1. Information we collect
We may collect:
Account information
- name
- email address
- login/authentication information
- account settings
- email preferences
Album information
- uploaded photos
- album titles
- captions
- gift messages
- selected layouts
- image crop adjustments
- cover choices
- recipient names
- family contributor information
Order and delivery information
- recipient name
- delivery address
- delivery phone number for carrier use
- order details
- plan type
- cover type
- extra gift copies
- shipping and tracking information
Payment information
Payments are processed by Stripe. We do not store full credit card numbers.
Technical information
- IP address
- browser/device information
- usage events
- pages visited
- cookies or similar technologies
First-party product analytics
We collect a small set of product-journey events using our own same-origin endpoint. These may include controlled utm_source, utm_medium, utm_campaign, and utm_content values, the referring hostname and a broad referrer category, plus random anonymous and per-tab session identifiers.
Product analytics does not contain photos, filenames, captions, reactions, names, email addresses, phone or postal addresses, payment details, or Stripe identifiers. It does not store full URLs or raw query strings.
For abuse prevention, our server transiently processes the single IP address supplied by our hosting platform, canonicalizes it, and replaces it with a one-way HMAC pseudonym. We do not store or log the raw IP address in analytics. The pseudonymous hourly budget row is retained for no more than two hours and purged hourly.
2. How we use information
We use information to:
- create and manage accounts
- let customers create albums
- upload and store photos
- generate album previews
- save crop adjustments and captions
- create print-ready PDF files
- manually prepare and coordinate production and shipping of printed albums
- send account, order, reminder, and support emails
- invite family contributors
- process payments through Stripe
- provide support
- prevent fraud or misuse
- improve the product
- comply with legal obligations
3. Photos and family content
Your family photos are private.
We use uploaded photos only to provide the Grandparent Album service, including preview creation, print file generation, printing, shipping, customer support, and the private digital album experience.
- We do not sell your photos.
- We do not make your albums public.
- We do not use your private family photos in advertising without your permission.
- We do not use private family photos to train public AI models.
4. Family contributors
If you invite family members to add photos, they may upload photos through a private contributor link.
Contributors should not see:
- payment details
- billing information
- subscription details
- private delivery addresses
- admin information
5. Service providers
We use the following providers to operate Grandparent Album:
- Vercel for website hosting and request processing
- Supabase for account authentication, the database, and photo/file storage
- Gelato for manually submitted print orders and coordinated shipping
- Stripe for payments, recurring billing, and the billing portal
- Resend for account and application email delivery
- Cloudflare Turnstile for an automatic bot check when you start an album
We share only the information needed for each provider to perform its service. For example:
- Our authorized staff manually provide Gelato with print files and the recipient details needed for fulfillment, including the delivery address and carrier contact phone number.
- Stripe processes payment and billing details. It also uses information for its own fraud prevention and legal compliance purposes, as explained in its Privacy Policy.
- Resend processes recipient email addresses and email content.
- Supabase stores account, album, photo, and order data.
- Vercel processes website requests and associated technical information.
- Cloudflare Turnstile receives technical browser and device signals to tell people from automated bots. It does not receive your photos, album content or email address.
Product analytics uses our own endpoint and existing hosting/database providers, not a separate third-party analytics SDK. Optional advertising measurement separately shares advertising measurement activity with Meta unless you opt out as described in our Cookie Policy. Support is handled through our contact email.
6. International transfers
Falvore s.p. is based in Slovenia. Customers may be located in the United States.
We operate from Slovenia. Our Supabase project stores account, album, photo, and order data in its North Virginia, United States region. Vercel hosts the website using its international network, including processing in the United States.
Our Resend sending region is Ireland. Resend stores account data, including email metadata, logs, and API records, in the United States regardless of the sending region. Stripe also processes information in the United States and other countries. Gelato uses an international network of production and service partners; a U.S. delivery address does not mean all processing takes place in the United States.
For questions about processing locations or the transfer protections applicable to your information, contact hello@grandparentalbum.com.
7. Legal bases for processing
Where GDPR applies, we process personal data based on:
- performance of a contract, such as creating, producing, and delivering albums
- legitimate interests, such as preventing misuse and providing support
- legal obligations, such as tax/accounting records
- consent for optional marketing emails
Our product analytics collects journey events unless you disable it in this browser or your browser supplies a Global Privacy Control signal. The browser control below lets you stop future collection; it does not ask for consent before collection begins.
8. How long we keep information
We retain information for the following service and recordkeeping purposes:
- account data: to maintain your account and provide access to your albums and orders
- unfinished albums started without an account: deleted, with their photos, after 3 days without activity, unless you order or set up an account
- album photos/layouts: to let you work on albums and preserve approved print content and already-paid albums, including after subscription cancellation
- order records: as required for accounting, tax, and legal purposes
- support emails: as needed to resolve issues
- email preferences: until changed or unsubscribed
- first-touch analytics attribution and anonymous identifier: up to 30 days
- raw first-party analytics events: up to 90 days
- Meta matching information and event queue: up to seven days
- pseudonymous analytics ingestion budget rows: up to two hours
To request deletion of your account or photos, contact hello@grandparentalbum.com. Deletion requests are handled through support, subject to applicable rights and records we must retain. Cancelling a subscription does not delete your account or already-paid albums.
Where the editor allows photo removal, stored-file cleanup may remain pending after the photo is removed from the editable album. Photos retained as sources for an approved album cannot be deleted through that editor action. Contact support for a privacy request concerning approved content; removing a photo is not account-wide deletion.
If an album has already been approved for print, produced, or shipped, we may not be able to stop production or remove information already sent to the print provider.
9. Your privacy rights
Depending on where you live, you may have rights to:
- access your personal information
- correct inaccurate information
- request deletion
- request restriction of processing
- object to certain processing
- request data portability
- withdraw consent
- unsubscribe from marketing emails
- lodge a complaint with a data protection authority
California and other U.S. state privacy laws may provide additional rights where applicable. When you allow advertising measurement, we share the limited event and matching information described in our Cookie Policy with Meta. You can disable this in Cookie Policy settings; Global Privacy Control also disables it.
To exercise privacy rights, contact: hello@grandparentalbum.com
10. Email preferences
We may send:
- account emails
- album reminders
- contributor invitations
- preview-ready emails
- order updates
- shipping updates
- optional marketing emails
You can manage reminder and marketing preferences in your account or unsubscribe using links in our emails. Transactional emails may still be sent when needed.
12. Security
We use reasonable technical and organizational measures to protect your information.
No online service is completely secure. Please keep your login details safe.
13. Children
Grandparent Album is intended for adults creating family albums.
Children may appear in uploaded family photos, but children should not create accounts or use the service without a parent or guardian.
14. Changes
We may update this Privacy Policy from time to time.
If changes are significant, we may notify users by email or in the app.
15. Contact
Falvore s.p.
Rimska cesta 90b
3311 Šempeter
Slovenia
Registration number: 7364741000
VAT ID: Not applicable
Email: hello@grandparentalbum.com
Website: grandparentalbum.com
For a privacy question or request, email hello@grandparentalbum.com and describe the account or information your request concerns.