1. What We Collect
Photo Data
When you upload a photo, we temporarily store the image to perform compliance checking, background removal, cropping, and resizing. This is the only purpose for which your photo is used.
- We do not use your photos for AI model training
- We do not share your photos with any third party for marketing or analytics
- We do not build facial recognition profiles or biometric templates from your photos
Account Data
If you create an account, we collect:
- Email address — for account access, order receipts, and support communication
- Authentication tokens — session cookies for keeping you signed in
- Marketing consent — if you opt in, we record your consent timestamp
Payment Data
Payments are processed by third-party payment providers. We never see, store, or have access to your full card number, CVV, or bank details. Our payment providers handle payment data under their own privacy policies. We receive only a transaction confirmation (amount, status, timestamp).
Technical Data
We automatically collect limited technical data to keep the service running:
- IP address — used for country auto-detection (to pre-select your country's photo requirements) and rate limiting. Not stored long-term.
- Browser type and device — basic request headers for debugging service issues
- Product analytics events — page views, navigation patterns, feature interactions, and conversion events collected to understand how people use passportsize-photo.online and improve the product experience.
- Job metadata — dimensions, compliance check results, country, document type, timestamps. This is anonymized and contains no personally identifiable information.
2. Photo Retention & Deletion
This is the most important section of this policy:
- Uploaded original photos are deleted after processing completes or fails, and in any event within 24 hours, unless we are required to keep limited data for legal, fraud-prevention, dispute-resolution, or security reasons.
- Processed photo outputs are retained for up to 90 days so you can re-download your purchased photo, access your order, and receive customer support. This includes the downloadable compliant photo, preview image, and any generated print-layout file.
- If an upload is interrupted or processing cannot be completed, we retain the uploaded image only as long as needed to recover, diagnose, or clean up the failed job, and in any event no longer than the uploaded-original retention period above unless legally required.
- We retain only job metadata (dimensions, pass/fail results, country, document type, timestamps, order/support status) for service operation, support, accounting, fraud prevention, and product improvement. This metadata contains no image data and cannot be used to reconstruct your photo.
You may request deletion of your photo data at any time by emailing support@passportsize-photo.online. We will process deletion requests promptly, and no later than 30 days after receipt in accordance with applicable data protection law, unless we need to retain limited information for legal, security, dispute-resolution, or accounting purposes.
3. How We Use Your Data
We use the data we collect for the following purposes only:
- Service delivery — processing your photo to meet document requirements
- Account management — authentication, order history, receipts
- Support — responding to your questions or refund requests
- Service improvement — anonymized job metadata helps us improve compliance accuracy
- Service improvement and analytics — understanding page views, navigation patterns, feature interactions, and conversion events so we can improve passportsize-photo.online
- Country detection — IP-based geolocation to pre-select your country (MaxMind GeoLite2 database, processed locally on our servers — your IP is not sent to any third party for this purpose)
4. Third-Party Services
We use a limited number of third-party services to operate passportsize-photo.online:
- Payment providers — secure payment processing. We never handle your full card details.
- Resend — transactional email delivery (order confirmations, password resets). Receives your email address only.
- PostHog — product analytics. Helps us measure page views, navigation patterns, feature interactions, and conversion events so we can improve the service. We do not use PostHog for advertising.
- Cloud infrastructure — our servers run on cloud infrastructure with industry-standard encryption at rest and in transit.
We do not sell, rent, or share your personal data with any third party for advertising, marketing, or data brokerage purposes.
5. Cookies
passportsize-photo.online uses a small number of cookies and browser storage technologies:
- Session cookie — keeps you signed in. Essential for the service to function. Expires when you sign out or after 30 days of inactivity.
- Theme preference — stores your light/dark mode choice in localStorage. Never sent to our servers.
- Analytics storage — PostHog uses cookies and localStorage to recognize repeat visits, understand product usage, and measure conversion events.
We use analytics technologies to understand how passportsize-photo.online is used and to improve the product. We do not use advertising cookies or sell your data to advertisers.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to access — request a copy of the personal data we hold about you
- Right to erasure — request deletion of your personal data (uploaded originals are deleted within 24 hours; processed outputs are retained for up to 90 days unless deleted earlier on request or retained where legally required; account data can be deleted on request)
- Right to rectification — request correction of inaccurate personal data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing of your personal data for specific purposes
- Right to withdraw consent — withdraw marketing consent at any time
To exercise any of these rights, contact us at support@passportsize-photo.online. We respond to all data rights requests within 30 days.
7. Legal Basis for Processing
GDPR (EEA and United Kingdom)
For users in the European Economic Area (EEA) and United Kingdom:
- Legitimate interest — processing your photo to deliver the service you requested
- Contractual necessity — account management and payment processing to fulfil your order
- Consent — marketing communications (opt-in only, withdrawable at any time)
DPDP Act (India)
For users in India, we process your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act). Your photo data is processed for the specific purpose of delivering the photo compliance service you requested. We obtain your consent at the point of upload and account creation. You may withdraw consent at any time by contacting us, and we will delete your personal data according to the retention periods and legal exceptions described in this policy. Your rights under the DPDP Act — including the right to access, correction, erasure, and grievance redressal — can be exercised by emailing support@passportsize-photo.online.
7a. Cross-Border Data Transfers
passportsize-photo.online operates cloud infrastructure that may process your data in regions outside your country of residence, including the United States and the European Union. When your data is transferred across borders, we ensure appropriate safeguards are in place, including encryption in transit and at rest, and contractual protections with our infrastructure and service providers. Payment data processed by our payment providers is handled under their own cross-border data transfer mechanisms.
8. Data Security
We protect your data with industry-standard measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. Photo data is processed in isolated environments and purged according to the retention periods described above.
9. Children's Privacy
passportsize-photo.online processes passport and document photos, which may include photos of children (infant and child passport photos are a common use case). We apply the same limited retention periods to children's photos as to all other photos: uploaded originals are deleted within 24 hours, and processed outputs are retained for up to 90 days for download and support. We do not knowingly collect personal information from children under 13 for account creation — accounts must be created by a parent or guardian.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users and posted on this page with an updated "Last updated" date. Continued use of passportsize-photo.online after changes constitutes acceptance of the revised policy.
11. Contact
For any privacy-related questions or data rights requests:
- Email: support@passportsize-photo.online
- Response time: within 48 hours for general inquiries, within 30 days for formal data rights requests