Privacy Policy

How Pixload protects your personal and photographic data

Last updated: April 7, 2026

Introduction

Pixload ("we", "our") is committed to protecting your privacy. This policy describes how we collect, use and protect your data when you use our photo management and distribution platform.

Data We Collect

Personal Information

  • • Name, email address, phone number
  • • Payment information (processed by Stripe)
  • • Profile photo and professional information
  • • IP address and connection data

Photographic Data

  • • Uploaded photos and their metadata (EXIF, GPS, capture date)
  • • Biometric templates computed from the faces in photos and from your selfie (processed on our servers in Europe, never shared, never used across events)
  • • AI curation results (quality scores, categorization)
  • • Thumbnails and resized versions

Usage Data

  • • Pages visited, features used
  • • Performance data and load times
  • • Browser type, operating system, screen resolution
  • • Traffic source and site interactions

How We Use Your Data

Service Delivery

Processing, storing and distributing your photos through our secure pipeline.

AI Processing

Our AI analyzes your photos for automatic curation, facial recognition and image enhancement. Processing is done on our secure servers in Europe.

Communication

Sending account notifications, service updates and marketing communications (with your consent).

Payment

Payments are processed by Stripe. We never store your credit card information.

Service Improvement

Anonymized analysis to improve performance and user experience.

Legal Obligations

Data retention required by French and European law.

How We Protect Your Data

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Storage

Your photos are stored on secure servers (Cloudflare R2, buckets configured in EU jurisdiction). Cloudflare Inc. (United States) operates these servers; the residual transfer to the US parent entity is covered by Standard Contractual Clauses.

Access Control

Data access restricted to authorized personnel. Multi-factor authentication required.

Galleries

Galleries are protected by signed links with expiration. Access is controlled by the photographer.

Facial Recognition

To match people with their photos, facial recognition detects the faces appearing in the event's photos and computes biometric templates, kept to enable matching within that event. Templates derived from event photos stay scoped to their event; cross-gallery matching exists only for the selfie template of a signed-in user who has explicitly opted in, and that consent can be withdrawn. Biometric data is never shared with third parties. Selfie photos are deleted within minutes of extracting the embedding; guest selfie-search data is erased within 24 hours; registered users' biometric embeddings are kept for up to 90 days, renewed while consent remains active and automatically deleted when it lapses.

Audits

Regular security audits and continuous monitoring of access and anomalies.

Technical Support Access

Our super-administrators may access your account and events data in read-only mode to diagnose technical issues you report or that we detect proactively. Every access is recorded in our audit trail with the identity of the administrator, the timestamp, and the resource accessed.

For operations requiring write access (e.g., fixing corrupted data on your behalf), we will ask for your explicit consent through a 'Grant support access' mechanism available in your account Settings. You can revoke this consent at any time.

Even with your consent, our administrators are technically prevented from performing destructive actions on your behalf: deleting your account, changing your email or password, or modifying your billing.

You can request a copy of the audit log related to your account at any time by contacting privacy@pixload.io.

We never access your content for purposes other than fulfilling the service - never for training AI models, browsing, or third-party sharing.

Cookies and Trackers

We use the following tools, only after your explicit consent:

Google Analytics - Audience measurement and traffic analysis (IP anonymized)

Duration: _ga 2 years, _gid 24 hours

PostHog - Product analytics, user journeys and session replay (EU-hosted). For logged-in users, your user ID and email are transmitted for identification.

Duration: ph_* 1 year

Sentry - Error monitoring and application performance (essential, no consent required)
pixload_attribution - Audience-measurement cookie: captures the first page visited and acquisition source (referrer, UTM tags) so we can tell which marketing channels actually work. HMAC-signed to prevent tampering. Only set after the cookie banner is accepted.

Duration: 30 days; automatically cleared on the first login after signup

pixload_ref - Referral cookie: stores the referral code from the link you clicked, so the matching discount can be applied when you sign up. It holds only that code, no browsing data, and is not used for analytics. As it is necessary to deliver the service you requested by clicking the link, it is set without prior consent.

Duration: 30 days

Essential cookies (authentication, preferences) do not require consent.

You can revoke your consent at any time from the Privacy section in your account Settings.

Legal Bases for Processing

Consent (Art. 6(1)(a) GDPR)

Analytics tracking via Google Analytics and PostHog, including user identification for logged-in users. You can withdraw your consent at any time from Settings.

Performance of Contract (Art. 6(1)(b) GDPR)

Processing your photos, managing your account, billing, and delivering the Pixload service.

Legitimate Interest (Art. 6(1)(f) GDPR)

Error monitoring via Sentry, anonymous internal engagement statistics, and service security.

Legal Obligation (Art. 6(1)(c) GDPR)

Data retention required by French and European regulations (accounting, tax, legal obligations).

International Data Transfers

Most of our sub-processors are US-incorporated companies operating EU-based processing instances for our users' data. Vercel Inc. (United States) hosts the service with server execution in Dublin, Ireland (EU) - Vercel region dub1. Supabase Inc. (United States) hosts your database in Ireland. Cloudflare Inc. (United States) stores your photos on R2 in EU jurisdiction. Functional Software Inc. d/b/a Sentry and PostHog Inc. (both United States) run their EU-region instances (EU region and eu.posthog.com respectively). For each of these sub-processors, the residual transfer to the US parent entity (logs, support, administrative access) is covered by Standard Contractual Clauses adopted by the European Commission. Stripe Inc. and Google LLC (payments and analytics) may transfer data to the United States under the EU-US Data Privacy Framework.

Sub-processors

We use the following service providers to operate Pixload:

Stripe Inc. (payments, United States - EU-US DPF), Supabase Inc. (database, United States - database hosted in Ireland, EU - Standard Contractual Clauses), Cloudflare Inc. (CDN and storage, United States - R2 buckets in EU jurisdiction - Standard Contractual Clauses), Vercel Inc. (hosting, United States - server execution in Dublin, Ireland, EU - Standard Contractual Clauses), Functional Software Inc. d/b/a Sentry (error monitoring, United States - EU region instance - Standard Contractual Clauses), PostHog Inc. (analytics, United States - EU region instance eu.posthog.com - Standard Contractual Clauses), Google LLC (analytics, United States - EU-US DPF)

Your rights over your data

The GDPR grants you the following rights over the personal data we process:

Right of access (Art. 15)

Obtain confirmation that we process data about you, and receive a copy of it. From your account: Settings > Your data and your rights > Download my data. The JSON file contains your profile, your consents with their timestamps and proof, your selfies, your events, your gallery access and your deletion requests. The biometric template itself is not included in the file for security reasons: its presence is reported, and it is provided on request at privacy@pixload.io.

Right to rectification (Art. 16)

Correct inaccurate or incomplete data. Your account information can be edited directly in your Settings; for anything else, write to privacy@pixload.io.

Right to erasure (Art. 17)

Request the deletion of your data. From your account: Settings > Danger zone. The request is reviewed within 72 hours and processed within 30 days at most; it deletes your events, your photos, your selfies and your biometric consents.

Right to restriction (Art. 18)

Request that a processing operation be frozen, for instance while you contest its accuracy or lawfulness. By email at privacy@pixload.io.

Right to portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format, to pass it on to another service. It is the same JSON file as the one for the right of access.

Right to object (Art. 21)

Object to a processing operation based on our legitimate interest, on grounds relating to your particular situation. By email at privacy@pixload.io.

Withdrawal of consent (Art. 7(3))

Withdraw a consent already given, at any time and as easily as you gave it. From your account: Settings > Your data and your rights. Finding your photos from a selfie (biometric data) and extending that search to your other galleries are withdrawn separately: withdrawing the extension does not withdraw the search itself. Withdrawing the selfie search immediately erases your biometric encoding and your selfie image from our database, and resets your matches. Deletion of your template held by our recognition engine is requested in the same step: if the engine does not confirm it, the screen says so instead of claiming a complete erasure, and you can retry or write to privacy@pixload.io. Withdrawal does not affect the lawfulness of processing already carried out.

Right to lodge a complaint (Art. 77)

Lodge a complaint with the CNIL or with the supervisory authority of your country of residence.

How to exercise them

Access, portability, erasure and withdrawal of consent are exercised straight from your Settings, without writing to us. For all the others, or if you have no account, write to privacy@pixload.io stating your request. We may ask you for further elements if we have reasonable doubts about your identity (Art. 12(6)), and only in that case.

Response time

We answer within one month of receiving your request (Art. 12(3)). That period may be extended by two months where the request is complex or where requests are numerous; we then tell you within the month, with the reasons. Exercising your rights is free of charge (Art. 12(5)).

Contact Us

For any questions about your personal data or to exercise your rights (access, rectification, deletion, portability, objection, restriction of processing), contact us:

Email: privacy@pixload.io

Pixload Limited
Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy
Central, Hong Kong S.A.R

Data Protection Officer: privacy@pixload.io

You have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), the French data protection authority, at www.cnil.fr.