Skip to main content

PRIVACY POLICY

Last updated: May 2026 • Effective: March 2026

We collect minimal data to deliver face-matched photo experiences at events. Your face data is deleted after 30 days. We never sell your data. You have full control over your privacy at any time.

Who we are

TIME&SPACE is an event media platform based in Lisbon, Portugal. We provide a face-recognition photo delivery system that helps event guests find and download their photos.

Company: Welcome Objective Unipessoal Lda, trading as TIME&SPACE

NIF: 517881721

Registered office: Lisbon, Portugal

Data Controller: Welcome Objective Unipessoal Lda (TIME&SPACE)

Privacy Contact: [email protected]

Legal Contact: [email protected]

What we collect

We collect only what's necessary to run the platform. Here's the breakdown:

Account data (organisers & photographers)

  • Name, email address, and account details
  • Hashed password (if you use password login)
  • Profile information: location, website, bio, social links
  • Payment information (handled securely by Stripe. We don't store your card)

Event data

  • Photos you upload to events
  • Event details: date, location, title, description
  • Event settings: watermark preferences, brand colours, retention period
  • Photo metadata: filename, size, EXIF data (date taken, camera model)

Biometric data (face recognition). See section below

  • Selfies taken by guests when they scan the QR code
  • Face embeddings (mathematical vectors, not images)
  • Explicit consent is required before any face processing

Guest data (participants)

  • Email address (optional, only if you want match notifications)
  • Matched photos from the event
  • Download history
  • No account is created. Guests remain anonymous

Usage & analytics data

  • Download counts, scan counts, view counts
  • Device type and browser (for platform improvements)
  • IP address (for fraud prevention and analytics only)
  • No personally identifiable information is collected

Referral programme data (referrers only)

  • Your unique referral code and referral link slug
  • Number of times your referral link has been opened (click count)
  • Records of referred users: their email address, sign-up date, and paid event history (to calculate your commission)
  • Commission earnings: amounts, rates, and payment status
  • Payout data (collected only when you request a payout): IBAN (bank account number), NIF/tax identification number. These are collected at the point of payout request and used solely to process your SEPA transfer and comply with tax obligations

Biometric data (face recognition)

Your face data is protected under GDPR Article 9 (special category data). Here's how we handle it:

What is a face embedding?

A facial embedding is a mathematical representation of your face (512 numbers). It is not a photo of your face. It cannot be reverse-engineered into an image. It's similar to a fingerprint: unique, but not revealing.

How it works

  1. You take a selfie at the event by scanning the QR code
  2. We convert your face into a mathematical embedding
  3. We match that embedding against all event photos
  4. We show you the photos where you appear
  5. Your original selfie image is automatically deleted after 30 days
  6. The embedding is deleted when the event ends

Your consent rights

  • Explicit consent: You must actively agree before your face is processed
  • Optional: You can browse the event gallery without scanning your face
  • Withdraw anytime: Contact us to withdraw consent and delete your face data
  • No retaliation: Refusing face recognition doesn't prevent you from finding photos by browsing

Data deletion timeline

  • Selfie image: Deleted automatically after 30 days
  • Face embedding: Deleted when the event ends or you withdraw consent
  • Consent log: Retained for legal compliance (GDPR proof of consent)

No sharing of biometric data

Your face embedding is used only for photo matching. We never share it with third parties, never use it for marketing or advertising, and never build a face database for surveillance.

How we use your data

  • Photo delivery: Match your selfie to event photos and show you your gallery
  • Communications: Send match notifications, account updates, and support responses
  • Platform improvement: Analyze usage patterns to make the platform better (face recognition accuracy, UI improvements)
  • Event analytics: Provide organisers with aggregate stats (total scans, downloads). Never individual guest data
  • Referral programme: Track referral attribution (who referred whom), calculate commission earnings, process payouts via SEPA. Your IBAN and NIF are used only for bank transfer processing and our tax obligations, never shared with third parties
  • Security: Detect and prevent fraud, abuse, and unauthorized access
  • Legal compliance: Retain records as required by law

Who we share data with

We do not sell your data. Data is processed by trusted service providers only:

Supabase (EU)

Database, storage, authentication. Supabase is GDPR-compliant and EU-hosted.

Vercel (US/Global CDN)

Application hosting and content delivery. Data transferred via Standard Contractual Clauses (SCCs).

Stripe (US)

Payment processing. We do not store card data. Stripe is PCI-DSS compliant.

Resend (US)

Transactional email delivery (match notifications, account alerts). Data transferred via SCCs.

Railway (EU — europe-west4, Netherlands)

Face recognition microservice — processes facial embeddings to match guest selfies to event photos. Data transferred via Standard Contractual Clauses (SCCs).

Referral programme data

If you participate in the TIME&SPACE referral programme, either as a referrer sharing your link, or as a referred organiser who signed up via a referral link, we process the following data:

If you refer others

  • Your unique referral code and link slug are generated automatically when you register and stored on your account
  • We record how many times your referral link has been opened (a click count, no personal data about link visitors is collected)
  • We record which accounts signed up using your link, and whether those accounts subsequently paid for events, in order to calculate your commission
  • Commission earnings (amount, rate, event ID, payment status) are stored as financial records
  • When you request a payout, we collect your IBAN and NIF (tax number) to process the SEPA bank transfer and meet our tax reporting obligations under Portuguese law. These are not used for any other purpose

If you signed up via a referral link

  • We record which referrer's code was used when you created your account (attribution)
  • Your paid event history (event count) is used to calculate the referrer's commission during the 90-day commission window from your sign-up date
  • A transparency notice is displayed in the Terms of Service so you are aware a commission may be paid. The commission does not affect the price you pay

Legal basis

Referral attribution and commission calculation: Legitimate interest (operating the referral programme, fraud prevention). Payout processing and financial records: Legal obligation (Portuguese tax law, Artigo 123.º CIRS requires financial records to be kept for 7 years).

Your rights regarding referral data

You may request deletion of your referral data (click history, attribution, earnings records) at any time by emailing [email protected]. Note that financial records (paid commissions, IBAN, NIF) may be retained for up to 7 years under tax law even after an account deletion request.

Full programme terms are at timeandspace.app/terms#referral.

How long we keep your data

Selfie images

Deleted automatically after 30 days

Face embeddings

Deleted when the event ends or you withdraw consent

Event photos

Kept for the event's retention period (configurable: 30, 90, or 365 days). Default: 180 days

Account data

Retained until you request deletion. You can delete your account anytime.

Consent logs

Kept indefinitely for legal compliance (GDPR proof of consent)

Payment records

Kept for 7 years (Portuguese tax law, Artigo 123.º CIRS)

Referral earnings

Commission records retained for 7 years (Portuguese tax law). IBAN and NIF stored only after a payout is requested; retained for 7 years as financial records. Referral attribution data (who referred whom) retained as long as your account is active, then deleted with your account

Analytics

Anonymised aggregate data kept for service improvement

Your rights

Under GDPR and similar privacy laws, you have these rights:

Right to access

Request a copy of all data we hold about you in a portable format (CSV, JSON)

Right to deletion ("right to be forgotten")

Request deletion of your account, photos, face data, or consent logs. We will delete within 30 days (some data kept for legal reasons).

Right to correction

Update your account information through your dashboard or request corrections via email

Right to restrict processing

Request that we stop using your data (except for legal obligations)

Right to data portability

Export your data in a machine-readable format to move to another service

Right to object

Opt out of marketing emails, analytics, and certain legitimate interest processing

Right to withdraw consent

Withdraw consent for face recognition anytime. No penalty.

To exercise any of these rights, email [email protected] with your request. We will respond within 30 days.

International data transfers

TIME&SPACE is based in the EU (Portugal), and most data is stored in the EU (Supabase). Some processors are based outside the EU (US).

When we transfer data outside the EU, we use Standard Contractual Clauses (SCCs) to ensure equivalent protection. For US processors, we rely on adequacy decisions or adequacy mechanisms.

You have the right to know which countries your data travels to. Contact [email protected] for a list of all data processors and their locations.

Cookies

Cookies are small files stored on your device. We use them minimally:

Essential cookies

Session tokens (NextAuth), CSRF protection. These are required for security and cannot be disabled.

Analytics cookies

Optional. Used to understand how you use the platform (e.g., which pages are popular). We use Google Analytics (GA4) and Meta Pixel for this purpose. You can opt out in your cookie consent settings.

No advertising cookies

We do not use cookies to track you across websites or show targeted ads.

B2C app: Guest profiles and social features

The TIME&SPACE mobile app allows registered users to create a guest profile, RSVP to events, follow other users, and discover events. The following data is processed when you use these features:

Guest profile data

  • Name and profile photo (optional)
  • Date of birth (used for age verification, minimum 16 years old)
  • Events you have RSVPed to (visible to your followers unless set to private)
  • Your follow/follower list
  • Photos matched to you at events you attended (linked to your profile)

Social discovery

When you follow another user, your followers can see which public events you have RSVPed to, so they can discover events through your activity. You can set individual RSVPs to private at any time. We show your social context to help others find events. For example, "2 people you follow are going to this event." We do not share your name with other users in this context without your consent.

AI Concierge conversations

If you use the AI Concierge tab, your conversation history is stored for up to 30 days. Conversations are private. They are never shared with other users. They are included in your data export (DSAR) and deleted when you delete your account. The Concierge is clearly identified as an AI assistant and does not share your data with any AI training systems.

Legal basis for processing: Legitimate interest (providing the social and discovery features you actively use). You can withdraw from social features at any time by deleting your guest profile in Settings.

Public profiles (organisers & photographers)

Organiser and Photographer accounts can create a public profile page at timeandspace.app/u/[username]. This is optional and fully controlled by you.

What is publicly visible

  • Your display name and profile photo
  • Your bio and location (if you have added them)
  • Social links you have added (website, Instagram, TikTok, etc.)
  • Event albums you have published

Your account email, phone number, billing information, and all private fields are never shown on your public profile.

Username and URL

Your chosen username forms your public URL. Usernames can be changed once every 30 days. When you change your username, your old URL redirects to your new one for 90 days, after which it becomes available to others. Your previous username is stored during this redirect window and permanently deleted once the 90-day window expires.

Visibility control

Your public profile is visible by default once you set a username. You can hide it at any time in Account Settings → Public Profile. Hiding your profile makes the page private but does not delete your username or data. You can re-enable visibility at any time.

Legal basis for processing: Legitimate interest in providing a professional presence on the platform. You can withdraw at any time by hiding your profile or deleting your account.

Push notifications

The TIME&SPACE mobile app may send push notifications. Under EU law, push notifications require your prior consent. We use two separate consent categories:

Photo match alerts (transactional)

Notifies you when your photos are ready, or when new photos have been matched to your face at an event. These are functional notifications directly related to the service you are using.

News and offers (marketing)

Notifies you about new events, platform features, or promotions. These require separate opt-in consent and are off by default.

You can change your push notification preferences at any time in Settings → Notifications. Withdrawing consent stops future notifications immediately. Your consent choices are logged in our system with a timestamp.

App store data (Apple & Google)

When you download or use the TIME&SPACE app from the Apple App Store or Google Play Store, Apple and Google may collect analytics and diagnostic data according to their own privacy policies. This data is collected by Apple and Google directly, not by TIME&SPACE.

For information on what Apple collects, see apple.com/privacy. For Google, see policies.google.com/privacy.

Data export (DSAR)

You have the right to request a full export of all personal data we hold about you (Data Subject Access Request or DSAR). For registered users, this is available directly from your account settings:

  1. Go to Settings → Account
  2. Select "Export my data"
  3. Your data export (JSON format) will be ready within 30 days
  4. The export includes: your profile, events, matched photos, scan history, notifications, referrals, and AI Concierge conversation history

You can also request your data by email at [email protected] with subject line "Data Export Request". We will respond within 30 days.

Children and minimum age

Minimum age: 16 years old, worldwide. There are no country exceptions. This applies to creating a guest profile, RSVPing to events, and using the B2C mobile app. This rule satisfies GDPR Article 8 (EU standard) and exceeds the minimum requirements of COPPA (US, under-13).

At registration, we collect your date of birth. If you are under 16, you will not be able to create an account. The platform shows you a message explaining that you can still use TIME&SPACE at events by scanning the QR code without creating an account. No age restriction applies to anonymous event scanning.

We do not knowingly collect personal data from children under 16. If we discover that a user is under 16, we will delete their account and all associated data immediately.

California (CCPA/COPPA): Our 16+ worldwide gate automatically satisfies COPPA (US children under 13). California residents have the right to know what personal data we collect, request deletion, and opt out of any sale of data. TIME&SPACE does not sell personal data. To exercise CCPA rights, email [email protected] with subject "CCPA Request."

Contact & complaints

Contact us

Privacy inquiries: [email protected]

General inquiries: [email protected]

Address: Lisbon, Portugal

EU Digital Services Act (DSA) contact point

TIME&SPACE is established in Portugal (EU). Our designated DSA contact point for authorities, trusted flaggers, and users making DSA-related requests is:

Email: [email protected]

Subject line: DSA Request

Response time: Within 5 working days

Supervisory authority

If you have privacy concerns, you can lodge a complaint with your data protection authority:

Portugal: CNPD (Comissão Nacional de Proteção de Dados)
EU: Contact your national data protection authority (search at edpb.ec.europa.eu)
California (CCPA): See our Children and minimum age section above for full CCPA rights. In summary: TIME&SPACE does not sell personal data. To exercise CCPA rights, email [email protected] with subject "CCPA Request".

You also have the right to use the EU Online Dispute Resolution platform for disputes.

Changes to this policy

We may update this policy. Material changes will be announced via email and on this page. Continued use after changes means you accept the new policy.

Questions about your data?

We're committed to being transparent about how we handle your information. If you have any questions or concerns about your privacy, contact us at [email protected].

You also have the right to lodge a complaint with your national data protection authority. We will cooperate fully with any investigation.

Terms of Service · Home