Legal
Privacy policy
What PopStudio collects, who actually holds it, how long it survives, and the things we have decided never to build.
Effective 31 July 2026 · System Advance Limited, New Zealand
This is a template, pending professional review. This policy was drafted in-house so it says what PopStudio actually does, and it is being reviewed by a New Zealand lawyer before launch. It is not legal advice, and it may change. When the reviewed version is published we will update the date at the top of this page and email account holders.
The short version
A summary, in human sentences. The sections below are the actual policy.
- We do not scan faces. No facial recognition, no faceprints, no age or emotion estimation. A person types a five-character code. That is the whole matching system.
- We hold guest details for the organisation, not for us. The church, photographer or venue running your event is the one collecting your information. We are their service provider and we never use it for our own purposes.
- We collect very little. From a guest: name, email, their check-in code, the photos, and timestamps. Nothing else — we never ask an age.
- Consent is the organiser's job. Any permission needed before someone is photographed, including a parent's for a child, is obtained by the organisation running the event, before the event. We have no consent step of our own.
- Photos delete themselves. 30 days by default, or 7, 90 or 365 if the organiser sets it. A job runs every day and removes them.
- You can delete your own photos, right now. There is a button on your photo page. It is immediate and permanent.
- No trackers, no ads, no analytics. One session cookie so you can stay signed in. That is the complete list.
- Two sub-processors. Cloudflare for hosting, database, storage and email. Stripe for payments, which is not live yet.
- We never sell your information, and we never train models on your photos.
Who we are
PopStudio is operated by System Advance Limited, a company incorporated in New Zealand. We serve customers in New Zealand and Australia.
PopStudio is software that event organisers use to run a pop-up photo station: a real photographer with a real camera tethered to a laptop. Guests scan a QR sign, check in on their phone, get a five-character code, have their photo taken, and receive a link to their photos by email about a minute later.
This policy covers both sides of that: the organisations who hold PopStudio accounts, and the guests whose photographs pass through it.
What we collect from customers
When your organisation creates an account we collect:
- Your name and email address.
- Your organisation name, industry and country.
- An optional description of what you want to use PopStudio for.
- A password hash — a one-way scramble. We never store your actual password and cannot recover it for you.
- Event settings you configure: event names, dates, retention period, your overlay.
- Basic operational logs needed to run and secure the service.
For this information, we are the agency under the Privacy Act 2020. We use it to give you an account, verify you, run your events, send receipts and cap warnings, and answer your support requests.
What we collect from guests
When a guest checks in at an event, PopStudio holds:
- Their name.
- Their email address, so the photos can be sent to them.
- The five-character code issued at check-in, which is how photos are joined to a guest.
- The photographs taken of them at that event.
- Timestamps: when they checked in, when the photos were taken, when they were delivered.
That is the whole list. We do not ask for a phone number, an address, a date of birth, an age, a gender, or anything else. We do not ask for anyone else's contact details. We do not buy data about guests, and we do not enrich or append anything to what a guest typed in.
We do not collect biometric information
PopStudio performs no biometric processing of any kind. We do not create faceprints or facial templates. We do not run facial recognition, facial matching, face clustering or face search. We do not estimate age, emotion, gender or ethnicity from a face. We do not generate, store or share any biometric identifier.
Photographs are images. We treat them as images: we develop them, resize them, put them behind a link for the guest, and delete them on schedule. Nothing analyses the face in them.
The way a guest gets their photos is deliberately boring — the guest checks in, gets a five-character code, and the operator types that code before shooting. A human matching a code, not a machine matching a face. This is a design decision, and it is one we are not planning to revisit.
We also do not permit customers to run face recognition against PopStudio output. That is in our acceptable use terms.
How we use information
We use guest information for exactly one thing: delivering the guest's photos and running the event the organisation asked us to run. That means matching the code to the person, developing and storing the photographs, emailing the link, serving the photo page, and deleting everything on schedule.
We use customer information to operate your account: authentication, verification, billing, event administration, support, security, and service notices.
We do not sell personal information. We do not share it with advertisers. We do not use guest photographs or guest details to train machine-learning models, ours or anyone else's. We do not use guest photographs in marketing without separate written permission from the customer who owns them.
Our role: agent for the organisation running the event
The organisation running the event is the agency collecting guest information. System Advance Limited holds and processes guest information solely as that organisation's agent and service provider, on their instructions, and never for our own purposes. Under section 11 of the Privacy Act 2020, information held by an agent solely on behalf of another agency is treated as held by that other agency — so the organisation is the holder of guest information, not us.
This matters for three practical reasons.
- Who to ask. If you are a guest and you want to know why a photo was taken, or you want it corrected or removed, the organisation that ran the event is the place to start — although you can also just delete your photos yourself, see below.
- Who tells you what. The organisation is responsible for its own privacy statement and for the notice it gives you at the event.
- Offshore storage. Because we hold the information solely as the organisation's agent, and our sub-processors hold it solely as ours, storing it on infrastructure outside New Zealand is not a disclosure under information privacy principle 12. The information stays with the organisation as its holder. We still hold our sub-processors to protective standards, as described below.
Where an organisation is covered by the Australian Privacy Act 1988, the same structure applies: they are the APP entity, and we act for them.
Sub-processors we use
We keep this list short on purpose. Every name here is a company we could not run without.
| Provider | What they do for us | What they hold |
|---|---|---|
| Cloudflare | Application hosting (Workers), database (D1), photo storage (R2), and sending the delivery emails | Everything: account records, guest check-ins, photographs, email delivery |
| Stripe | Payment processing. Not live yet — we are not charging cards through it today | Customer billing details only. Never guest information, never photographs |
That is the entire list. There are no advertising networks, no analytics providers, no session recorders, no marketing pixels and no data brokers in PopStudio. If that ever changes we will update this page and email account holders before it takes effect.
Where data is stored, and international transfers
PopStudio runs on Cloudflare's global network. Data is held in Cloudflare's D1 database and R2 object storage, and may be stored on or served from servers outside New Zealand and Australia. Current storage region configuration: [storage region setting to be confirmed].
As explained above, because we hold guest information solely as the customer organisation's agent, and Cloudflare holds it solely as ours, this arrangement is not an IPP 12 disclosure — the organisation remains the holder throughout.
That does not get us off the hook for looking after it. We only use sub-processors who are contractually bound to protect personal information, to process it only on our instructions, to keep it secure, and not to use it for their own purposes. For Australian customers, we take reasonable steps consistent with APP 8 in choosing and contracting with them.
Retention and automated deletion
Photographs delete themselves. The default retention period is 30 days from the event. The organisation running the event can set it to 7, 30, 90 or 365 days instead, depending on their plan and their own policy.
An automated job runs daily and purges everything past its retention date: the stored image objects, and the guest records that go with them. It is not a flag in a database that hides the photo. The objects are removed.
Customer account records are kept while the account is open. When you close your account we delete your events, guests and photographs through the same purge process. We keep financial and tax records for as long as New Zealand law requires us to, and minimal security logs for a short period so we can investigate abuse.
Guests: deleting your own photos
Every guest photo page has a delete button. You do not need to email anybody, prove who you are, or wait for an organiser to get back to you.
- Open the link that was emailed to you.
- Scroll to the bottom and choose to delete your photos.
- Confirm.
It is immediate and it is permanent. The stored image objects are removed. We cannot restore them, and neither can the organiser. If you want to keep a copy, download it first.
Deleting your photos does not delete any copy the photographer kept on their own camera card or laptop — that is theirs and outside PopStudio. Ask them directly about that.
There is a fuller walkthrough written for guests on our guest help page.
Your rights under the Privacy Act 2020 and the Australian Privacy Principles
In New Zealand, the Privacy Act 2020 gives you the right to ask for access to personal information held about you, and the right to request correction of it. In Australia, the Australian Privacy Principles give you equivalent access and correction rights under APP 12 and APP 13.
How to use them with PopStudio:
- If you hold a PopStudio account (a customer), email privacy@popstudioapp.com. We are the agency for your account information and we will respond directly. New Zealand law gives us 20 working days; we aim to be much faster than that.
- If you are a guest, the organisation that ran the event is the holder of your information, so start with them. If you cannot reach them, or you are not sure who they are, email us anyway — we will help you identify the right organisation and pass the request on, and we will tell you what we did.
We will ask you to verify your identity before we release personal information, because handing it to the wrong person is its own privacy breach. There is no charge for a request.
How we protect information
- Everything travels over HTTPS. Photo links are served over TLS.
- Passwords are stored as one-way hashes, never in readable form.
- Guest photo pages are reached through unguessable links rather than public URLs, and are scoped to that guest's own photographs.
- Access to production data is limited to the people who need it to operate the service, and is used for operating and supporting the service — not for browsing.
- Storage and database access run through scoped credentials rather than shared logins.
- Retention limits are enforced by an automated daily purge rather than by anyone remembering to do it.
No system is perfectly secure, and we will not claim otherwise. What we can say is that the surface is deliberately small: few sub-processors, little data collected, and a short life for everything we hold.
If something goes wrong: breach notification
If we become aware of a privacy breach affecting information in PopStudio, we will:
- Tell the affected customer organisation without undue delay, and aim to do so within 72 hours of becoming aware, with what we know at that point rather than waiting for a complete picture.
- Help them assess whether it is a notifiable privacy breach — one likely to cause serious harm — and support the notifications they need to make.
- Where we are the agency, for example for customer account information, notify the Office of the Privacy Commissioner and the affected people ourselves, as the Privacy Act 2020 requires.
- Meet the Notifiable Data Breaches scheme obligations under the Australian Privacy Act where they apply.
- Write up what happened and what we changed.
Cookies, analytics and tracking
Plainly: PopStudio sets a single essential session cookie, and runs no tracking of any kind.
- The cookie is named
ps_session. It is set only when you sign in to a PopStudio account. It is HttpOnly, Secure and SameSite=Lax, and it expires after 30 days. Its only job is keeping you signed in. - No analytics. No Google Analytics, no product analytics, no heatmaps, no session recording.
- No advertising. No ad pixels, no retargeting tags, no conversion trackers, no third-party fonts or scripts phoning home.
- Guests browsing their own photo page are not given a tracking cookie at all.
That is also why the site loads as fast as it does. There is nothing on it that is watching you.
Children's information
PopStudio accounts are for adults. You must be at least 18 to hold one.
Children do get photographed at events — that is the reality of church youth nights, school events and family fun days — so we will be plain about what the platform does and does not do about it.
We do not knowingly treat any guest differently on the basis of age, because we never learn anyone's age. PopStudio does not ask for an age or a date of birth, does not estimate age from a photograph, and has no separate path, setting or consent step for children. Every guest gives their own name and email address, and their photographs are delivered to that address.
That means the organisation running the event is responsible for obtaining whatever parental or guardian consent its own policies and the applicable law require, before anyone is photographed. This is set out in the Terms of Service. It is their obligation, not ours, and nothing in the product substitutes for it.
What we do is narrower. No guest is photographed unless they choose to check in and present their code. Nothing biometric is collected. Photos are delivered only to the address that guest entered, and are never published in a public gallery. Everything deletes itself at the end of the retention period the organisation set.
If you are a parent and you want your child's photos gone, you can use the delete button on the photo page yourself. It works immediately, and you do not need anyone's permission. If you do not have the link, ask the organisation that ran the event, or email us at privacy@popstudioapp.com and we will pass the request to them and help them action it.
Complaints
Start with us. Email privacy@popstudioapp.com with what happened. We will acknowledge it quickly and give you a substantive answer, and if we got something wrong we will say so.
If you are not satisfied, you can complain to the regulator.
- New Zealand — Office of the Privacy Commissioner. privacy.org.nz. They can investigate complaints about how an agency handled your personal information.
- Australia — Office of the Australian Information Commissioner. oaic.gov.au. The OAIC generally asks you to raise it with the organisation first.
Remember that for guest information the organisation that ran the event is the holder, so a complaint about how photographs at an event were collected usually belongs with them. We will not hide behind that — tell us and we will help you work out who to talk to.
How to contact us, and when this applies from
Privacy questions, access requests, correction requests and complaints: privacy@popstudioapp.com. Anything else: hello@popstudioapp.com.
Effective date: 31 July 2026. If we make a material change to this policy we will post it here and email account holders before it takes effect.
Company details
- Legal entity
- System Advance Limited
- Trading as
- PopStudio
- Incorporated in
- New Zealand
- NZBN
- [NZBN to be added]
- Registered office
- [registered office address to be added]
- GST number
- [GST number to be added]
- Serving
- New Zealand and Australia
- General enquiries
- hello@popstudioapp.com
- Privacy requests
- privacy@popstudioapp.com
Anything in square brackets is a placeholder we have not filled in yet. We would rather show you a gap than a made-up number.