This Privacy Policy is the notice given by FABPix ("we", "us") under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Information Technology Act, 2000 and the rules made under it. It explains what personal data we collect when you use the FABPix app, websites and host dashboard (the "Service"), the purposes for which it is processed, how we protect it, and the rights you have. It should be read with our Terms & Conditions.
For the personal data we handle to run the Service, FABPix is the Data Fiduciary (the entity that determines the purpose and means of processing) and you are the Data Principal (the individual to whom the personal data relates). Our infrastructure providers act as Data Processors who process personal data on our behalf under contract. By providing personal data and using the Service you give your consent to the processing described in this notice; you may withdraw that consent as set out below.
1. What we collect
- Account data - your name, email address, and a profile photo if you add one. Sign-in is handled by Google Firebase Authentication; if you use Google sign-in, we receive your basic Google profile (name, email, photo).
- Event data - events you create or join, invite codes, event names and dates, your role (host/guest), and settings.
- Content you upload - the photos, videos and moments you capture, together with technical details such as file size, type and the time of upload, and the name shown as the uploader.
- Reports & moderation data - if you report content, or a host moderates it, we record that action.
- Usage & device data - basic logs needed to run and secure the Service (for example IP address, app version, and error diagnostics).
We do not perform facial recognition or build biometric profiles from your photos.
2. How we use it
- To provide the Service - create and run events, store your Content, show the shared album to event members, generate QR posters, and enable downloads and exports.
- To enforce plan limits (guest caps, storage, retention) and process add-ons.
- To keep the Service safe - moderation, handling reports, preventing abuse, and enforcing our Terms.
- To provide support and respond to your requests.
- To meet legal obligations.
We do not sell your personal data or your Content, and we do not use your Content for advertising.
3. Consent & lawful basis
Under the DPDP Act we process your personal data on the basis of your consent, which you give when you create an account, join an event and upload Content. Your consent is free, specific, informed, unconditional and unambiguous, and is limited to the purposes described in section 2 above (purpose limitation). We collect only the personal data that is necessary for those purposes (data minimisation).
We may also process personal data for certain legitimate uses permitted by the DPDP Act, such as complying with a legal obligation, responding to a legal claim, and keeping the Service secure and preventing fraud and abuse.
You may withdraw your consent at any time - for example by deleting your Content, deleting your event, or asking us to close your account. Withdrawing consent will not affect processing already carried out, and may mean we can no longer provide parts of the Service. Withdrawing consent is as easy as giving it.
4. People who appear in photos & videos
Event albums contain photographs and videos of real people, who are also Data Principals. The Event Host is the organiser who created the event and decides who is invited and what is captured; the host and their guests are responsible for photographing and uploading only people who are happy to be photographed and shared within that event, and for obtaining any consent required by law. FABPix processes this Content solely to operate the shared album for that event. We do not perform facial recognition, build biometric profiles, or use anyone's image to identify or track them. If you appear in an event's Content and want it removed, see section 8 and the notice below on contacting the Event Host.
5. Who we share with
- Other members of your event - Content you add to a shared album is visible to that event's host and guests. Hosts can see all Content in their event (including items pending moderation).
- Infrastructure providers - we use Google Firebase (authentication) and Cloudflare (application hosting, database, and media storage) to run the Service. They process data on our behalf under their own security and privacy commitments.
- Legal & safety - we may disclose data where required by law, to enforce our Terms, or to protect the rights and safety of users and the public (for example, reporting illegal content).
We do not share your personal data with third parties for their own marketing.
6. Storage & security
We maintain reasonable security safeguards as required by the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Content and data are stored with our infrastructure providers using access controls and encryption in transit. Access to Content is restricted to the members of the relevant event (and our systems that operate the Service). If a personal data breach occurs, we will notify the Data Protection Board of India and affected Data Principals as required by law. No online service can be guaranteed perfectly secure, so please keep your own copies of important media.
7. Retention & deletion
- Content is kept for the retention period of the event's plan, then permanently deleted by automated jobs.
- If a host deletes an event, its Content is retained for a grace period of 30 days (or the remaining retention days, if fewer) and then permanently deleted.
- Moments expire automatically 24 hours after upload.
- You can delete individual items, and hosts can delete any item in their event. Deleted media is removed from storage and cannot be recovered once purge jobs run.
8. Your rights as a Data Principal
Under the DPDP Act, as a Data Principal you have the right to:
- Access - obtain a summary of the personal data we process about you and the processing activities;
- Correction & completion - have inaccurate or incomplete personal data corrected, completed or updated;
- Erasure - have your personal data erased where it is no longer needed for the purpose it was collected or where you withdraw consent, unless retention is required by law;
- Withdraw consent - as described in section 3;
- Grievance redressal - have your complaint addressed by us first, through the mechanism in section 9;
- Nominate - nominate another individual to exercise your rights in the event of your death or incapacity.
You can edit your profile in the app, delete your Content and events, and contact us to delete your account. To exercise any of these rights, email [email protected] or contact our Grievance Officer below. We may need to verify your identity, and we will respond within the timelines set out in section 9. You also have the right to complain to the Data Protection Board of India if you are not satisfied with our response. You are responsible for the accuracy and truthfulness of the information you give us.
9. Grievance redressal
As required by the DPDP Act and the Information Technology Act, 2000 and the rules made under it, FABPix has appointed a Grievance Officer to address questions and complaints about how we handle your personal data and to receive requests to exercise your rights.
- Name: [grievance officer name]
- Email: [grievance officer email]
- Address: [address], Goa, India
- We will acknowledge your grievance within 24 to 48 hours of receipt.
- We will resolve it as soon as possible and in any event within 15 days of receipt.
10. Children
The Service is not directed at children under 18 years of age. A person under 18 may use the Service only with the verifiable consent of a parent or legal guardian given in a manner permitted by the DPDP Act. We will not knowingly process a child's personal data in a way that is likely to cause any detrimental effect on the child, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us personal data without appropriate parental consent, contact us and we will delete it.
11. Cookies & local storage
Our websites and dashboard use only essential cookies and local storage needed to keep you signed in and to remember your session and preferences. We do not use third-party advertising or tracking cookies.
12. International transfers
Our providers (Google, Cloudflare) operate global infrastructure, so your data may be processed on servers located outside India. Where this happens, we rely on those providers' safeguards for such transfers, and we will not transfer personal data to any country that is restricted by the Central Government under the DPDP Act.
13. Changes & contact
We may update this Privacy Policy from time to time; the current version is always on this page and material changes will be notified in the app or on the website. For any privacy question or request, contact [email protected].
