Privacy policy
Last updated 19 August 2026
We store your photos and your event data in Frankfurt, Germany. We do not sell anything, scan anything, or train AI on anything. Photos are deleted when your event window ends. The formal document below says the same thing in the language the law asks for.
In questa pagina
01Who we are
Twirl is a product of Ciceroni VOF, a company registered in the Netherlands.
| Detail | Value |
|---|---|
| Legal entity | Ciceroni VOF |
| Legal form | Vennootschap onder firma (VOF). A conversion to a besloten vennootschap (BV) is planned. This policy will be updated on conversion. |
| Trade name | Twirl |
| KVK (Dutch Chamber of Commerce) number | 76619176 |
| Registered address | Franklinstraat 161, 2562 CD Den Haag |
| VAT identification number | NL860705626B01 |
| Website | https://twirl.photos |
| Contact for privacy matters | privacy@twirl.photos (general contact: hello@twirl.photos) |
In this policy, "we", "us" and "Twirl" mean Ciceroni VOF. "You" means whoever is reading, which may be an organizer or a guest. Where the distinction matters, we say which.
02Who this policy is for
Two very different groups of people show up in Twirl, and the law treats them differently.
- Organizers are the people who buy Twirl and run an event. Usually a couple, sometimes a parent or a planner acting for them. Organizers create an account with us.
- Guests are the people invited to that event. Guests do not create an account, do not set a password of their own, and do not download an app. They open a link or scan a QR code, enter the shared event password, and upload or RSVP.
- Visitors are anyone reading the public marketing site at twirl.photos without doing either of the above. This policy covers all three. Section 6 is written for organizers, section 8 is written for guests, and the rest applies to everyone.
03Our two roles under the GDPR
This is the single most important thing to understand about how Twirl handles data, so we are putting it near the top rather than burying it.
3.1We are the controller for organizer account data
When you sign up as an organizer, we decide what account information we need and why. Your email address, your login credentials, your billing records, your support correspondence with us. For that data we are the controller, and this policy is the notice required under Articles 13 and 14 of the GDPR. Section 6 sets out the detail.
3.2We are the processor for guest data
Everything that guests put into an event belongs to the organizer's side of the relationship. The photographs, the videos, the voice memos, the names typed at upload, the RSVP answers. The organizer decides who is invited, what questions to ask, what to keep, what to delete and when. That makes the organizer the controller for that data, and Twirl the processor, acting on the organizer's instructions.
In practice this means that if you are a guest and you want your photograph taken down, the person with the authority to make that decision is the couple, not us. We will still help. Section 8.6 explains how.
Our processing on behalf of organizers is governed by a Data Processing Agreement, which every organizer accepts as part of the Terms of Service and which is available in full at data processing agreement.
3.3Where the line is honestly a little blurry
We set some parameters that a strict reading might call controller decisions. We decide how long an unextended event window runs before deletion, we set the threshold at which flagged content is escalated, and we decide what security logging happens. We do these things to run a functioning and lawful service rather than for our own purposes, and we treat them as processor activity. We would rather flag this than pretend the boundary is cleaner than it is.
04What we do not do
Stated plainly, because absence of a practice is harder to prove than presence of one and we would rather commit to it in writing.
- We do not sell personal data, and we do not share it with data brokers, advertisers or list buyers.
- We do not use uploaded photos, videos or voice memos to train machine learning or artificial intelligence models, and we do not permit our subprocessors to do so.
- We do not run advertising or behavioural tracking on the site.
- We do not look at event media except where we are required to for a specific reason: responding to a support request from the organizer, investigating content flagged by a guest or organizer, or complying with a legal obligation.
- We do not require guests to create an account, hand over a phone number, or install anything.
05Sources of the data we hold
We get personal data from four places: directly from organizers when they sign up and configure an event, directly from guests when they upload or RSVP, automatically from devices when anyone uses the service (IP address, browser type, timestamps), and from our payment provider Stripe, which tells us whether a payment succeeded and gives us limited billing details but never card numbers.
06Organizer data, where we are the controller
6.1What we collect
| Category | Specifically | Where it comes from |
|---|---|---|
| Account data | Email address, hashed password, account creation date, last login, email verification status | You, at signup |
| Event configuration | Event name, event date, lock date, programme and sub-event details, guest categories, custom RSVP questions, event password you set, display preferences | You, in the dashboard |
| Guest list metadata | Names and, where you enter them, contact details of the people you invite, plus any category assignments. Note that this is guest personal data for which you are the controller, covered by section 8 and by the DPA. | You, by entry or spreadsheet import |
| Billing and transaction data | Purchase records, amounts, currency, VAT treatment, country of purchase, Stripe customer and payment identifiers, invoice records. We do not receive or store full card numbers. | Stripe, and you at checkout |
| Support correspondence | Emails you send to hello@twirl.photos or privacy@twirl.photos and our replies | You |
| Technical and security data | IP address, browser and device type, pages requested, timestamps, error diagnostics, authentication events | Automatically, from your device |
| Email delivery data | Whether a message was delivered or bounced. We have deliberately turned off open tracking and click tracking on all our email, so we do not know whether you opened anything we sent you. | Brevo, our email provider |
6.2Why we process it, and on what legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and running your account, letting you log in | Account data | Art. 6(1)(b), performance of a contract |
| Providing the event page, uploads, RSVP and dashboard you paid for | Account data, event configuration | Art. 6(1)(b), performance of a contract |
| Taking payment, applying the correct VAT, issuing invoices | Billing and transaction data | Art. 6(1)(b) for the payment itself, and Art. 6(1)(c) for tax and invoicing obligations |
| Sending transactional and lifecycle email (payment receipts, window reminders, co-host invitations, deletion notices) | Account data, event configuration, email delivery data | Art. 6(1)(b). These are service messages, not marketing, and you cannot opt out of the ones that carry legally or practically necessary information such as an impending deletion. We keep delivery and bounce data because we need to know whether a deletion warning actually arrived. |
| Answering support requests | Support correspondence, account data | Art. 6(1)(b), and Art. 6(1)(f) where the request concerns someone other than you |
| Keeping the service secure, preventing abuse, rate limiting, detecting fraud | Technical and security data | Art. 6(1)(f), legitimate interest in operating a secure service |
| Diagnosing errors and crashes through Sentry | Technical and security data, limited error context | Art. 6(1)(f), legitimate interest in a working product. Media content is not sent to Sentry. |
| Keeping accounting records | Billing and transaction data | Art. 6(1)(c), Dutch tax law requires a seven year retention period |
| Establishing, exercising or defending legal claims | Whatever is relevant to the claim | Art. 6(1)(f), and Art. 6(1)(c) where disclosure is compelled |
| Optional product news or feature announcements, if we ever send them | Email address | Art. 6(1)(a), consent, given by a separate opt-in and withdrawable at any time |
Where we rely on legitimate interest, we have considered whether our interest is overridden by your rights and concluded that it is not, given the narrow scope of the data involved. You can object to any of that processing under section 14, and you can ask us for our reasoning.
6.3How long we keep it
| Data | Retention |
|---|---|
| Organizer account, where events still exist | For as long as the account is open |
| Organizer account, after you close it or after your last event is deleted | Deleted or irreversibly anonymised within 90 days, except for records we must keep under the rows below |
| Event configuration and guest list | Deleted with the event, per section 9 |
| Billing, invoice and transaction records | Seven years from the end of the financial year, as required by Dutch tax law |
| Support correspondence | 24 months from the last message in the thread |
| Security and access logs | 90 days, unless retained longer for a specific investigation |
| Error diagnostics in Sentry | 90 days |
| Email delivery and bounce records | 12 months |
07Website visitors
The public pages at twirl.photos are static. Reading them does not require you to accept anything, and we do not set advertising or analytics cookies on them. Our host records standard server request data, including IP addresses, for security and delivery. See the Cookie Policy for the full picture, including the position if we introduce privacy-preserving analytics later.
08Guest data, where we are the processor
This section is written for guests. If you were sent a link to a wedding gallery and you want to know what happens to your photographs, this is the part to read.
8.1The short answer
The couple hosting the event decides what happens to your content. We store it for them, we protect it, and we delete it when the event window ends. We do not sell it, publish it, or train anything on it. If you want it removed, section 8.6 tells you how.
8.2What is collected when you take part
| Category | Specifically |
|---|---|
| Media you upload | Photographs, videos and voice memos, at full resolution, including any embedded metadata the file carries (which for photographs commonly includes the time taken, camera model, and sometimes GPS coordinates) |
| Attribution | The name you type when you upload, if the organizer has enabled attribution. This is free text. Nothing verifies it and you are not obliged to use your legal name. |
| RSVP responses | Whether you are attending, plus-one details, and your answers to whatever custom questions the organizer set, which commonly include meal or dietary choices |
| Event access data | The fact that the event password was entered successfully, session information needed to keep you in the gallery, and technical data such as IP address and browser type |
| Content you flag | If you flag something as inappropriate, the fact of the flag and any reason you give |
8.3The people in the photographs
A photograph of a person is personal data about that person, not only about whoever pressed the shutter. That means a guest who uploads a group photograph is putting other people's personal data into the event, and those people have rights over it even though they never touched the app. The organizer is responsible for the lawfulness of that, as controller. We support it by making deletion straightforward, by giving the organizer moderation tools, and by acting on takedown requests that reach us. Section 8.6 applies to anyone depicted, not only to the person who uploaded.
8.4Dietary answers and other potentially sensitive responses
Most meal choices are not sensitive. Some are. "No pork" or "kosher" or "halal" can reveal religious belief, and a stated allergy can reveal health information. Both are special categories of personal data under Article 9 of the GDPR when they are used or understood that way.
We take the cautious position that RSVP dietary answers can fall into Article 9 and should be treated as such. The organizer, as controller, needs a valid Article 9 condition, which in this setting is normally explicit consent given freely by the guest when they answer the question. Guests are never required to answer a dietary question, and an organizer configuring one should make that clear. On our side we apply the same access controls to these answers as to everything else, and we do not use them for any purpose except showing them to the organizer.
8.5How long guest data is kept
Guest content lives and dies with the event window described in section 9. When the window ends and the organizer does not extend it, everything goes: media, RSVP responses, guest names. Nothing is quietly retained for our own purposes afterwards, and we do not keep a shadow copy for analytics.
8.6How to exercise your rights when you never had an account
You have the full set of GDPR rights listed in section 14 even though you never signed up for anything. Because the organizer is the controller, requests are usually resolved fastest by going to them directly, and they can delete a photograph from the dashboard in seconds. But you do not have to go through the couple, and we understand that there are situations where you would rather not.
Write to privacy@twirl.photos. Tell us which event you mean (the link, the couple's names, or the event code all work), what you uploaded or what you appear in, and what you want done. We will:
- Acknowledge within five working days.
- Because we act as processor, pass the request to the organizer without undue delay and support them in answering it, which is what Article 28(3)(e) requires of us.
- Act ourselves, without waiting, where the content is clearly unlawful, where it appears to have been uploaded without the consent of the person depicted, or where leaving it up risks harm. We do not need the organizer's permission to take down content of that kind, and section 4 of the Guest Terms reserves that right.
- Tell you what happened, and if we cannot help, tell you why and who can. We do not charge for this and we do not require you to prove your identity with formal documents unless the request is one where getting it wrong would itself cause harm, for example a request to hand over a copy of someone's data rather than delete it. Where we do need to verify, we will ask for the least we can get away with.
09Retention, the event window, and deletion
Twirl is deliberately not a permanent archive. The window model is the core of both our pricing and our privacy position, so here is exactly how it works.
- The base package opens a two month window, which starts running from the first upload rather than from purchase. Uploads and downloads are both open during it.
- The organizer can extend with a full extension, which keeps uploads and downloads open for a further month at a time, or a download-only extension, which closes uploads but keeps downloads open for a further month at a time. Extensions stack onto the existing end date rather than replacing it.
- Before the window ends, we email the organizer to say so, more than once, and the dashboard shows the date. At the end of the window the organizer has three paths, and one of them happens whether they act or not:
- Close now. The organizer confirms they have downloaded what they want, and we delete the event and all its media immediately.
- Let it lapse. The organizer does nothing. Deletion is scheduled and then carried out. The organizer is notified before this happens and can still extend or download until it does.
- Extend. A new payment pushes the end date out and nothing is deleted. Deletion means deletion. Media objects are removed from our storage provider and database records are removed. Encrypted backups may hold residual copies for a short period until they rotate out, and we do not restore deleted content from backup for any purpose other than recovering from a failure that affected live data. Residual copies persist for no more than 30 days, after which the backups holding them have rotated out entirely.
We do not describe this lifecycle on our marketing pages, because we would rather explain it properly at the point where it matters than compress it into a sales bullet. It is shown in the app before purchase and throughout the event.
10Children
Twirl is sold to adults and is not directed at children. We do not knowingly allow anyone under 16 to create an organizer account, and organizers confirm they are 18 or older in the Terms of Service.
That is the easy part. The harder part is that children are at weddings, and photographs of children will end up in events. We think it is more useful to address that than to pretend a wedding gallery is an adults-only environment.
- A photograph of a child is that child's personal data. The organizer, as controller, is responsible for the basis on which it is collected and shown, which in a private family setting normally rests on the consent or the exercise of parental responsibility of the child's parent or guardian.
- The Netherlands sets the digital consent age at 16 under Article 8 of the GDPR. Other member states set it lower. Where consent is the basis and the child is under the applicable age, it must come from the person holding parental responsibility.
- Galleries are password protected and not indexed by search engines. They are private by default, not public by default, which materially reduces the exposure involved.
- A parent or guardian who wants a photograph of their child removed should use section 8.6. We treat these requests as high priority and we will act on them ourselves rather than waiting for the organizer where there is any doubt.
- We do not run facial recognition, biometric matching or age estimation on uploaded content. If we ever build a feature that would, it will be assessed and disclosed before it ships, not after.
11Sharing, and who else touches the data
We share personal data with the service providers we need to run Twirl, and with nobody else except where the law compels us.
Each of these providers acts as our subprocessor under a written agreement that meets Article 28 of the GDPR, and each is bound to process data only on our instructions. The current list is published and maintained at where your photos live, which is the authoritative version. The table below summarises it at the time of writing.
| Provider | What it does | Where |
|---|---|---|
| Vercel | Application hosting and content delivery | EU regions, with a US parent company |
| Supabase | Database and organizer authentication | EU, Germany |
| Our storage provider | Object storage for photographs, videos and voice memos. Currently OVHcloud. See the subprocessor list for the current provider and region. | EU, Germany (Frankfurt) |
| Stripe | Payment processing, VAT calculation, invoicing | EU and US |
| Brevo | Transactional and lifecycle email | EU, France |
| Sentry | Error and crash diagnostics. Receives technical error context, never media content. | EU region where available, see the subprocessor list |
Your photographs and your event data are both in Germany. Media sits with OVHcloud in Frankfurt, and the database sits with Supabase in Frankfurt. One country, inside the EU, with no adequacy decision or transfer mechanism needed for either.
We name the storage provider here for clarity, but the subprocessor list is the authoritative version. If we ever move, that page changes first and this one follows. We would rather point you at a page we keep current than at a sentence that quietly goes stale.
Beyond subprocessors, we may disclose personal data to professional advisers under confidentiality, to authorities where we are legally required to and after checking that the request is valid, and to an acquirer if the business is sold, in which case we will notify organizers before any transfer of their data and this policy will continue to apply until replaced by one no less protective.
12International transfers
Our default is that data stays in the European Economic Area. Some of it does not, and here is the basis for each case.
Media storage and the database are both in Frankfurt, Germany. Neither involves a transfer outside the EEA and neither needs a transfer mechanism. The cases below are the remainder.
| Situation | Transfer basis |
|---|---|
| Media storage (OVHcloud) and database (Supabase) | EU, Germany. No transfer outside the EEA. No mechanism required. |
| Brevo, for email | French company, EU infrastructure. No transfer outside the EEA in normal operation. |
| US-parented providers running in EU regions (Vercel, Sentry) | Data is held in EU regions. Where any access from the US occurs, we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented by the provider's certification under the EU-US Data Privacy Framework where they hold one. |
| Stripe | Stripe Payments Europe Ltd is the contracting entity for European customers. Onward transfers to Stripe entities outside the EEA rely on Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. |
| UK customers | Transfers from the UK rely on the UK International Data Transfer Addendum to the Standard Contractual Clauses, or on UK adequacy regulations where they exist for the destination. |
You can ask us for a copy of the relevant transfer mechanism by writing to privacy@twirl.photos. We may redact commercial terms.
13Security
The measures below are the ones in place. This is a summary rather than a complete description, because a complete description of security measures is itself a security risk. Annex 2 of our Data Processing Agreement carries the fuller version for organizers who need it.
- All traffic is encrypted in transit using TLS. Stored media and database contents are encrypted at rest by our providers.
- Organizer passwords are hashed. We never see them and cannot recover them.
- Event galleries are protected by a password the organizer sets, are not publicly listed, and are excluded from search engine indexing.
- Media is served through time-limited signed links rather than permanently public URLs.
- Database access is restricted by row-level security policies so that an event's data is reachable only in the context of that event.
- Access to production systems is limited to the founders, protected by multi-factor authentication, and used for operations rather than routine browsing of customer content.
- We use an error tracking service that receives technical diagnostics and is configured not to receive media content.
- We keep dependencies patched and monitor for known vulnerabilities. No system is perfectly secure and we are not going to claim otherwise. If a personal data breach occurs affecting organizer data where we are controller, we will notify the Autoriteit Persoonsgegevens within 72 hours where the breach is likely to result in a risk to people's rights, and we will notify affected people directly where the risk is high. Where the breach affects guest data and we are processor, we will notify the organizer without undue delay so that they can meet their own obligations, and we will help them do it.
14Your rights
If you are in the EEA or the UK, you have the following rights. They apply to organizers and guests alike, although for guest data the organizer is the controller and we will normally route your request to them, as explained in section 8.6.
| Right | What it means in practice |
|---|---|
| Access (Art. 15) | Ask what personal data we hold about you and get a copy of it. |
| Rectification (Art. 16) | Correct data that is wrong or incomplete. Organizers can edit most of this themselves in the dashboard. |
| Erasure (Art. 17) | Ask for your data to be deleted. For event media this is usually immediate. We may keep billing records where tax law requires it. |
| Restriction (Art. 18) | Ask us to stop processing while a dispute about accuracy or legitimate interest is resolved. |
| Portability (Art. 20) | Get the data you gave us in a structured, machine readable format. Organizers can export guest lists and RSVP data as a spreadsheet and download all media in bulk at any time during the window, without asking us. |
| Objection (Art. 21) | Object to processing based on legitimate interest. We will stop unless we have compelling grounds that override your interests. |
| Withdraw consent (Art. 7(3)) | Where we relied on consent, withdraw it at any time. This does not affect processing that already happened. |
| Not to be subject to automated decision making (Art. 22) | We do not make decisions with legal or similarly significant effects by automated means. Our content flagging system counts flags and alerts a human. It does not decide anything on its own. |
To exercise any of these, write to privacy@twirl.photos. We respond within one month, and we will tell you if we need to extend that by up to two further months because a request is complex, which is rare. There is no charge unless a request is manifestly unfounded or excessive, which we have never yet had to invoke and hope never to.
If you are unhappy with how we have handled something, we would like the chance to fix it first. But you do not have to come to us. You can complain directly to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live or work. UK residents can complain to the Information Commissioner's Office (ico.org.uk).
15Cookies and similar technologies
Inside the product, meaning organizer dashboards and guest event pages, we use only strictly necessary cookies. No analytics, no advertising, no behavioural tracking. We have also turned off open and click tracking on our email.
On the public marketing pages at twirl.photos we count visits, because otherwise we have no way of knowing whether anything we write is useful. The tool we use sets no cookies, stores nothing on your device and does not identify you, which is why you have not been shown a consent banner. The Cookie Policy names it and says exactly what it collects.
16If you are outside the EU
16.1United Kingdom
The UK GDPR and the Data Protection Act 2018 apply to UK users. Your rights are materially the same as those in section 14, and your supervisory authority is the Information Commissioner's Office.
16.2California and other US states
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not process it for cross-context behavioural advertising. California residents have rights to know, delete, correct and to non-discrimination for exercising them. Use privacy@twirl.photos, the same as everyone else. Comparable rights under other US state privacy laws are honoured on the same basis.
16.3Canada
For users in Canada, we handle personal information consistently with PIPEDA principles. The rights in section 14 are available to you.
17Changes to this policy
We will update this policy when the service changes, when our subprocessors change in a way that affects you, or when the law does. The version and date are at the top. If a change materially affects organizers, we will email them before it takes effect rather than relying on them noticing. Routine changes to the subprocessor list are handled through the notice mechanism in the Data Processing Agreement rather than through a change to this document.
18Contact
Privacy questions, rights requests and takedown requests: privacy@twirl.photos
Everything else: hello@twirl.photos
By post: Ciceroni VOF, Franklinstraat 161, 2562 CD Den Haag, the Netherlands.
We have not appointed a Data Protection Officer, because we do not believe Article 37 requires one at our scale and we do not carry out large scale monitoring or large scale processing of special category data as a core activity. The address above is the contact point for all data protection matters and reaches a founder directly, not a ticket queue. If our processing changes such that a DPO becomes required, we will appoint one and say so here.
