EventPix is operated by Laligence, an AI company based in Laos. This policy explains what data we collect, why we collect it, how long we keep it and what you can do about it. It applies to everyone who uses EventPix — attendees searching for photographs of themselves, photographers and organisers who upload them, and visitors who only browse.
Face search means we process biometric data, so that part is set out separately and in full below.
1. What we collect
- Account data
- Your name, email address, password (stored hashed, never in plain text), the roles on your account, and your language and theme preference.
- Photographs and their metadata
- Photographs uploaded by Creators and Contributors, together with the EXIF metadata embedded in them (such as capture time and camera settings), the derived thumbnails and resized copies, and the account each photograph is attributed to.
- Biometric data
- Numerical face embeddings derived from the faces in uploaded photographs, and the selfie you submit when you run a face search. See section 2.
- Bib numbers
- For races, the competitor numbers our optical character recognition reads from a photograph.
- Content screening results
- An automated score indicating whether an uploaded image contains explicit content.
- KYC verification data
- For Creators requesting payouts: a government-issued identity document and a liveness selfie. See section 4.
- Transaction data
- What you bought, when, for how much, and the outcome reported by the bank. We do not receive or store your card number or banking credentials.
- Technical data
- IP address, browser and device information, and request logs with a correlation identifier, used for security, abuse prevention and debugging. Once you have accepted this policy, similar data is also collected by Google Analytics for Firebase to produce aggregate usage statistics — see sections 6 and 7.
2. Face search and biometric data
This is the most sensitive data we handle, so here is exactly what happens.
Faces in uploaded photographs
When a photograph is uploaded, we detect the faces in it and convert each one into a numerical vector — a mathematical representation of the face, not a picture of it. These embeddings are stored alongside the event and are what makes a search possible. They are used only to match searches against that event’s own gallery. They are never sold, never shared with advertisers, and never used to identify anyone outside EventPix.
The selfie you search with
- We ask for your explicit consent before any facial processing takes place.
- Your selfie is converted to an embedding, compared against the faces in that one event, and then deleted within one hour.
- It is never added to a gallery, never published, and never sold.
- It is not used to identify you in any other event or any other context.
- Matching uses a high confidence threshold specifically so that other people’s photographs are not returned to you.
Turning it off
Face search is a per-event setting. An organiser can disable it entirely, in which case no facial processing happens for that event. As an attendee, you simply do not have to use it — browsing and bib search work without it.
3. Why we use your data
- To run the service — hosting galleries, indexing photographs, returning search results, delivering purchases.
- To take payment and pay Creators — processing transactions, calculating revenue splits, issuing payouts.
- To keep the platform safe — screening uploads for explicit content, detecting abuse, enforcing our Terms and Conditions.
- To meet legal obligations — identity verification for payouts, accounting records, responding to lawful requests.
- To communicate with you — transactional email such as verification, purchase confirmation, event expiry warnings and payout notices.
We do not sell your personal data, and we do not use your photographs or your face to train models for anyone else.
4. Identity verification
Creators who want to receive payouts must complete identity verification: a government-issued identity document and a liveness selfie, with a maximum of three attempts. These documents are encrypted at rest with AES-256, are accessible only to the small number of staff who review them, and are deleted 90 days after approval. We keep only the fact that verification succeeded and when.
5. How long we keep things
| Data | Retention |
|---|---|
| Face search selfie | Deleted within 1 hour |
| Event photographs and face embeddings | Deleted 121 days after publication (60 days live, 60 days retention) |
| Your copy of a purchased photograph | 60 days from purchase |
| KYC documents | 90 days after approval |
| Transaction and accounting records | As long as the law requires |
| Account data | Until you close your account, then removed or anonymised |
6. Who we share data with
- Banks and payment providers — BCEL, LDB and JDB, to take payment and make payouts. They receive the amount and reference, not your gallery activity.
- Cloud storage and hosting providers — to store and serve photographs and run the service.
- Google — in two separate situations. If you choose to import photographs from Google Photos or Google Drive, we request the narrowest access needed for that import and use it for nothing else. Separately, once you have accepted this policy, we load Google Analytics for Firebase to count page views and understand which parts of the site are used. It receives your IP address, your browser and device information, the pages you visit, and an anonymous installation identifier that distinguishes your browser from another. It never receives your photographs, your search selfie, your bib searches or your account credentials.
- Event Creators — a Creator can see the transactions and download activity for their own event, but not your account credentials or your search selfie.
- Authorities — where we are legally required to disclose.
7. Cookies and browser storage
We use a session cookie to keep you signed in. We also store a small amount of data in your browser’s local storage — your language preference, your light or dark theme choice, your record of accepting this policy, and your shopping cart before you sign in (it moves to your account when you do).
Once you have accepted this policy we load Google Analytics for Firebase. It sets first-party cookies (_ga and _ga_*) to recognise a returning browser and group its page views into a single visit, and it stores an anonymous installation identifier in your browser’s IndexedDB storage for the same purpose. The cookies stay on your device for up to two years unless you clear them. We use the resulting statistics only to see how the site is used — which pages people reach, on what kind of device, and where they give up. We do not use advertising cookies, we do not run remarketing or ad personalisation, and we do not sell or share this data with advertisers.
Analytics does not load until you accept, and it never loads for search-engine crawlers. To stop it after accepting, clear this site’s data in your browser: that removes the analytics cookies, the installation identifier and the record of your acceptance, so nothing loads again unless you accept a second time. Google also publishes an opt-out browser add-on that blocks it on every site.
8. Your rights
You can:
- access the personal data we hold about you;
- correct it if it is wrong;
- ask us to delete your account and its data;
- ask us to remove a photograph you appear in, whether or not you have an account;
- withdraw consent to facial processing at any time;
- object to a particular use of your data.
Write to [email protected] and we will respond within 30 days. Some data — accounting records in particular — we are obliged to keep even after an account is closed.
9. Security
Photographs and identity documents are encrypted at rest, purchased originals are delivered through signed time-limited links, passwords are hashed, and access to production data is restricted and logged. No system is perfectly secure, but if a breach affects your data we will tell you and the relevant authorities without undue delay.
10. Children
EventPix is not intended for children under 13, and we do not knowingly create accounts for them. If you believe a child under 13 has an account, or that a photograph of a child should not be public, contact us and we will act.
11. Changes to this policy
We may update this policy. The date at the top shows when it last changed, and we will give notice of material changes through the service.
12. Contact
Privacy questions, removal requests and data requests: [email protected]. See also our Contact page.