Biometric data retention and destruction
Last updated 11 September 2026
This policy explains what face data we collect when you sign up to get your photos from an event, why we collect it, how long we keep it, and when we destroy it. It applies to every guest who signs up through an event link or QR code. It is published here so you can read it before you decide to hand anything over.
It is written in plain English on purpose. Where something is uncertain or on a different schedule, we say so rather than smoothing it over.
1. What we collect
When you sign up, you take one selfie. From that selfie, Amazon Rekognition derives a face template — a set of numbers describing the geometry of your face. The template, not the picture, is what photographs are matched against. Both are biometric data and both are covered by this policy.
We keep two things: the selfie, in private cloud storage, and the face template, in a face collection belonging to that one event.
We also collect your name and email address. Those are not biometric data — we use them to know who you are and to send you your photos. We collect a mobile number only if you tick the optional text-message box when you sign up. If you do, we use it for one thing: telling you about your place in line and letting you know when your photos are ready. It is never sold, and never shared for third-party marketing. The number is never required to sign up, to join the line, or to receive your photos — those all work on your email address and your gallery link alone. If you leave the field blank we hold no number for you; if you fill it in without ticking the box, we keep it as a contact detail and do not text you.
2. Why we collect it
Solely to find you in the photographs taken at the event you signed up for, and to deliver those photographs to you. Nothing else.
Your face template is held in a collection that contains only that event's guests, and it is only ever compared against that event's photographs. It is not compared against other events, not used to identify you anywhere else, not sold, and not shared for advertising or any other purpose.
3. How long we keep it — 30 days
We destroy your biometric data no later than 30 days after you sign up for an event. That covers both the face template held by Amazon Rekognition and the selfie you took.
Once it is destroyed, no further matching is possible — you would have to sign up again to be matched to anything new.
You can ask us to destroy it sooner, and we will. Ask the host who gave you your link and they will reach us.
4. Your photographs are on a separate clock
This is the part most easily misread, so to be explicit: the 30-day term above is about your face data, not about the photographs.
The event photographs, and your access to the gallery, are the deliverable the host paid for. We keep them, and keep the gallery open, until the host asks us to remove them. That is the host's call, and it is not this 30-day term.
So: destroying your face data stops any further matching, but it does not delete the event photographs you already appear in, and it does not withdraw photos already delivered to you. If you want a particular photograph taken down, that is the host's decision — contact them.
5. Who else receives it — Amazon Web Services
We run on Amazon Web Services (AWS), in the United States. AWS is our processor: it handles this data on our instructions, for us. Three AWS services are involved and they are not interchangeable, so we name them separately rather than saying “AWS” and leaving it there.
Amazon S3 — storage
Holds your selfie and the event photographs in a private bucket. Not readable without our credentials.
Amazon Rekognition — the face engine
Receives your selfie and the event photographs, derives the face templates, and performs the matching. This is the only service that handles biometric data. Rekognition stores the face vectors and returns only opaque identifiers to us.
Our AWS account carries an organisation-level AI-services opt-out that covers Rekognition, so the images we send it are not used to develop or improve AWS services.
Amazon Bedrock (Nova Multimodal Embeddings) — photo search
Powers searching a gallery in words (“the cake”, “the toast”). It receives event photographs only. It never receives your selfie and never receives your face template.
The AI-services opt-out described above does not cover Bedrock. Our use of Bedrock rests instead on our contractual terms with AWS and on pinning those requests to a United States region. We state this plainly because treating “AWS” as one undifferentiated whole would misdescribe the controls actually in place. Note again that the data at stake here is photographs, not face templates.
6. Contact
Questions about this policy, or a request to have your data destroyed early: contact the host who gave you your link — they can reach us directly.
sendadm — face-sorted event photo delivery.