← Back to Highlite Venue

Privacy Policy

Last updated: September 2026

1. Who We Are

Highlite Venue is a collaborative photo and video sharing platform for events. The data controller is Highlite Venue. Privacy questions: [email protected]

2. Data We Collect

  • Account data: username, email address, phone number, and an optional short bio and profile picture.
  • Content: photos and videos uploaded to moments.
  • Usage data: moments created or joined, timestamps, device type.
  • Payment data: subscription and purchase history (processed by RevenueCat — we do not store card details).
  • Anonymous participation: joining via QR code stores a session identifier and timestamp only.

3. How We Use Your Data

  • To provide and operate the Highlite Venue service.
  • To send account verification and transactional notifications (email and SMS).
  • To send push notifications about your moments (opt out in device settings).
  • To process payments and manage subscription entitlements.
  • To enforce our data retention policy and moment lifecycle.

We do not sell your personal data. We do not use your data for advertising profiling.

4. Data Retention

Your data is retained as long as your account is active. Moments follow this lifecycle:

Free tier

Moments and all media are permanently deleted 90 days after creation. No recovery is possible.

Creator & Business tier

Active for 24 months from creation, then permanently deleted. If your subscription ends, remaining retention is capped at 60 days (restored in full if you resubscribe). On-demand moments keep the full 24 months regardless of subscription.

⚠ Permanent deletion means no recovery is possible under any circumstances.

Upon account deletion, all of your personal data and the moments you own — including every photo and video in them — are erased within 30 days.

Photos and videos you contributed to someone else’s moment are an exception: they stay with that moment, because they are part of another person’s event and removing them would take content away from everyone who was there. Your account is unlinked from them, so nothing identifies you as the contributor, and they are deleted along with that moment when it reaches the end of its own retention window above. If you want a specific contribution removed before then, delete it from the moment before deleting your account, or ask the moment’s owner to remove it.

5. Third-Party Processors

ProcessorPurposeData shared
TwilioSMS verificationPhone number
Firebase / Google CloudPush notifications, social login, analytics, crash reportingDevice push token, Google account ID, advertising ID, app usage and crash data
WasabiObject storage for photos and videosUploaded media files
RevenueCatIn-app purchases & subscriptionsUser ID, purchase history

Each processor operates under a Data Processing Agreement and is contractually required to protect your data in accordance with GDPR.

6. Cookies & Local Storage

We use browser local storage to keep you logged in (authentication tokens) — strictly necessary to provide the service. We do not use third-party tracking or advertising cookies. On mobile, our analytics and crash reporting (Firebase) accesses your device advertising ID to measure app usage and diagnose faults. We do not use it to build advertising profiles or to target ads, and we do not sell it.

7. Your Rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • Access — export all your data (Settings → Download My Data).
  • Rectification — update your profile in Settings at any time.
  • Erasure — delete your account and all data (Settings → Delete Account).
  • Data portability — export as JSON (Settings → Download My Data).
  • Objection / restriction — contact [email protected].
  • Lodge a complaint — contact your local supervisory authority.

8. Children

Highlite Venue is intended for adults aged 18 and over and is not directed at children. If you believe a minor has created an account, contact [email protected] and we will delete it promptly.

9. Security

All data in transit is protected by HTTPS. Passwords are hashed. Media files are stored on encrypted S3-compatible object storage. JWT-based authentication uses short-lived access tokens.

10. Breach Notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours. Affected users will be notified without undue delay where the breach is likely to result in a high risk to their rights.

11. Contact

Questions? [email protected]