Privacy

Effective July 24, 2026. This notice explains how Toss Cam handles information through the Toss Cam website and Android app when hosts create event films, guests join them, and people use an account, support, moderation, payment, or optional advertising-measurement feature.

Account and identity data. Host accounts use an email address, an account or provider user ID, enabled sign-in methods, and account and sign-in timestamps. If you choose Google or Facebook sign-in, Google or Meta and our authentication provider return a verified email address and basic account identity; Toss Cam never receives your Google or Facebook password. Email-and-password authentication is handled by our authentication provider. Toss Cam stores only hashed, opaque app-session credentials.

Films, photos, and activity. We store the film title and occasion type, creation, camera-closing and reveal dates, guest and shot limits, selected visual filter, album and download settings, cover image, uploaded photos, and any recap video the host asks us to generate from those photos. A contribution can include an optional guest display name, an app-generated pseudonymous guest identifier, a contributor identifier, upload and terms-acceptance timestamps, and its association with a film. We also record the actions needed to operate the service, such as film ownership, uploads, event closure, reveals, reports, moderation decisions, and entitlement changes. Uploaded images are re-encoded for the service and embedded location metadata is not retained.

Reports, support, and beta access. A photo report contains the selected reason, optional notes, a pseudonymous reporter identifier, timestamps, status, and any moderation resolution. If you contact support, we process your sender details, message, request category, and resolution record. Complimentary beta access is tied to the exact account email and records the allowed tier, film credits, expiry, redemption or revocation state, and limited internal reason and audit entries.

Purchases. Stripe processes website checkout and refunds, and Google Play Billing and the Google Play Developer API process Android purchases, licensing, refunds, and chargebacks. Toss Cam receives and stores limited purchase history: provider and order or transaction references, product, amount, currency, status, timestamps, refund state, and the film entitlement. For reliable Google Play purchase completion, Toss Cam stores a cryptographic hash of the purchase token and may temporarily store an authenticated-encrypted copy until Google confirms that the consumable purchase was used; the encrypted copy is then deleted. Stripe may receive a signed-in host's email for checkout. Toss Cam does not receive or store full payment-card details.

Technical data. We use hashed session and security identifiers to keep accounts and films working safely. Hosting and platform services may process limited connection, device, app-interaction, fraud-prevention, and diagnostic information needed to deliver and protect Toss Cam. In particular, Google Play components may process device or account identifiers, app interactions, purchase information, and diagnostics under Google's terms and privacy notice. The website also stores your optional-analytics choice locally in your browser so it can respect that choice on later visits.

How we use information. We use this information to create and operate films, enforce camera and guest limits, authenticate hosts, reveal and deliver albums, generate requested recap videos, provide purchases or complimentary access, send transactional account email, prevent fraud and abuse, resolve support requests, moderate reported content, maintain audit records, and comply with legal obligations.

Sharing you direct. Toss Cam films are not placed in a public directory, but their invitation, guest, album, and management links act as access keys. When a host shares a QR code or link, the host directs us to make the film available to its recipients. Depending on the host's settings and whether the film has developed, people with an enabled link may see the film name, cover, participant display names, photos, and recap, and may download photos. Hosts can make the developed album host-only and can disable guest downloads. Keep management and private film links secure.

Optional advertising measurement. On eligible public marketing pages, and only after you select “Accept optional analytics,” Toss Cam may activate the TikTok Pixel. TikTok may then process limited browser and device information, IP address and user agent, a TikTok click identifier, campaign tags, the public page path, timestamps, and a public-page view. If a consented TikTok campaign visit later results in a completed registration, checkout start, or confirmed website purchase, Toss Cam may also report that conversion through TikTok's server-side Events API using the click identifier. We use this information to attribute visits and purchases to campaigns, understand advertising performance, prevent duplicate event counts, and improve our public marketing. Declining does not reduce access to Toss Cam.

What advertising measurement never includes. We do not send TikTok your event photos, uploaded media, film or invitation codes, guest contributions, form contents, payment-card information, password, or account email address. The TikTok Pixel is restricted to public marketing pages; private film, album, host, capture, account, and administrative pages do not load it. Downstream conversion reports use a fixed public Toss Cam source URL rather than a private film or account URL.

Your choice and withdrawal. You may accept or decline optional analytics with equally available controls. We honor an enabled Global Privacy Control signal as a decline; optional measurement remains off while that browser signal is active. You can review or withdraw consent at any time using the “Privacy choices” control on a public Toss Cam page or this notice. Withdrawal stops new optional measurement, asks TikTok's browser tools to disable their cookies, clears Toss Cam's advertising-attribution cookie and any unsent conversion attribution, and refreshes the current page if needed to stop a Pixel already loaded. Essential authentication, security, film, and payment storage remains in use because the service cannot operate safely without it.

Service providers and data locations. Supabase provides account authentication and identity storage. DigitalOcean hosts the application, database, media, and operational backups. Google provides Google sign-in, Play Billing, and purchase verification for Android. Meta provides Facebook sign-in when enabled. Stripe provides website checkout and refund processing when website payments are enabled. Brevo delivers account confirmation, password-recovery, and owner-issued beta invitation email. If you accept optional analytics, TikTok and its affiliates provide advertising measurement and campaign attribution. These providers may process information in countries outside Canada under their own safeguards and applicable agreements. We provide each service only the information needed for its role. We do not send film photos to identity, email, payment, or advertising-measurement providers.

No sale or photo training. We do not sell personal information or train AI models on customer photos. Optional advertising measurement is used only as described above and is not activated without consent.

Retention. A film, its settings, photos, cover, and generated recap remain available until the host deletes the film or the owning account is deleted; a film is not automatically deleted merely because the event ended or it developed. Account records remain while the account is open. Reports and their resolution record remain with the film until it is deleted, subject to the limited audit retention below. Support records are kept as reasonably needed to resolve and document the request. Operational backups run daily and can retain a deleted copy for up to 14 days, after which the normal rotation removes it. Backups are used for disaster recovery, not to return deleted content to normal use.

Deletion and removal. A host can permanently delete a film from its management screen. Account holders can delete their account and all owned films from account settings or follow our public deletion instructions. Account deletion removes the account identity from Toss Cam and Supabase, active Toss Cam sessions, owned films, photos, covers, recaps, and related reports. We may retain limited de-identified or account-redacted payment, refund, beta-grant, security, and administrative audit records where reasonably needed or legally required for accounting, fraud prevention, disputes, compliance, and service integrity. Guests who want a contributed photo removed should contact the film host or email us with the film code and enough detail to identify the photo.

Security. We use HTTPS in production, restricted media routes, hashed credentials, upload validation, rate limits, and access-controlled administrative tools. No online service can promise absolute security, so hosts should download important photos and protect management links.

Questions or privacy requests? Write to hello@tosscam.com.