mAlbum ("we", "our", or "us") is operated by Bintree Software, India. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use mAlbum at www.malbum.live and app.malbum.live. By using mAlbum, you agree to the practices described here.
This policy is compliant with India's Digital Personal Data Protection (DPDP) Act, 2023.
1. Information We Collect
We collect the following categories of data:
- Face / biometric data: When you take a selfie to find your photos, we generate a face embedding (a mathematical representation of your facial features) and use it to match photos from the event. We do not store the selfie image itself after matching.
- Photographer account data: Name, email address, phone number, and business details provided during registration.
- Payment data: Billing details for photo delivery charges. Card data is handled by our payment processor and never stored on our servers.
- Usage data: Pages visited, device type, browser, IP address, and event interactions — collected via Google Analytics, Meta Pixel, and Ahrefs Analytics.
- Communications: Messages you send us via Crisp chat or email.
2. How We Use Your Data
- To match your selfie with event photos using AI face recognition (AWS Rekognition).
- To deliver matched photos to you and the photographer.
- To operate, maintain, and improve the mAlbum platform.
- To process payments and send receipts.
- To send service-related communications (event links, download notifications).
- To respond to support requests.
- To comply with legal obligations.
3. Face Recognition Data
mAlbum uses face recognition to match guests with their event photos. Here is how we handle this sensitive data:
- The selfie you take is sent to AWS Rekognition (Amazon Web Services) to generate a face embedding. The embedding, not the image, is used for matching.
- Face embeddings are stored only for the duration of the event and are deleted within 30 days of the event date.
- Face data is never sold, shared with third parties for marketing, or used for any purpose other than photo matching.
- Guests may request deletion of their face data at any time by contacting us at support@malbum.live.
4. Data Sharing
We share data only with:
- AWS (Amazon Web Services): For cloud hosting, storage (S3), and face recognition (Rekognition). Data is stored in the Mumbai (ap-south-1) region.
- Payment processors: For billing. They are bound by PCI-DSS obligations.
- Analytics providers: Google Analytics, Meta (Facebook), Ahrefs — for usage analytics under their respective privacy policies.
- Crisp: For customer support chat.
- Law enforcement: If required by a court order or applicable law.
We do not sell your personal data to any third party.
5. Data Retention
- Guest selfie embeddings: deleted within 30 days of the event.
- Event photos: stored until the photographer deletes the event or their account is closed.
- Photographer account data: retained for the lifetime of the account and up to 3 years after closure for legal compliance.
- Analytics and logs: retained for up to 24 months.
6. Your Rights (DPDP Act 2023)
As a data principal under India's DPDP Act 2023, you have the right to:
- Access — request a summary of personal data we hold about you.
- Correction — request correction of inaccurate data.
- Erasure — request deletion of your personal data.
- Grievance redressal — raise a complaint with our Grievance Officer.
- Nominate — nominate another person to exercise your rights in case of incapacity.
To exercise any right, email us at support@malbum.live. We will respond within 30 days.
7. Cookies
We use essential cookies for session management and analytics cookies (Google Analytics, Meta Pixel) to understand how visitors use the site. You may opt out of analytics cookies by using browser settings or a privacy extension. Essential cookies cannot be disabled.
8. Children's Privacy
mAlbum is not directed at children under 18. If a minor's photo is uploaded at an event by a photographer, parental or guardian consent is the responsibility of the event organiser (photographer). If you believe a child's data has been processed without consent, contact us immediately at support@malbum.live.
9. Security
We use industry-standard security practices including HTTPS encryption, access controls, and regular security reviews. Face embeddings and photos are stored in private S3 buckets accessible only by authenticated users.
10. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. Continued use of mAlbum after changes constitutes acceptance of the updated policy.
11. Contact & Grievance Officer
For privacy concerns, data requests, or grievances:
- Email: support@malbum.live
- Company: Bintree Software, India
We aim to resolve all grievances within 30 days of receipt.