PixloadPixload

Privacy Policy

How Pixload protects your personal and photographic data

Last updated: April 7, 2026

Introduction

Pixload ("we", "our") is committed to protecting your privacy. This policy describes how we collect, use and protect your data when you use our photo management and distribution platform.

Data We Collect

Personal Information

  • Name, email address, phone number
  • Payment information (processed by Stripe)
  • Profile photo and professional information
  • IP address and connection data

Photographic Data

  • Uploaded photos and their metadata (EXIF, GPS, capture date)
  • Biometric templates computed from the faces in photos and from your selfie (processed on our servers in Europe, never shared, never used across events)
  • AI curation results (quality scores, categorization)
  • Thumbnails and resized versions

Usage Data

  • Pages visited, features used
  • Performance data and load times
  • Browser type, operating system, screen resolution
  • Traffic source and site interactions

How We Use Your Data

Service Delivery

Processing, storing and distributing your photos through our secure pipeline.

AI Processing

Our AI analyzes your photos for automatic curation, facial recognition and image enhancement. Processing is done on our secure servers in Europe.

Communication

Sending account notifications, service updates and marketing communications (with your consent).

Payment

Payments are processed by Stripe. We never store your credit card information.

Service Improvement

Anonymized analysis to improve performance and user experience.

Legal Obligations

Data retention required by French and European law.

How We Protect Your Data

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Storage

Your photos are stored on secure servers (Cloudflare R2, buckets configured in EU jurisdiction). Cloudflare Inc. (United States) operates these servers; the residual transfer to the US parent entity is covered by Standard Contractual Clauses.

Access Control

Data access restricted to authorized personnel. Multi-factor authentication required.

Galleries

Galleries are protected by signed links with expiration. Access is controlled by the photographer.

Facial Recognition

To match people with their photos, facial recognition detects the faces appearing in the event's photos and computes biometric templates, kept to enable matching within that event. Templates derived from event photos stay scoped to their event; cross-gallery matching exists only for the selfie template of a signed-in user who has explicitly opted in, and that consent can be withdrawn. Biometric data is never shared with third parties. Selfie photos are deleted within minutes of extracting the embedding; guest selfie-search data is erased within 24 hours; registered users' biometric embeddings are kept for up to 90 days, renewed while consent remains active and automatically deleted when it lapses.

Audits

Regular security audits and continuous monitoring of access and anomalies.

Technical Support Access

Our super-administrators may access your account and events data in read-only mode to diagnose technical issues you report or that we detect proactively. Every access is recorded in our audit trail with the identity of the administrator, the timestamp, and the resource accessed.

For operations requiring write access (e.g., fixing corrupted data on your behalf), we will ask for your explicit consent through a 'Grant support access' mechanism available in your account Settings. You can revoke this consent at any time.

Even with your consent, our administrators are technically prevented from performing destructive actions on your behalf: deleting your account, changing your email or password, or modifying your billing.

You can request a copy of the audit log related to your account at any time by contacting privacy@pixload.io.

We never access your content for purposes other than fulfilling the service - never for training AI models, browsing, or third-party sharing.

Cookies and Trackers

We use the following tools, only after your explicit consent:

Google Analytics - Audience measurement and traffic analysis (IP anonymized)

Duration: _ga 2 years, _gid 24 hours

PostHog - Product analytics, user journeys and session replay (EU-hosted). For logged-in users, your user ID and email are transmitted for identification.

Duration: ph_* 1 year

Sentry - Error monitoring and application performance (essential, no consent required)
pixload_attribution - Audience-measurement cookie: captures the first page visited and acquisition source (referrer, UTM tags) so we can tell which marketing channels actually work. HMAC-signed to prevent tampering. Only set after the cookie banner is accepted.

Duration: 30 days; automatically cleared on the first login after signup

pixload_ref - Referral cookie: stores the referral code from the link you clicked, so the matching discount can be applied when you sign up. It holds only that code, no browsing data, and is not used for analytics. As it is necessary to deliver the service you requested by clicking the link, it is set without prior consent.

Duration: 30 days

Essential cookies (authentication, preferences) do not require consent.

You can revoke your consent at any time from the Privacy section in your account Settings.

Legal Bases for Processing

Consent (Art. 6(1)(a) GDPR)

Analytics tracking via Google Analytics and PostHog, including user identification for logged-in users. You can withdraw your consent at any time from Settings.

Performance of Contract (Art. 6(1)(b) GDPR)

Processing your photos, managing your account, billing, and delivering the Pixload service.

Legitimate Interest (Art. 6(1)(f) GDPR)

Error monitoring via Sentry, anonymous internal engagement statistics, and service security.

Legal Obligation (Art. 6(1)(c) GDPR)

Data retention required by French and European regulations (accounting, tax, legal obligations).

International Data Transfers

Most of our sub-processors are US-incorporated companies operating EU-based processing instances for our users' data. Vercel Inc. (United States) hosts the service with server execution in Dublin, Ireland (EU) - Vercel region dub1. Supabase Inc. (United States) hosts your database in Ireland. Cloudflare Inc. (United States) stores your photos on R2 in EU jurisdiction. Functional Software Inc. d/b/a Sentry and PostHog Inc. (both United States) run their EU-region instances (EU region and eu.posthog.com respectively). For each of these sub-processors, the residual transfer to the US parent entity (logs, support, administrative access) is covered by Standard Contractual Clauses adopted by the European Commission. Stripe Inc. and Google LLC (payments and analytics) may transfer data to the United States under the EU-US Data Privacy Framework.

Sub-processors

We use the following service providers to operate Pixload:

Stripe Inc. (payments, United States - EU-US DPF), Supabase Inc. (database, United States - database hosted in Ireland, EU - Standard Contractual Clauses), Cloudflare Inc. (CDN and storage, United States - R2 buckets in EU jurisdiction - Standard Contractual Clauses), Vercel Inc. (hosting, United States - server execution in Dublin, Ireland, EU - Standard Contractual Clauses), Functional Software Inc. d/b/a Sentry (error monitoring, United States - EU region instance - Standard Contractual Clauses), PostHog Inc. (analytics, United States - EU region instance eu.posthog.com - Standard Contractual Clauses), Google LLC (analytics, United States - EU-US DPF)

Contact Us

For any questions about your personal data or to exercise your rights (access, rectification, deletion, portability, objection, restriction of processing), contact us:

Email: privacy@pixload.io

Pixload Limited
Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy
Central, Hong Kong S.A.R

Data Protection Officer: privacy@pixload.io

You have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), the French data protection authority, at www.cnil.fr.