Privacy & POPIA Policy
How GuestDrop safeguards your event photos, personal information, and shared memories in strict compliance with South Africa's Protection of Personal Information Act (Act 4 of 2013).
POPIA & PAIA Compliant
Full compliance with South African privacy laws and statutory data subject rights.
100% Media Ownership
You own all your photos. We never sell, license, or use your photos for AI model training.
PCI-DSS Security
Payments handled by Level 1 certified gateways. Zero card details stored on our servers.
Quick Navigation
Responsible Party & Overview
This Privacy and POPIA Compliance Policy explains how GuestDrop ("GuestDrop", "we", "us", or "our"), operated by CodeWays (Pty) Ltd, acts as a "Responsible Party" under the Protection of Personal Information Act, No. 4 of 2013 (POPIA) and the Promotion of Access to Information Act, No. 2 of 2000 (PAIA).
GuestDrop provides a friction-free, web-based group photo and video sharing platform designed for events, vacations, weddings, milestone birthdays, celebrations, corporate offsites, and gatherings. Our platform allows hosts to create shared event albums and allows attendees to instantly contribute media via QR code or shared link without forcing any mobile application installation.
This policy applies to all visitors, event organizers ("Hosts"), and attendees ("Guests" or "Uploaders") interacting with our websites (guestdropalbum.com), upload widgets, live slideshow walls, audio guestbooks, and scavenger hunt games.
Categories of Personal Information Collected
In strict compliance with POPIA Condition 2 (Processing Limitation) and data minimisation principles, GuestDrop collects only the personal information strictly necessary to operate our event photo sharing service:
A. Event Organizers / Hosts
- Contact Information: Full name and email address provided during event creation and checkout to receive magic access links, receipts, and gallery notifications.
- Event Metadata: Event title, event date(s), custom URL slug, selected duration pass (1-Day, 3-Day Weekend, 7-Day Trip, or custom extension), and optional event password or PIN.
- Billing Records: Transaction amount, currency (ZAR/USD), timestamp, and payment provider transaction reference. We do not store raw card numbers.
B. Event Attendees / Guests (Uploaders & Participants)
- Uploader Display Name / Nickname: Voluntarily provided by the guest when uploading photos so the host can identify who took which picture. No user account registration or password is required.
- Uploaded Media: Full-resolution photos, short video clips, guestbook text notes, and audio voicemail recordings voluntarily submitted by the guest into the host's event album.
- Embedded Photo Metadata (EXIF): Image capture timestamps, camera/lens parameters, and dimensions. Geolocation GPS tags embedded in images are processed solely for album timeline sequencing.
- Scavenger Hunt & Game Data: Completed photo quest submissions, leaderboard points, and guest votes.
C. Automated Technical Telemetry
- Device & Browser Information: Browser version, operating system, and device screen dimensions used to render responsive web upload interfaces.
- IP Address & Security Tokens: Processed ephemerally for rate limiting, DDoS mitigation, spam upload prevention, and geographic routing.
Photo & Media Ownership Guarantee
GuestDrop claims zero intellectual property or copyright ownership over any photos, videos, audio notes, or text captions uploaded by hosts or guests.
We operate under strict ethical data policies:
- No Selling or Licensing: We never sell, lease, monetize, or license your photos or personal data to advertisers, brokers, or third parties.
- No AI Model Training: Your private photos, faces, and audio guestbook notes are never ingested, used, or processed to train machine learning or generative AI models.
- Private by Default: Event galleries are accessible only to individuals with the event QR code, link, or host-configured password/PIN.
- High-Resolution Preservation: We preserve original capture fidelity and deliver untampered, original full-resolution files to the host via 1-click ZIP export.
Payment & Financial Security (PCI-DSS)
All payment transactions are handled exclusively through registered, PCI-DSS Level 1 certified payment service providers (including PayFast, Stripe, Apple Pay, and Google Pay).
When purchasing an event pass on GuestDrop:
- Card details and CVV security codes are entered directly into the PCI-DSS compliant checkout iframe/gateway and never touch our servers.
- All payment transmissions are strictly secured with end-to-end TLS 1.3 cryptographic encryption.
- GuestDrop receives only an encrypted authorization token and transaction reference verifying that payment has cleared.
Lawful Grounds for Processing (POPIA Section 11)
Under Section 11 of the Protection of Personal Information Act, personal information may only be processed on recognized lawful grounds. GuestDrop processes data under the following legal bases:
Creating and hosting event albums, processing media uploads, rendering live slideshows, generating ZIP archives, and issuing payment receipts.
Guests voluntarily entering their display nickname, capturing photos, recording audio guestbooks, and submitting entries into the scavenger hunt.
Maintaining cybersecurity, preventing automated spam and malicious uploads, enforcing rate limits, and investigating platform abuse.
Retaining financial billing records as required by the South African Companies Act, Tax Administration Act (SARS), and commercial record laws.
Service & Event Notifications
GuestDrop strictly restricts email and electronic messages to essential transactional service notices:
Host Transactional Notices
Hosts receive instant order confirmations, tax invoices, host console access magic links, upload milestones, and reminders prior to gallery expiration.
Zero Unsolicited Marketing
We never spam hosts or guests with third-party marketing or newsletters. Guests uploading photos do not receive promotional emails.
Third-Party Operators & Gateways
Under POPIA Sections 20 and 21, third-party service providers who process data on our behalf are classified as "Operators". All GuestDrop operators are vetted and bound by strict written data processing agreements requiring state-of-the-art security:
| Operator Category | Purpose | Compliance & Safeguards |
|---|---|---|
| Payment Gateways (PayFast, Stripe) | Processing pass purchases and add-ons | PCI-DSS Level 1 certified, SARB / PASA regulated |
| Cloud Storage & Edge Infrastructure | Encrypted media storage, fast global CDN delivery | ISO 27001, SOC 2 Type II, TLS 1.3, AES-256 encryption at rest |
| Transactional Email Service (Resend / Mailers) | Delivering host receipts and magic links | DKIM/SPF authenticated, TLS transmission in transit |
Trans-Border Data Transfers (POPIA Section 72)
GuestDrop utilizes high-speed distributed edge cloud infrastructure to provide ultra-fast photo uploads worldwide. Consequently, encrypted media files may be transmitted or cached across international cloud data center nodes.
In strict compliance with Section 72 of POPIA, all cross-border data transmissions occur only to jurisdictions that maintain adequate legal data protection standards substantially equivalent to POPIA (such as GDPR-compliant European and UK jurisdictions), or under robust contractual clauses ensuring recipient compliance with equivalent privacy safeguards.
Security Safeguards & Encryption (POPIA Section 19)
In accordance with POPIA Section 19, we apply comprehensive physical, technical, and operational measures to safeguard personal data against loss, damage, or unauthorized access:
Security Breach Notification Protocol (POPIA Section 22)
In the event that personal information is accessed or acquired by an unauthorized party, GuestDrop will immediately notify both the South African Information Regulator and all affected data subjects in writing as soon as reasonably possible, detailing the nature of the breach, potential impact, and corrective actions taken.
Data Retention & Gallery Expiration (POPIA Section 14)
In compliance with POPIA Section 14, personal data is retained only for the duration necessary to deliver the service or satisfy legal record obligations:
- Standard Event Albums: Every event pass includes 31 days of active gallery access and high-res ZIP downloads following the conclusion of the event. Hosts receive reminder emails at 30 days, 14 days, 7 days, 3 days, and 24 hours before expiration.
- Permanent Post-Expiration Purging: After the 31-day retention window expires, all stored photos, videos, and associated media are automatically and permanently purged from Cloudflare R2 cloud storage.
- Immediate Host Deletion: Hosts have complete authority to delete individual photos or purge their entire event album at any time via the Host Console.
- Financial & Tax Records: Invoiced billing transactions are retained for 5 years as required by the Tax Administration Act and Companies Act.
Host Moderation & Guest Privacy Controls
GuestDrop empowers event hosts and guests with intuitive privacy and moderation tools:
Children's Privacy Protection (POPIA Section 35)
Under Section 35 of POPIA, the processing of personal information concerning children (persons under 18 years of age) is prohibited unless carried out with the consent of a parent, legal guardian, or competent person.
GuestDrop is designed for general family events, weddings, and celebrations. When photos containing minors are uploaded by attendees, the host and uploader warrant that they have obtained the necessary consent from the child's parent or legal guardian. If a parent or guardian wishes to have any photo containing their child removed, they may contact us at [email protected] for expedited takedown.
Your Statutory Data Subject Rights Under POPIA
As a Data Subject under the Protection of Personal Information Act, you hold explicit statutory rights regarding your personal information:
Request confirmation of whether we hold personal information about you and receive a copy of that record.
Request the correction, updating, or permanent deletion of inaccurate, irrelevant, or excessive data.
Object on reasonable grounds to the processing of your personal information where processing is based on legitimate interest.
Withdraw your consent at any time where processing was originally based on voluntary consent.
To exercise any of these statutory rights, please submit a written request to our Information Officer at [email protected]. We respond to verified data subject requests within thirty (30) calendar days without undue delay.
Information Officer & Complaints Procedure
If you believe your personal information has been handled in violation of POPIA, you have the statutory right to lodge a formal complaint with the South African Information Regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Complaints Email: [email protected]
Website: inforegulator.org.za