arrow_backBack to Home
gavelPrivacy Policy

Privacy Policy

Last updated: 7 June 2026

This Privacy Policy explains how Cristo Pliakas, a self-employed individual (freelancer)("we", "us", "I"), collects, uses and protects personal data when you use Instants at instants.pliakas.dev(the "Service"). Personal data is processed in accordance with the EU General Data Protection Regulation (GDPR).
1

Who is responsible (Data Controller)

The Service is operated by Cristo Pliakas, a self-employed individual (freelancer) based in Spain. As an individual provider, the identification details are:

  • Name: Cristo Pliakas
  • Tax ID (NIF/DNI): [YOUR NIF / DNI]
  • Address: [YOUR ADDRESS]
  • Email: cristo@pliakas.dev
2

Data we collect

Depending on how you use the Service, we may process:

  • Account data (hosts): email address and an encrypted password, or your name and email if you sign in with Google or Apple.
  • Event data (hosts): the event name, optional date and description, and plan settings you choose.
  • Photos: images taken by guests through the in-browser camera, stored for the event.
  • Guest data: an optional display name and a randomly generated device identifier stored locally on the guest's device.
  • Payment data: when you purchase a plan, payment is processed by Stripe. We do not store your card details — only a payment reference.
  • Technical data: IP address and basic request metadata used for security (bot protection) and to operate the Service.
3

How and why we use your data

We process personal data on the following legal bases:

  • To provide the Service (performance of a contract): creating events, storing and displaying photos, managing accounts.
  • To process payments (performance of a contract): handling plan purchases and upgrades via Stripe.
  • Security and fraud prevention (legitimate interests): bot protection via Cloudflare Turnstile and rate limiting.
  • Legal compliance: retaining transaction records where required by law.
4

Service providers (processors)

We share data with trusted providers strictly to run the Service:

  • Supabase — authentication and database hosting.
  • Cloudflare R2 — private photo storage.
  • Cloudflare Turnstile — bot protection.
  • Stripe — payment processing.
  • Google / Apple — optional single sign-on, if you choose it.

These providers act as our processors and only handle data on our instructions. Some may process data outside the EU under appropriate safeguards (e.g. Standard Contractual Clauses).

5

Photo visibility

Photos are stored privately and are never publicly accessible by URL. Within an event, a guest can only see the photos they took themselves; the event host can see all photos from their event. Anyone with the 6-character event code can join an event and add photos.

6

Data retention

We keep event and photo data for as long as your account or event exists. Hosts can delete individual photos or an entire event at any time, which permanently removes the associated images and metadata. Account data is retained until you ask us to delete your account. Payment records may be retained longer where required by law.

7

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time. To exercise any of these rights, contact cristo@pliakas.dev. You also have the right to lodge a complaint with your local data protection authority.

8

Cookies

We use a small number of essential and functional cookies. See our Cookie Policy for details.

9

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the latest version. Significant changes will be communicated through the Service.