This Privacy Policy explains how ClopudBooth handles information when people attend a CloudBooth-powered event or when organisations and individuals use the CloudBooth platform.
1. People attending a CloudBooth event
The organisation operating an event decides what information it asks a guest to provide and the purpose for collecting it. Depending on the event configuration, CloudBooth may process:
- Photographs, videos and other media created during a booth session, together with storage identifiers and timestamps.
- Event, booth and session identifiers needed to associate captures and interactions with the correct event.
- Email address and/or mobile number when a guest enters them for photo delivery or another disclosed purpose.
- Answers to custom input fields configured by the organisation. Custom input fields can contain other personal information selected by that organisation.
- Consent and checkbox choices recorded by the event, including marketing permissions where configured.
- Delivery status and operational metadata required to send email/SMS, generate a secure gallery, or troubleshoot the guest experience.
- Limited technical and security information such as request identifiers, IP/network information and browser/device details where needed for security, reliability or abuse prevention.
Marketing: organisations using CloudBooth must clearly tell attendees when personal information will be used for marketing and provide required consent and communication opt-out choices. Concerns can be raised with the event organiser and with [email protected].
2. Organisations and individuals using the CloudBooth platform
For account holders, administrators, staff and other platform users, CloudBooth may process:
- Name, login/email address, phone number, profile image and notification preferences.
- Organisation/workspace membership, assigned roles and permissions, and account activity.
- Password hashes rather than plain-text passwords, MFA records, encrypted authenticator secrets, passkey/WebAuthn identifiers, sessions and authentication-security records.
- Billing contact information, plan/subscription state, invoice/transaction metadata and payment-provider identifiers. Complete card numbers and card security codes are handled by the configured payment provider rather than stored as CloudBooth application fields.
- API-key metadata and hashes, booth/device pairing identifiers, saved designs/templates/events and workspace settings.
- Audit/security logs, request/reference IDs, timestamps, IP/network information, user-agent/browser details, application telemetry and feature usage required to secure, support and operate the service.
- Error Diagnostics for signed-in platform users, including support reference, page path, release version and bounded error/console context. Diagnostic collection is designed to exclude cookies, request bodies, authorisation headers and obvious secret/token fields.
3. How information is used
- Operate workspaces, events, booth sessions, templates, galleries, media capture and delivery.
- Authenticate users, enforce tenant/role permissions and protect accounts.
- Process subscriptions, usage, communication credits and invoices.
- Deliver service, security, lifecycle, event email and SMS communications.
- Diagnose faults, investigate support references and improve reliability.
- Prevent misuse, comply with legal obligations and enforce applicable agreements.
4. Roles and responsibilities
The organisation operating an event normally determines the purpose of guest data collection. It is responsible for choosing appropriate fields, providing accurate notices, obtaining required consent, honouring opt-outs and responding to guest privacy requests. CloudBooth provides the platform and supporting tools but does not remove those responsibilities.
5. Service providers and disclosures
Information may be provided to infrastructure hosting, private object storage, email, SMS, payment, security/monitoring and support providers only as needed to operate the service. Information may also be disclosed where required by law, to protect safety/security, or as part of a lawful business transaction. We do not sell personal information for third-party advertising.
6. Storage, processing location and media privacy
CloudBooth stores event images in private Cloudflare object storage. Media objects are authenticated and are not exposed as public bucket objects; access is provided through controlled application and signed-media paths. Cloudflare may place and serve infrastructure close to users according to its platform capabilities and the configured storage location. Where a customer has specific data-residency requirements, CloudBooth can assist with supported regional storage/processing arrangements. Enterprise customers may also request an on-premises storage or deployment architecture, subject to technical and contractual assessment.
7. Retention and deletion
Information is retained for as long as needed to provide the service and meet contractual, legal, security, dispute-resolution and audit requirements. Organisations can manage event and gallery material subject to configured retention rules, backups and legal obligations. Privacy deletion of a guest record removes identifying guest fields from the active record while required non-identifying operational or audit evidence may be retained.
8. Security
CloudBooth uses tenant boundaries, role-based access control, signed sessions, authentication and step-up controls, encryption for designated secrets, private media storage, signed-media delivery, audit records and operational monitoring. No service can guarantee absolute security; users should protect credentials and report suspected incidents promptly.
9. Access, correction, deletion and communication choices
Depending on applicable law, individuals may have rights to request access, correction or deletion, or to object to certain uses. Event attendees should normally contact the organisation responsible for the event because that organisation selected the guest fields and purpose. Platform users can update many account details directly and can contact support for additional requests.
10. International privacy requirements
Privacy requirements vary by jurisdiction. CloudBooth and the responsible organisation should apply the rules relevant to the people and operations involved, including appropriate contractual or cross-border safeguards where required. Customers with regulated or sovereign workloads should discuss their residency, support-access and deployment requirements before production use.
11. Contact
Privacy, data-access and deletion questions can be sent to [email protected]. Event attendees should include the event/organisation name and enough information for the responsible organisation to identify the relevant session without sending unnecessary sensitive information.