU)
  • Cloudflare R2 — media storage (EU)
  • Lemon Squeezy — payment processing
  • Resend — transactional email
  • Plausible Analytics — privacy-first analytics (no cookies)

8. Cookies

We use only strictly necessary cookies for authentication (Supabase session cookie). We do not use advertising or tracking cookies. Plausible Analytics requires no cookies.

9. Contact & complaints

Data controller: [COMPANY NAME], [ADDRESS].
Email: privacy@lenso.media.
You have the right to lodge a complaint with your national data protection authority.