Skip to content

Legal

Privacy Policy

What we collect when you and your guests use ShareTheDay, why we hold it, how long we keep it, and how to get it back or have it erased.

Last updated

01Introduction

Share the Day ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This policy explains how we collect, use, disclose and safeguard your information when you use the Service.

By using Share the Day you consent to the data practices described here.

02Information we collect

Personal information

Information you give us directly:

  • Account information (name, email address, password)
  • Profile information and preferences
  • Event details and RSVP information
  • Payment information, processed securely through Stripe
  • Communications with our support team

Content and media

  • Photos, videos and audio recordings uploaded to memory links
  • Text messages and comments
  • Event customisation data (themes, colours, text)

Technical information

  • Device information (browser type, operating system)
  • Usage data (pages visited, features used, time spent)
  • IP address and general location information
  • Cookies and similar tracking technologies

03How we use your information

We use your information to:

  • Provide and maintain the Service
  • Process payments and manage your account
  • Send service-related communications
  • Improve the Service and develop new features
  • Ensure security and prevent fraud
  • Comply with legal obligations
  • Respond to support requests and customer inquiries

04Information sharing and disclosure

We do not sell, trade or otherwise transfer your personal information to third parties, except in the following circumstances:

  • With your explicit consent
  • To service providers who help us operate the Service, such as Stripe for payments and our cloud storage provider for media
  • When required by law, or to protect our rights and safety
  • In connection with a business transfer or acquisition

All third-party providers are contractually bound to protect your information and use it only for the purposes we specify.

05Data security

We apply technical and organisational measures appropriate to the sensitivity of what you store with us:

  • Encryption of data in transit and at rest
  • Payment processing handled entirely by Stripe, so card details never reach our servers
  • Regular security assessments and updates
  • Access controls and authentication
  • Staff training on data protection practices

No method of transmission over the internet is completely secure, and we do not claim otherwise.

06Data retention

We keep information for as long as it is needed to run the Service and meet the purposes set out above:

  • Account information: until you delete your account or ask us to
  • Memory content: for as long as the memory link remains active
  • Payment records: seven years, for tax and legal compliance
  • Usage logs: twelve months

07Your rights and choices

Depending on where you live, you may have the following rights over your personal information:

  • Access: ask what personal data we hold about you
  • Correction: ask us to fix information that is wrong or incomplete
  • Deletion: ask us to erase your personal information
  • Portability: ask for a copy in a machine-readable format
  • Objection: object to certain kinds of processing
  • Restriction: ask us to restrict processing in certain circumstances

08Cookies and tracking technologies

We use cookies and similar technologies to:

  • Remember your preferences and settings
  • Keep you signed in to your account
  • Analyse usage patterns and improve the Service
  • Provide a personalised experience

You can control cookies through your browser settings, though disabling them may affect how the Service works. Our Cookies Policy has the detail.

09Third-party services

The Service relies on third parties that have their own privacy policies:

  • Stripe, for payment processing
  • Our cloud hosting and object storage provider, for the application and uploaded media
  • Google Analytics, for aggregate usage measurement

We encourage you to review their policies as well as ours.

10International data transfers

Your information may be transferred to and processed in countries other than the one you live in. Where that happens we ensure appropriate safeguards are in place.

11Children's privacy

The Service is not intended for children under 13, and we do not knowingly collect personal information from them. If we become aware that we have, we delete it.

12California privacy rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act:

  • The right to know what personal information is collected
  • The right to have personal information deleted
  • The right to opt out of the sale of personal information — we do not sell it
  • The right not to be treated differently for exercising these rights

13European data protection (GDPR)

If you are in the European Economic Area, the General Data Protection Regulation gives you the right to:

  • Be told the lawful basis on which we process your data
  • Access, rectify or erase your data
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent at any time
  • Lodge a complaint with your supervisory authority

14Changes to this policy

We may update this policy from time to time. Changes are published on this page and the "Last updated" date above changes with them.

Continuing to use the Service after a change means you accept the updated policy.

15Contact us

If you have questions about this policy or about how we handle data, write to us. We respond within 30 days.