PopStudio.

Our privacy position

No face recognition,
ever

PopStudio collects no biometric data. It runs no face matching. It never will. A guest is joined to their photos by a five-character code they were handed themselves — nothing in the system looks at a face.

  • No faceprints, templates or embeddings. None are created, stored or bought in.
  • No scanning the crowd. A guest who does not check in is never matched to anything.
  • No age estimation, no advertising trackers. Not on the guest phone, not anywhere.
  • Photos expire on a timer and guests can delete their own at any moment.
See exactly what we collect Ask a privacy question

The mechanism

How other platforms do it. How we do it.

This is the whole difference. It is worth two minutes, because everything else on this page follows from it.

The common approach

Match by face

A guest uploads a selfie. The platform turns that face into a mathematical template — a faceprint — and compares it against every face in every photo from the event.

It genuinely works, and it works at festival scale. That is why big events use it. The cost is that a biometric identifier now exists for every guest who was scanned, and often for people who simply walked through the frame and never asked to be in anything.

selfie → faceprint → searched against every photo

PopStudio

Match by code

A guest scans one printed sign while queuing, types their name and email, and gets a five-character code with a QR on their phone.

At the front of the line the operator scans that code, shoots, and taps Done. The code is the join. It is issued to one person, held by that person, and shown by that person. No face is measured at any point in the chain.

K4M9T → scanned at the station → those photos, that inbox

New Zealand

The Biometric Processing Privacy Code

The Office of the Privacy Commissioner issued a Biometric Processing Privacy Code in 2025. It is in force now, and deployments that were already running must comply by 3 August 2026.

If a tool does automated facial recognition, the Code puts real work on whoever runs it:

  • A privacy impact assessment before you switch it on.
  • A proportionality test — is the benefit worth the privacy cost, and is there a less intrusive way to get the same result?
  • Explicit notice to the people being processed, in plain language, where they will actually see it.

That is a sensible bar for anyone building a face database. It is also a bar a volunteer running a Friday youth night should not have to clear.

Where PopStudio sits

PopStudio performs no biometric processing, so the Code does not apply to it. There is no assessment to file, no proportionality argument to construct, and no biometric notice to write, because there is no biometric anything.

You still have ordinary privacy obligations — tell people what you are collecting, keep it safe, use it only for what you said. Those apply to any event photography. The Code is the extra layer, and choosing a non-biometric tool is how you step around it rather than through it.

Read the Code at privacy.org.nz →

This is information, not legal advice. We are a photography platform, not your lawyer. We have summarised a public Code in plain words and linked the source so you can read it yourself. If your organisation has a specific obligation — a school, a health provider, a government agency — take proper advice on it.

Australia. Biometric data is sensitive information under the Privacy Act, which means it needs consent before it is collected. Separately, the OAIC is developing a Children's Online Privacy Code, due to be registered by December 2026, which treats under-15s as unable to consent for themselves. The first question does not arise here, because no biometric data is collected at all. The second sits with you as the organiser: if consent is needed for a young person, you obtain it your way, before the event.

Consent

Nobody is in the system by accident

Check-in is the consent. It is a deliberate act, taken on the guest's own phone, before any photo exists.

01

They choose to scan

One static QR sign near the queue. Reading a sign is not consent; scanning it is a choice.

02

They enter their own details

Name and email, typed by the guest. We never buy, guess or import a guest list.

03

They get a code

Five characters plus a QR. Showing it at the station is the second, in-person confirmation.

04

No code, no match

A guest who never checks in is never matched to anything. There is no "find me in the crowd".

The same check-in for everyone

There are no per-event consent settings and no branching paths. Every guest gives a name and an email address, and their photos go to that address. We do not ask anyone's age, and nothing in the system treats one guest differently from another. Deciding who is photographed at your event, and obtaining any permission your policy or the law requires, is the organiser's call.

Children & young people

You decide who is photographed. We never ask an age.

PopStudio has no minor path, no age question and no parental-consent step. It cannot tell a fourteen-year-old from a forty-year-old, and it does not try. Every guest gives a name and an email, and their photos go to that address.

That means consent sits where it always really sat: with the organisation running the event. You are the one collecting the information and taking the photographs; we process it as your agent, under the Terms of Service. If your safeguarding policy or the law where you operate requires a parent's permission before you photograph a young person, you obtain it your way, before the event.

What the product does guarantee is narrower and checkable. Nobody is photographed unless they chose to check in and showed their code. Nothing biometric is collected, so no face is measured and no age is estimated. Photos go to the address that guest typed, and to no gallery. Every delivery email carries a delete button that works, and everything expires on the retention clock whether or not anyone remembers.

If a parent wants photos of their child sent to their own inbox, they can simply use their own email address at check-in. That is a choice they make at the sign, not a mode you configure.

Retention

Photos do not live here forever

Every photo has an expiry from the moment it is taken, and every guest has a delete button they do not need our permission to use.

The clock

Default retention is 30 days. You can set 7, 30, 90 or 365 to suit your organisation's own policy. The free test drive keeps photos for 7 days.

The purge

A job runs daily and deletes everything past its date. After that the guest's photo page says "Photos expired" — a plain answer, not a broken grid of missing images.

The button

Every guest photo page carries a delete button. Tapping it removes the stored objects. No email to us, no waiting, no form.

What "deleted" actually means

The stored files are removed — both the original camera file and the developed version — and the database rows that pointed at them go too. It is not a hidden flag or a trash folder we keep. One honest caveat: a group photo belongs to everyone in it, so it survives until the last participant deletes it. One person's deletion removes it from their page and their copy; it does not delete other people's copies out from under them.

The full list

What we collect, exactly

Not a summary. This is the list.

CollectedWhyNever collected
Name So the operator can call the right guest forward and the email reads like a human wrote it. Faceprints — no face is ever measured.
Email address It is the delivery address. That is its only job. Biometric templates or embeddings of any kind.
A five-character code, issued at check-in It is how photos are joined to the right guest. Nothing else does that job. Age, or anything about it — we never ask, and we never infer.
The photos They are the product. They are what the guest came for. Advertising or analytics trackers on the guest photo page.
Timestamps — check-in, capture, delivery To run the queue, honour retention, and answer "did mine send?" Location, contacts, or anything else on the guest's phone.

Guest data is never sold, never rented, and never passed to an advertiser. It is used to deliver photos to the person who asked for them, and for nothing else.

Infrastructure

Where it lives

Storage

Photos are stored on Cloudflare R2, encrypted in transit and at rest.

Access

Your team sees your own events, and nobody else's. We do not browse customer photos. Staff access exists only to keep the service running and to fix something when you ask us to.

Sub-processors

Cloudflare for hosting, database and photo storage, and an email delivery provider to send the link. That is the list. There is no analytics vendor and no ad network in it.

PopStudio is operated by System Advance Limited, a New Zealand company. Full detail is in the Privacy Policy.

If you are a guest

You checked in, and you want your photos changed or gone

You do not need us for that. The delete button on your own photo page does it. If the link never arrived, or you want to know what is held about you, the guest help page walks through both.

Guest help →

Ask us

Send us the hard question

Board papers, a school policy review, a privacy officer with a checklist — send it through. We would rather answer a pointed question before your event than a complaint after it. Real answers from the people who built the system.

Ask a privacy question