Legal
Privacy Policy
What FiveFrames collects, why, who can see it, how long we keep it, and your rights.
Last updated 11 October 2026
Who we are
FiveFrames runs the FiveFrames web app and is responsible for the personal information described here. Contact us about privacy at privacy@fiveframes.app.
What we collect
From hosts:
- your email address and password (the password is stored only in a form we can’t read);
- your events: name, date, timezone, welcome message, event image, hashtag, colour and settings;
- payment records: the plan, amount, method, reference and dates. We don’t store card details.
From guests (no account, email or phone number is needed):
- the display name you enter;
- the photos you keep, any message you add, and when you kept them;
- a cookie that remembers your place in that one event.
Inside photo files: the original is kept exactly as uploaded, so it may include details your phone added, such as when and where it was taken and the device. The host, and the guest who took it, can download that original. The copies shown on screen, in the gallery and in keepsakes have those details removed.
From everyone: our hosting provider records technical information about each request, such as IP address, browser and time, for security and to fix problems.
How we use it
- to run events: capture, galleries, downloads, keepsakes and signage;
- to show photos only to the people the event’s settings allow;
- to take and record payments and handle refunds;
- to support hosts, including through support access (below);
- to keep FiveFrames secure and to fix problems;
- to tell hosts when their event is about to end.
We don’t sell personal information, show advertising, or use photos to train AI. There is no face recognition or other automated analysis of what is in a photo.
Who can see the photos
- The host sees every photo kept at their event and can download the originals.
- Each guest sees and can download their own photos.
- Once the host reveals the gallery and makes it open to link holders, anyone with the gallery link can view it. Hidden photos never appear there.
- Anyone a guest shares a keepsake with sees that keepsake. It never shows the guest’s name, other guests’ photos or a link into the event.
- FiveFrames staff, through support access, on the host’s behalf (below).
- Our service providers, only to store and deliver them for us.
The event image the host chooses is shown to everyone who opens the event link, on signage and on keepsakes.
FiveFrames staff and support access
FiveFrames staff set up, run and support events, often without being at the venue. To do that on a host’s behalf, an authorised member of our team can open any event’s own host pages and act as the host would, without asking first. In support access, staff can:
- change the event’s details, look, gallery and sharing settings, open and close capture, reveal the gallery, and replace or turn off its links;
- see the event’s photos, and hide or unhide them;
- download the original photos, one at a time or all together, for example to send them to the host;
- make a guest’s Full Set keepsake, as the host can.
Staff in support access can’t change the plan or take payment, request a refund, delete the event or any photo, favourite a photo, or change anything about a guest’s five frames.
Every action in support access is permanently recorded, including each time staff view the photos, download an original or make a keepsake. The host’s event page lists what FiveFrames support did and when. Nobody, including our staff, can edit or delete that record.
Service providers
We use these providers to run FiveFrames. They process information only on our instructions:
- Vercel, to host the app;
- Supabase, for our database and host sign-in;
- Cloudflare, to store photos and event images;
- a payment provider, if you pay online.
Some of them process information outside the Philippines, including in Singapore and the United States. We use them under terms that require them to protect it.
How long we keep it
Photos, their messages, every copy made from them and the event image are permanently deleted 30 days after the event’s hosted access ends (Free for 7 days, Standard for 6 months and Premium for 12 months). We can’t recover them after that.
We keep the host account, the event’s record (its name, date and settings), guests’ display names, payment records and the support access record after that, for as long as the account exists or as long as the law requires us to keep financial records. Ask us to delete them and we will, unless we must keep them by law.
Your rights
Under the Data Privacy Act of 2012, you can ask to be informed about and get a copy of your personal information, have it corrected, object to its processing, have it deleted or blocked, and receive it in a portable form. You can also complain to the National Privacy Commission.
To make a request, email privacy@fiveframes.app. Guests: tell us the event and the display name you used, so we can find your photos. We may ask you to show it’s you before we act. Hosts can also hide or delete a guest’s photos directly.
How we protect it
Photos are kept in private storage, never at public web addresses. Each one is shown through a short-lived link issued only after an access check. Only a few authorised staff have support access, and everything they do is recorded and shown to the host.
Children
Hosts must be adults. Guests under 18 should join with a parent’s or guardian’s permission. Hosts are responsible for running their event in a way that respects the people photographed at it.
Changes to this policy
If we change this policy in a way that matters, we’ll update this page and tell hosts before the change applies to them.
See also our Terms of Service.