Privacy policy
Last updated 18 September 2026
Spreadfold is a service for wedding and event photographers in India. A studio uploads the photos of an event, shares them with its client and guests, and receives the client's album picks. This policy explains what information we handle, why, where it is kept and when it is deleted. It is written to meet India's Digital Personal Data Protection Act, 2023.
Spreadfold is operated by an individual (sole proprietor) based in Andhra Pradesh, India. Contact: support@spreadfold.com.
Who this policy covers
- Studios: photographers who sign in and upload events. For their account, we decide how the data is used.
- Clients: the people who booked a studio (for example a couple), who open a private link with a PIN.
- Guests: people who open an event's guest link, and may search for their photos with a selfie.
- Visitors: anyone on spreadfold.com, including people who sign up for our pilot.
The photos of an event belong to the studio, and the studio decides what is uploaded and who it is shared with. For those photos we act on the studio's instructions. If you are in an event's photos and want something changed, you can ask the studio, or write to us and we will pass it on or act on it.
What we collect
- Studio accounts: your name, email address and account identifier from Google sign-in; your studio name, city and mobile or WhatsApp number; and the events you create.
- Event photos: the files a studio uploads, the smaller copies we make of them (thumbnails and web-size copies), and details read from the files such as the time a photo was taken.
- Face data: only while a studio has turned on guest search for an event, we detect faces in its photos and store a mathematical description of each face, its position in the photo, and which faces belong to the same person. We do not attach names to faces.
- Guest selfies: if a guest chooses to search with a selfie, we use the selfie once, to find matching faces in that event, and discard it in the same request. Selfies are never stored. We keep a record that the guest agreed to the search and when, and which photos it found so the guest can reload them.
- Choices people make: photos or people a client hides from guests, the client's favourites and album picks, and likes from guests.
- Security records: to stop abuse (for example repeated selfie searches or PIN guesses), we keep a one-way scrambled (salted hash) value made from a device identifier and IP address. It cannot be turned back into either.
- Pilot sign-ups: studio name, contact name, phone number, city, events per year and your message.
- Payments: when paid plans start, payments are handled by Razorpay. We receive the payment status and reference, never your card, UPI or bank details.
- Technical logs: IP address, browser and the time of each request, kept for up to 30 days to run and secure the service.
How we use it
- To run the service: storing and showing photos, sharing links, guest search, client selection and downloads.
- To keep it secure: sign-in, PIN checks, rate limits and investigating misuse.
- To support studios, and to bill for events once paid plans start.
- To meet legal obligations, such as tax records.
We do not sell personal data, we do not show advertising, and we do not use your photos or face data to train AI models.
Google sign-in
When a studio signs in with Google we receive only its basic profile: name, email address and a Google account identifier. We use it only to sign the studio in and to contact it about its account. We do not request access to Gmail, Drive, contacts or any other Google data. Spreadfold's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Face data and consent
- A guest sees what the selfie is used for and must agree before the camera opens.
- The selfie is compared with that one event only, then discarded.
- Guests can mark a photo as “not me”, and it leaves their results.
- A client can hide any photo, or a whole person, from guests.
- Face data for an event is deleted when the studio deletes it, and no later than 12 months after the event.
- Selfie search is not meant for children under 18. A parent or guardian can search on a child's behalf.
Where data is kept, and who helps us
Your data is stored outside India, mainly in Singapore. We use these providers, each bound to use the data only to provide their service to us:
- Amazon Web Services (Singapore): application servers, studio sign-in (Amazon Cognito) and face recognition (Amazon Rekognition).
- Neon (on AWS, Singapore): our database.
- Cloudflare R2: storage of photos and their copies.
- Vercel: the spreadfold.com website.
- Google: sign-in for studios.
- Razorpay: payments, once paid plans start.
We disclose information to authorities only when Indian law requires it.
How long we keep it
- Full-size photo files: 90 days after an event's last upload, then deleted, except while the client's album selection is open. Studios should keep their own copies.
- Smaller copies of photos: while the studio keeps the event, or until the studio or you ask us to delete them.
- Face data and stored guest search results: until the studio deletes them, and no later than 12 months after the event.
- Guest consent records: kept as proof that consent was given.
- Studio accounts: while the account is open, and deleted within 30 days of a deletion request, except records the law requires us to keep (such as invoices).
- Technical logs: up to 30 days.
Security
All traffic is encrypted (HTTPS). Photos are stored privately and shown only through links that expire within an hour. Client links need a PIN and lock after repeated wrong attempts. Data is encrypted at rest by our storage providers, and access inside Spreadfold is limited to what each part of the service needs.
Your rights
Under the Digital Personal Data Protection Act, 2023, you can ask us to:
- tell you what personal data we hold about you and how it is used;
- correct or complete it;
- delete it, or withdraw a consent you gave (for example for selfie search);
- name someone to act for you if you die or cannot act yourself.
Write to support@spreadfold.com. We aim to reply within 7 days and to resolve requests within 30 days. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
Cookies and browser storage
We use no advertising or analytics cookies. The site stores only what it needs in your browser: your sign-in, a client's session after the PIN, and small preferences such as the tab you were on.
Changes
If we change this policy we will update the date above, and tell studios by email about any change that affects how their data is used. See also our terms of service.
Grievances
Grievance contact: support@spreadfold.com