Last updated 10 September 2026
Privacy policy.
hazel is run by [Company legal name] Ltd, [Registered address], company number [Company number], registered with the UK Information Commissioner's Office as [ICO registration number]. This policy says what we collect, why, how long we keep it, and what you can ask us to do. It is written to be read.
1. What we collect, and from whom
If you host a gathering: your name, email address and password (stored hashed), or your Google account details if you sign in that way; the gatherings you create, including the name, dates, type, cover photo, welcome message and, for business gatherings, your business name and logo; and your payment history. Card details never reach us; Stripe handles them.
If you join a gathering as a guest: your first name and email address, the photos and video clips you choose to add, the consent wording you agreed to and when, and a cookie so you don't have to log in again for 90 days.
Photos. When a photo arrives we remove the hidden data cameras add to it, such as where it was taken and on which device, from every copy we keep. A full-size copy is stored privately so the host can download it; a smaller copy is what appears in the Album.
Automatically: the pages you visit and the rough performance of the site, measured without cookies (see the Cookie Policy). We do not record your IP address against your account.
What we do not do: we do not use facial recognition, we do not analyse who is in a photo, we do not build profiles, and we do not sell or rent any of this to anyone. We do not use your photos in hazel's own marketing unless we have asked you first and you have said yes.
2. Why we use it, and the legal basis
- To run the service you asked for (contract): creating gatherings, letting guests join and add photos, building and sharing the Album, taking payment, sending the emails that are part of it, such as the invite, the Album link, the log-back-in code and the reminders before photos are deleted.
- Because you agreed (consent): when you join a gathering you tick a box saying your photos can go into that gathering's Album and be shared with the other guests. For a business gathering the wording also says the business may use your photos in its own marketing. We keep a record of the exact wording you agreed to. You can withdraw consent at any time by asking us to remove your photos.
- To keep the service safe and working (legitimate interests): bot protection on forms, security logs, rate limits, the counter that tracks how many photos you have added, and checking uploads against lists of known illegal images (see section 6).
- Because the law says so (legal obligation): keeping payment records for tax, and reporting illegal content to the authorities.
We do not send marketing email. Every email we send is part of running a gathering you host or joined.
3. Who can see what
Photos you add go to the host first. Nobody else sees them until the host chooses what makes the Album and shares it. Your first name appears on each of your photos in the Album, so people know who took what. Your email address is never shown to other guests.
When an Album is shared, anyone with the link can open it. That is how a host passes it on to people who could not be there. For a business gathering marked private, no Album is shared: the photos go to the business only.
A host can see the first names and email addresses of the guests who joined their gathering, and can download the photos.
4. How long we keep things
Photos and Albums: one year from the day uploads closed. We email the host 30, 7 and 1 days before, and guests once, 7 days before, so everyone can save what they want. The host can keep a gathering for another year with a one-off payment. Otherwise the Album goes offline on the date, the files are kept for 14 more days in case the host changes their mind, and then they are permanently deleted. A record that the gathering existed, with its name and dates, stays on the host's account; guest email addresses are removed from it at the same time as the photos.
Guest records: deleted with the gathering, as above.
Host accounts: until you delete the account from your settings, or ask us to. Payment records are kept for six years because tax law requires it.
Support messages: two years, so we can follow up on a reference.
5. Where it lives, and who helps us
We keep data in the UK and the EU. These companies process it for us under written data processing agreements, and none of them may use it for their own purposes:
- Cloudflare: photo and video storage, bot protection on forms, and the illegal-image check in section 6.
- Supabase: the database and host sign-in, hosted in London.
- Vercel: runs the website.
- Resend: sends our emails.
- Stripe: takes payments and issues invoices. Stripe is a controller in its own right for the payment itself.
- Google: only if you choose to sign in with Google.
Resend and Stripe move some data to the United States. They do so under the UK and EU standard contractual clauses in their agreements with us.
6. Illegal images
Every upload is checked against lists of digital fingerprints of known child sexual abuse images held by the National Center for Missing and Exploited Children and the Internet Watch Foundation. This check cannot see or interpret a photo; it only recognises files already known to the authorities. A match is blocked, preserved as the law requires, and reported. We do no other automated analysis of photos.
Every photo in a shared Album has a Report button. A reported photo is hidden immediately, a person at hazel reviews it, usually the same day, and the host is told what was decided.
7. Children
You must be 16 or over to create a host account. Guests joining a gathering give only a first name and an email. Hosts are responsible for the gatherings they run and the people they invite. If you are a parent or guardian and want photos of your child removed from a gathering, tell us through the contact form and we will remove them.
8. Your rights
You can ask us to show you the personal data we hold about you, correct it, delete it, give you a copy, or stop using it, and you can withdraw consent you gave. Guests can remove their own photos from a gathering while uploads are open. After that, and for anything else, write to us through the contact form with your reference; we answer within a month, usually much faster. Hosts can delete their account from their settings.
If you think we have got something wrong you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first.
9. Security
Connections are encrypted. Passwords are stored hashed. Guests are identified by a signed cookie, and every request checks the photos and gathering belong to that guest. Originals sit in a private store that only the host's download can reach. If a breach ever affects your data we will tell the ICO within 72 hours and you without undue delay.
10. Changes to this policy
If we change anything that matters we will say so on this page, with the date at the top, and email hosts if the change affects them. Older versions are available on request.
Questions about any of this? Use the contact form and a person replies.