Privacy Policy
How ThankQR collects, uses, retains, and deletes personal data for hosts, guests, and face-powered event features.
REVISED / 3 August 2026ThankQR is a private event gallery service for hosts and guests. This policy explains what data we collect, why we use it, how long we keep it, and how you can exercise your rights.
This version is written for a UK and EU launch baseline. It covers account data, event media, guest participation, cookies, face-processing features, and deletion requests.
Who we collect data from
We collect information from hosts who create and manage events, guests who join or interact with events, and visitors who browse the marketing site or contact us.
The exact data we hold depends on how you use ThankQR. Some data is required to run the service, while some is optional and only used if you choose to use specific features.
Data we collect
Host account data can include name, email address, password hash, billing and subscription records, account settings, event metadata, support messages, and session/security logs.
Guest account data can include name, email address, notification preferences, joined-event history, saved Find Me results, guestbook activity, and session/security logs.
Event media data can include uploaded photos, thumbnails, processing metadata, comments, likes, upload timestamps, uploader identity, and moderation/report records.
Face-processing data can include detected face regions, reference encodings created for Find Me, match distances, saved reference-profile metadata, and face-group associations used to organize event galleries.
Technical data can include security session information, CSRF tokens, verification or password-reset artifacts, and optional device preferences. With analytics consent, we store a pseudonymous browser subject, a protected session digest, event name, source, bounded metadata, consent-receipt reference, and timestamp.
Why we use personal data
We use personal data to provide core product functions, including account creation, event management, guest access, private gallery delivery, billing, support, fraud prevention, and service security.
We use event media and related processing metadata to generate thumbnails, optimize uploads, power comments/likes, support moderation, and operate face-based Find Me searches when enabled by product flows.
We use optional preference storage to keep helpful device-level state such as signup drafts, guest draft content, and dashboard layout choices. We do not treat that storage as necessary for core authentication.
After an eligible paid event, we may send the host a practical event recap and use their name, email address, and event reference to request one neutral service review through Trustpilot.
Lawful bases
We rely on contract and legitimate interests to provide the hosted service, secure accounts, prevent abuse, and support event delivery.
We rely on consent for pseudonymous product analytics. Find Me uses separate explicit choices for an event search and for saving a reusable event-scoped biometric profile; those choices are not bundled with cookie consent.
We may retain limited records where needed to comply with legal obligations, enforce terms, investigate abuse, or maintain financial records.
Cookies and local storage
Necessary cookies are used for sign-in sessions, CSRF protection, and related security controls. These are required for the app to function.
Optional local storage is used for convenience features such as signup progress, guest continuity drafts, and dashboard layout preferences. Those categories stay off until you opt in through our consent banner or cookie preferences.
Analytics remains disabled until our API records a current consent receipt. One browser choice applies across thank-qr.com and app.thank-qr.com, expires after 180 days, and can be withdrawn through the persistent Cookie settings control.
Raw consented analytics events are retained for 90 days. They exclude host IDs, event IDs, IP addresses, and browser user-agent strings. Withdrawing consent stops new collection and schedules that browser’s remaining raw events for deletion.
Face processing and Find Me
ThankQR can detect faces in event photos and compare them to a guest-supplied reference image to help surface likely matches inside that event.
Face data is used only to operate those in-product features, group event photos, and return likely matches. It is not sold or licensed for advertising, profiling, or unrelated identification.
Reference detection and searching require explicit event-level consent. Saving a reusable biometric profile requires a second explicit choice and applies only to that event.
Guests can withdraw Find Me consent and delete saved reference profiles. Withdrawal removes transient search data and reusable biometric profiles, while ordinary photos deliberately saved to My Photos remain until separately removed.
Third parties and processors
ThankQR may use infrastructure and service providers for hosting, storage, email delivery, payment processing, and content delivery. That can include providers such as Fly.io, object-storage/S3-compatible services, Resend or SES for email, and Stripe for billing.
For eligible hosts, Trustpilot may receive the host name, email address, and an internal event reference so it can send a single service-review invitation. The invitation is not selected according to sentiment, and Trustpilot provides its own unsubscribe control.
Those providers process data only to deliver the service on our behalf or to complete a transaction you request.
International transfers
Depending on where our providers host or process data, personal data may be transferred outside the UK or EEA. Where that happens, we rely on appropriate contractual or legal transfer mechanisms and keep data sharing limited to what is needed to operate the service.
Retention
Hosts and guests can request deletion. In version one of our deletion workflow, accounts are immediately deactivated, active sessions are revoked, and a purge or anonymization process runs after a defined grace period.
Verification codes, password-reset artifacts, magic links, and email-change tokens are short-lived and are routinely removed after expiry or shortly after use.
Raw analytics events are kept for 90 days. Minimal consent evidence—purpose and wording versions, decision, source site, and server timestamps—is kept for up to three years for accountability and does not contain IP addresses, user-agent strings, or biometric values.
Guest saved-photo references, event-scoped face profiles, guest continuity storage, and report records are kept only as long as needed to deliver the feature, resolve abuse issues, or honour a valid deletion request.
Billing, webhook, and limited security logs may be retained longer where necessary for fraud prevention, financial recordkeeping, dispute handling, or legal compliance.
Deletion and your rights
Hosts and guest-account users can request account deletion from authenticated settings flows. After you request deletion, the account is deactivated immediately and access is blocked while the grace-period purge runs.
You can also ask for access, correction, deletion, or objection in line with applicable UK and EU data protection rights by contacting enquiries@thank-qr.com.
If you believe event media is harmful or inappropriate, guests can report photos from the event gallery and hosts or admins can review those reports in moderation tools.
Security and updates
We use access controls, hashed credentials, session security, signed media access, and moderation tooling to reduce misuse, but no system can promise absolute security.
If this policy changes materially, we will update this page and revise the effective date shown above.
Contact
Questions, privacy requests, or deletion issues can be sent to enquiries@thank-qr.com.
