01Information we collect
To run the service we collect:
- Account details: your name, email address, and (optionally) phone number.
- Event photos: images uploaded by event organizers, photographers, or guests.
- Selfies & facial data: the selfie you submit to find yourself in an event, and the numeric face signature derived from it (see “Facial recognition” below).
- Usage & device data: basic analytics, device information, and IP address, used to operate and secure the service.
- Payment data: handled by our payment providers, Paymob or SuperPay. We never see or store your full card number, expiry, or security code.
02How we use your information
- To deliver the photo-matching and gallery service you signed up for.
- To match faces between your selfie and event photos so you receive the right images.
- To communicate with you about your account, events, and purchases.
- To operate, secure, troubleshoot, and improve the service.
- To meet legal, tax, and accounting obligations.
03Facial recognition
When you submit a selfie to find your photos, our system converts it into a numeric face signature (a mathematical vector) and compares that signature against faces detected in event photos. This signature is what powers matching. It is not a usable picture of your face.
A face signature is biometric data and we treat it as sensitive. We use it only to match you to photos within events you choose to join, and you can delete it at any time, which removes you from future matching.
04How your data is protected
Your data is hosted on Google Cloud infrastructure. It is encrypted in transit using TLS (HTTPS) and encrypted at rest by the storage platform. Saved payment tokens are additionally encrypted by us using AES-256-GCM before storage.
We restrict internal access to personal data and keep applying reasonable technical and organizational safeguards. No online service can promise perfect security, so we describe what we actually do rather than over-promise.
06Data retention
We keep your data while your account is active and for as long as needed to provide the service and meet legal obligations. When you delete your selfie, account, or an event, the associated data is removed from our active systems. Backups age out on a rolling basis.
07Your rights
You can:
- access the personal data we hold about you;
- correct inaccurate information;
- request deletion of your data, including your face signature;
- opt out of non-essential communications;
- control which events can match your selfie.
To exercise any of these, use the controls in your account or email privacy@dsprs.com. If you are in the EU/EEA or UK, see our GDPR page for how these rights map to GDPR.
08Children
DSPRS is not directed to children. We do not knowingly create accounts for, or build face signatures of, children under the age required by local law without appropriate consent. If you believe a child’s data is in the service, contact us and we will remove it.
09Family photos and children (“My Family”)
A signed-in adult can add household members, such as their children or partner, to their own account so that events they attend also find photos of those people. This is optional and only the account holder can add, pause, or remove a family member.
- Consent: before a child is added, the adult must confirm that they are the child’s parent or legal guardian and accept the consent text shown in the app. For an adult family member, the account holder confirms that person knows and agrees. We record the consent version and time.
- What we store: the name and relation you enter, an optional birth year, up to three reference photos of that person, and the private face signature derived from those photos (the same kind of numeric signature described under “Facial recognition”).
- How it is used: only to find that person in photos of events you join and have chosen to include them in. Family members are never used for public search or for “discovery” across events you did not attend, and their reference photos are never shown to other guests or organizers.
- Organizer verification: some organizers (for example a school) may confirm a child against their own roster or restrict matching to verified children. That confirmation is visible to you in the app; the organizer does not receive the reference photos you added.
- Deletion: you can remove a family member at any time. Removing them deletes their reference photos and face signature and stops matching immediately; you choose whether the event photos already delivered to your gallery are kept or also deleted. Deleting your account removes all family members with it.
- One face per person: your own selfie, and each family member’s reference photo, may only be replaced by a photo of the same person. If a new photo looks like someone else, we decline it and offer two honest options: add that person as a family member, or ask for a review if it really is you. Reviews are decided by the organizer that verified you or by our team, and both photos are visible only to the reviewer.
- Purchases are per person: where an organizer sells photos, a purchase unlocks the photos of the person it was made for, whether that is you or one family member. Photos of another family member are a separate purchase, and some organizers (for example sports events) may allow purchases for the ticket holder only.
If you believe someone has been added to a family without the right to do so, contact us at privacy@dsprs.com and we will investigate and remove the data.
10Who we are & how to contact us
This service is operated by DSPRS, based in Cairo, Egypt (Arab Republic of Egypt).
Privacy questions: privacy@dsprs.com · Data Protection enquiries: dpo@dsprs.com.
Registered entity: DSPRS · Cairo, Egypt. Full registration details available on request.
This policy is governed by the laws of the Arab Republic of Egypt.
