Dayfolds Back to home
Legal

Privacy Policy

Last updated July 27, 2026

Dayfolds is a product of VISK, registered with the Dutch Chamber of Commerce (KVK) under number 86233890. This policy explains what information we collect when you use Dayfolds, why we collect it, and what choices you have. We have tried to write it in plain language rather than dense legal text. If anything is unclear, email us at hello@dayfolds.com and we will explain it properly.

1. Who this policy applies to

Dayfolds has two kinds of users. Hosts create an account, set up an event, and pay to activate it. Guests scan a QR code and upload photos, videos, voice messages, or written notes to a host's event, without ever creating an account. Both groups are covered by this policy, but the data we hold about each is different, which is why we have split things out below.

2. What we collect from hosts

When you sign up as a host we collect your email address and, if you choose to sign in with a provider like Google, whatever basic profile information that provider shares with us (typically your name and email). When you create an event, we store the event name, date, location, cover image, and the settings you choose, like whether uploads require approval. When you pay to activate an event, payment is handled entirely by Stripe, our payment processor. We never see or store your card details ourselves, we only receive confirmation that a payment succeeded and a reference we use to keep your account and Stripe's records linked.

3. What we collect from guests

Guests do not create an account and we do not ask for an email address or phone number to upload something. If a guest chooses to add a name or caption to their upload, we store exactly what they typed, nothing more. We also store the file itself (photo, video, or audio) and basic technical metadata needed to serve it, such as file type, size, and upload time. We do not knowingly collect precise location data from guest uploads.

4. Why we process this data

We use host account data to let you sign in, manage your events, and process payment for activating them. We use guest upload data for the single purpose the product exists for: displaying it in the host's private event gallery, and, if the host has enabled it, in a live slideshow view. We also use limited technical data to keep uploads working reliably on inconsistent venue wifi, and to detect abuse of the service.

5. Who else sees this data

We rely on a small number of external providers to run Dayfolds, and your data passes through them as part of normal operation. We use Google Firebase for account sign-in and app data, Stripe for payment processing, and Cloudflare for storing and delivering the photos, videos, and audio files guests upload. Each of these providers processes data on our behalf under their own security and privacy commitments, and we do not sell or rent your data to anyone for advertising or any other purpose.

6. How long we keep event media

Event media (photos, videos, voice messages, and guestbook notes) is available for 3 months from the event date, starting from whichever comes first, the event date itself or the first upload to that event, whichever locks in the retention window under the hood. After that window ends, we permanently delete the media files and the associated upload records as part of a daily cleanup process. We recommend downloading your full event archive before this window closes, since we are not able to recover media once it has been deleted. Host account information (like your email and past event names) is kept for as long as your account exists, so you can see your event history, unless you ask us to delete it sooner.

7. Cookies and similar technology

We use a minimal set of cookies and local storage to keep you signed in as a host and to remember basic preferences like dark mode. We do not use third-party advertising cookies or cross-site trackers. If we ever add analytics in the future, we will update this policy first.

8. International data transfers

Our infrastructure providers operate data centers in multiple regions. Where your data is transferred outside the European Economic Area, we rely on the safeguards those providers offer, such as standard contractual clauses, to keep it protected to a comparable standard.

9. Changes to this policy

We may update this policy from time to time as the product changes. If we make a change we consider significant, we will update the date at the top of this page and, where reasonably possible, let existing hosts know. Continuing to use Dayfolds after a change means you accept the updated policy.

10. Contact

Dayfolds is a product of VISK, KVK 86233890. For any question about this policy or your data, email hello@dayfolds.com.