Privacy Policy

Last updated: May 2025 · GDPR compliant

At Stream Circle, we take your privacy seriously. This policy explains what personal data we collect, why we collect it, how we process it, and your rights under the GDPR.

1. Data Controller

Stream Circle is the data controller responsible for your personal data. For any questions or requests: contact form.

2. Data We Collect

We process the following personal data to provide our service:

CategoryDataSource
Identity & contactFirst name, last name, email addressRegistration or social sign-in
Profile photoUploaded avatar or photo from your social accountOptional
Event dataEvent name, date, location, descriptionWhen you create an event
Media filesUploaded photos and videosVia guest upload or direct upload
Payment referenceTransaction reference (card details stay with Stripe)When purchasing a plan
Technical dataIP address, browser type, server logsAutomatically on each request
Session dataSession token, last login dateWhen you sign in

3. Legal Basis for Processing (GDPR Article 6)

4. Data Retention

Data TypeRetention PeriodReason
Account dataWhile account is active + 30-day backup
Event data & mediaUntil the event is archived or deleted
Payment records7 yearsTax compliance
Server logs90 daysSecurity and debugging
Session tokens7 days (active session) or until sign-out

5. Third Parties

We never sell or share your data with third parties for marketing purposes.

6. Your Rights Under GDPR

To exercise any of these rights, use our contact form. We will respond within 30 days.

7. Data Security

All data is transmitted over HTTPS. Passwords are stored as bcrypt hashes — never in plain text. Session tokens are single-use and rotated on every sign-in. Cloudflare R2 storage uses AES-256 encryption.

8. Cookies

For detailed information about our use of cookies, see our Cookie Policy.

9. Changes to This Policy

We may update this policy from time to time. For significant changes, we will notify you at your registered email address.