Legal

Privacy Policy

What we collect, why, who processes it, how long we keep it, and the rights you have over it.

Last updated 3 October 2026

Privacy Policy Terms of Service Refund & Cancellation Cookie Policy
On this page
  1. Who we are
  2. Applicable law
  3. Our role
  4. Information we collect
  5. How face search works
  6. How we use information
  7. Consent
  8. Service providers
  9. Where data is stored
  10. Retention and deletion
  11. Children
  12. Your rights
  13. Cookies and browser storage
  14. Security
  15. Data breaches
  16. Third-party websites
  17. Communications
  18. Changes to this policy
  19. Grievance Officer and contact

In short

  • Guests never give us a name, email, phone number or password.
  • A guest’s selfie is used for one search and then discarded. We don’t save it.
  • Face data from event photos is used only to find photos within that one event, and is deleted with the event.
  • We don’t sell personal data, and we don’t use photos, selfies or face data to train AI models.

1. Who we are

SnapTrace (“SnapTrace”, “we”, “us”, “our”) is a product of UNIT3A, a sole proprietorship owned by Raguram and based in India.

SnapTrace lets photographers and photography studios upload event photos, and lets guests at those events find the photos they appear in by taking a selfie. This policy covers our website, the photographer dashboard, the SnapTrace Camera Agent desktop app, event photo galleries, and the face-search feature (together, the “Services”). We currently provide the Services in India.

Business address
7/31 Railway Feeder Road, Keelakadayam 627415, Tirunelveli, Tamil Nadu, India
Email
unit3a.official@gmail.com

By using the Services, you confirm that you have read and understood this policy.

2. Applicable law

We handle personal data in line with the privacy and data-protection laws of India, including, where they apply:

  • the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
  • the Digital Personal Data Protection Rules, 2025;
  • the Information Technology Act, 2000;
  • the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and
  • the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Nothing in this policy limits any right or protection you have under applicable law.

3. Our role

For photographer and studio accounts, billing, and our website, we decide why and how personal data is processed, so we act as a Data Fiduciary under the DPDP Act.

For event photos, the studio chooses to photograph the event and upload the photos, and decides whether guests can preview and download them. We process those photos to provide the Services to the studio. Our specific responsibilities depend on the nature of the processing and on our agreement with the studio. For guest face search, we collect the guest’s consent ourselves before any face data is processed.

4. Information we collect

4.1 Photographers and studios

  • Account details: your name, email address, studio or business name, and, if you give it, your phone number. If you sign in with Google, we receive your name, email address and account identifier from Google.
  • Studio profile and branding: your logo, watermark settings, and preferences.
  • Event details: event names, dates, itineraries, featured photos, and gallery settings.
  • Billing records: the plan or vouchers you bought, order and payment IDs, amounts, dates, payment status and subscription status. We never receive or store card numbers, UPI PINs, or banking passwords. Our payment provider handles those.
  • Camera Agent pairing: a one-time setup code and an access token that links the desktop app to your studio.
  • Support messages: anything you send us by email or the contact form.

4.2 Event photos

Studios upload photos through the Camera Agent or the dashboard. Photos can show identifiable people, so they may contain personal data. Before upload, the Camera Agent makes a compressed full-size copy and a smaller preview copy on the photographer’s computer. It also checks each photo on that computer for faces and near-duplicates. Photos with no detectable face, and repeat shots of the same moment, are still stored, but aren’t sent for face indexing. Photos that do have faces are indexed as described in Section 5.

4.3 Guests

Guests don’t create an account, and we never ask for a guest’s name, email, phone number or OTP. A shorter Guest Privacy Notice explains this part for guests. When a guest uses an event gallery, we process only:

  • A consent record: the time the guest agreed, the event, a random session ID, and, where available, a one-way hash of the selfie (a code that can’t be turned back into the image).
  • The selfie: used for one search, then discarded. We don’t save the selfie or a face template made from it.
  • Search results: the list of matched photo IDs, and the IDs of the event-photo faces that matched best. They are kept against the session ID so a returning guest sees their photos, and any new ones, without another selfie.
  • A rate-limit counter: how many searches the session has made recently, to prevent misuse.

Where a guest makes a reel or collage from their photos, it is built entirely on the guest’s own device from photos they can already see. It isn’t uploaded to us, and we don’t receive or keep it.

4.4 Website visitors

If you use our contact form, we receive your name, email address and message.

4.5 Technical information

When you use the Services, our systems record standard technical data: IP address, browser and device type, pages and features used, dates and times, and error and security logs. We use this to run, secure and troubleshoot the Services.

5. How face search works

  1. A studio uploads event photos. For each photo with a face, our face-recognition provider creates a face template: a set of numbers describing facial features. It isn’t an image. The template is stored in a collection that belongs to that one event only.
  2. A guest scans the event’s QR code, reads the notice, and taps to agree. Nothing is searched until that consent is recorded.
  3. The guest takes a selfie. It is compared only against the face templates for that event, never against other events, other studios, or any outside database.
  4. The selfie is discarded after the search. The guest sees thumbnails of the matched photos.
  5. When the guest returns, new photos from the event are checked using the face template from a photo the guest already matched, so no new selfie is needed.

Face templates are biometric data, and we treat them with extra care. We use them only to show guests their photos from that event. We don’t use them for identification, advertising, profiling, or training any AI model. They are deleted with the event (see Section 10).

Face matching is automated and isn’t perfect. It can miss a photo or, occasionally, show a photo of someone who looks similar.

6. How we use information

  • To run the Services: accounts and sign-in, event creation, photo upload and storage, galleries, QR codes, face search, previews and downloads.
  • To process payments, manage vouchers, subscriptions and top-ups, and keep billing records.
  • To provide support and send service messages.
  • To prevent fraud, misuse and security incidents, including rate-limiting searches.
  • To understand our costs and keep the Services working and improving.
  • To comply with legal obligations, resolve disputes, and enforce our Terms of Service.

We don’t sell personal data or share it with third parties for their own marketing.

7. Consent

We process a guest’s selfie and search face templates only after the guest gives clear consent in the gallery. If a guest doesn’t agree, face search doesn’t start.

We process studio account and billing data to provide the Services the studio signed up for, and to meet our legal obligations.

You can withdraw consent at any time (see Section 12). Withdrawing doesn’t affect processing that happened before. It may mean we can’t offer face search to you.

8. Service providers

We use trusted service providers to run the Services. They process personal data only on our instructions and only for the purposes below. They are bound by contract to keep it secure and confidential, and they may not use it for their own purposes, including advertising or training AI models.

Type of providerWhat it does for usData involved
Cloud hosting and database providerDatabase, sign-in, backend processing, and website hostingStudio accounts, event and billing records, consent records, logs
Photo storage and delivery providerStores event photos and delivers them quickly to guestsEvent photos, previews, logos, featured photos
Face-recognition service providerCreates face templates from event photos and runs guest searchesFace templates from event photos; guest selfies during a search
RBI-authorised payment gatewayPayments, subscriptions and refundsOrder details, amount, payment status. Card, UPI and bank details go directly to the gateway and never reach us.
Website service providersDeliver contact-form messages, and load fonts and scripts on our websiteName, email and message (contact form); IP address and browser details (page loading)

A list of our current service providers is available on request from our Grievance Officer (Section 19).

We may also disclose information if required by law, court order, or a government authority, or where needed to protect the rights, safety or property of our users, the public, or UNIT3A.

9. Where data is stored

Our database, backend processing and face recognition run on servers in India. To load photos quickly, our photo delivery provider may serve cached copies from servers outside India. Website service providers may also process data in other countries. Where data is processed outside India, we follow the transfer requirements of Indian law.

10. Retention and deletion

We keep personal data only as long as we need it. Event data is deleted automatically: the clock starts at an event’s last photo upload, so late guests and a photographer’s final batch aren’t cut off.

DataHow long we keep it
Guest selfieNot stored. Discarded as soon as the search finishes.
Event photos, face templates, guest consent records and search results Deleted after the event’s retention period, counted from the last upload:
  • Free trial, Essential, Classic: 5 days
  • Premium: 7 days
  • Signature: 10 days
  • Legacy: 14 days
Events on a monthly plan follow the tier the plan is named after (for example, Monthly Premium: 7 days).
Studio account and profileWhile the account is active. Deleting your account from Settings erases it straight away; a request by email is completed within 30 days. Either way, we keep only what the law requires, such as billing records, plus a one-way fingerprint of the account’s email and Google account so the free trial event can’t be claimed again by signing up afresh.
Billing and tax recordsFor as long as tax and accounting laws require.
Support and contact messagesAs long as needed to resolve the request, then up to 12 months.
Technical and security logsA limited period, typically up to 90 days, unless needed to investigate an incident.

We may keep information longer where needed to comply with the law, resolve a dispute, prevent fraud, or establish or defend a legal claim. Backup copies are removed on their normal cycle.

Studios should keep their own copies of their photos. SnapTrace isn’t a long-term archive, and deleted events can’t be recovered.

11. Children

Photographer and studio accounts are only for people aged 18 or over.

Guests under 18 may use face search only with a parent or lawful guardian, who gives consent on the child’s behalf and takes or approves the selfie. A parent or guardian can also find a child’s photos by searching with the child present. We follow Section 9 of the DPDP Act and the DPDP Rules, 2025 for children’s data. We don’t track, profile or target advertising at children.

Event photos often include children. Studios are responsible for having the permissions needed to photograph and upload them.

12. Your rights

Subject to applicable law, you have the right to:

  • get information about the personal data we process about you;
  • have inaccurate or incomplete data corrected or updated;
  • have your personal data erased where it’s no longer needed or you withdraw consent;
  • withdraw consent at any time;
  • nominate someone to exercise your rights if you die or become incapacitated; and
  • raise a grievance with us, and then with the Data Protection Board of India.

Guests: because we don’t know who you are, please tell us the event (or send the gallery link) and describe or attach the photos concerned. You can also contact the studio that photographed the event. If a request is valid, we’ll remove your matches or restrict access to the photos, working with the studio where needed.

Studios: you can update most details in the dashboard, and you can delete your account yourself from Settings → Delete my account. Before anything is deleted, it shows exactly what will be erased, what you will lose, and what we keep. For anything else, email us from your account email address, or use the “Privacy or data request” option on our contact form.

We may need to verify a request before acting on it. Send requests to unit3a.official@gmail.com or to our Grievance Officer (Section 19).

13. Cookies and browser storage

We don’t use advertising cookies. Apart from optional analytics (below), we use only what the Services need to work:

  • Studio sign-in: our sign-in service keeps you signed in using your browser’s storage.
  • Guest session: the gallery keeps a random ID for each event in your browser’s local storage. It lets the gallery remember your consent and results without an account, so you can return to your photos. It contains no personal data, and you can remove it by clearing this site’s data.
  • Analytics cookies: if you accept them in the cookie banner, we use analytics cookies (Google Analytics) to understand how the website and dashboard are used and improve them. You can change your choice any time from “Cookie settings” in the footer.

If you block browser storage, sign-in and the gallery may not work properly. Our Cookie Policy lists each item in more detail.

14. Security

We use reasonable technical and organisational safeguards, including:

  • encrypted connections (HTTPS);
  • access rules so each studio can reach only its own data;
  • short-lived upload links, so the Camera Agent and browsers never hold our cloud credentials;
  • secrets kept in a managed secret store;
  • signature checks on payment notifications;
  • restricted administrative access;
  • rate limits; and
  • logging.

No system is completely secure, but we review and improve these measures regularly.

15. Data breaches

If we become aware of a personal data breach, we will act promptly to contain and investigate it. We will notify the Data Protection Board of India and affected people as the DPDP Act and Rules require.

16. Third-party websites

Our website links to other services, such as Instagram, LinkedIn, Facebook, and WhatsApp for demo requests. We don’t control their privacy practices. Please read their policies before sharing information with them.

17. Communications

We send studios messages they need about their account, security, payments, subscriptions, events and changes to our policies. If we send promotional messages, you can unsubscribe at any time. Required service messages will continue.

18. Changes to this policy

We may update this policy when the Services, our providers, or the law change. We’ll post the new version here with a new “Last updated” date. For significant changes, we’ll also notify studios by email or in the dashboard.

19. Grievance Officer and contact

For questions, privacy requests or complaints, contact:

Grievance Officer
Raguram
Email
Raguram.murugesan12@gmail.com
General enquiries
unit3a.official@gmail.com
Address
UNIT3A, 7/31 Railway Feeder Road, Keelakadayam 627415, Tirunelveli, Tamil Nadu, India

We acknowledge grievances within 24 hours and aim to resolve them within 15 days. If you’re not satisfied with our response, you can complain to the Data Protection Board of India.

Business details

Business
UNIT3A (SnapTrace is a product of UNIT3A)
Address
7/31 Railway Feeder Road, Keelakadayam 627415, Tirunelveli, Tamil Nadu, India
Phone
+91 70926 03577 (calls and WhatsApp)
Email
unit3a.official@gmail.com
Billing
Payments, refunds and subscription questions: see our Refund & Cancellation Policy, or email us from your studio account.

© 2026 UNIT3A. SnapTrace is a product of UNIT3A.

Questions about this policy, or a data request? Contact us

Back to top