Privacy Policy

Last Updated: February 9, 2026

1. Information We Collect

We collect the following information:

  • Account Information: Name, e-mail address, profile photos
  • Staff Photos: Photos uploaded to staff boards
  • Usage Data: Basic information about how you use our service

2. How We Use Your Information

We use your information to:

  • Provide the StaffPhotoBoard service
  • Display staff photos and boards
  • Manage your account
  • Send important service updates

3. Information Sharing

We do not sell or share your personal information with third parties, except:

  • Service Providers: Microsoft Azure (hosting), Auth0 (authentication), Stripe (payment processing)
  • Legal Requirements: When required by law

4. Payment Data & Retention

When you use StaffPhotoBoard's paid features, payment processing is handled by Stripe. We do not store your full card details on our servers.

On account deletion:

  • All saved payment methods are deleted immediately from Stripe.
  • Invoice records (transaction amounts, dates, and invoice identifiers) are retained for 6 years as required by UK tax law (Finance Act 1998, VAT Act 1994).
  • This retention is exempt from the GDPR right to erasure under Article 17(3)(b) (compliance with a legal obligation).
  • Retained records are restricted to compliance and audit purposes only.
  • Retained records are not accessible to any new account created with the same e-mail address.

On re-signup:

  • A new Stripe customer is created. Your new account has no access to billing history from any previous account.

5. Data Security

We protect your information using:

  • Encryption for data in transit and at rest
  • Secure authentication
  • Regular security updates

6. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete your account and data
  • Contact us with privacy concerns

Note: All data requests require identity verification. Certain records (such as invoices) may be retained where required by law, even after account deletion — see Section 4 above.

7. Contact Us

For privacy questions or data requests, contact us through the application support channels.

8. Changes to This Policy

We may update this policy. We will notify you of significant changes.

---

By using our service, you agree to this Privacy Policy.