Skip to content

Our privacy position

No face recognition,
ever

PopStudio is a pop-up photo studio platform: a person with a real camera, guests who join the queue by QR, photos emailed minutes later. It collects no biometric data and runs no face matching, ever. A guest is joined to their photos by a five-character code they were handed themselves. Nothing in the system looks at a face.

  • No faceprints, templates or embeddings. None are created, stored or bought in.
  • No scanning the crowd. A guest who does not join the queue is never matched to anything.
  • No age estimation, no advertising trackers. Not on the guest phone, not anywhere.
  • Photos expire on a timer and guests can delete their own at any moment.
See exactly what we collect Ask a privacy question

The mechanism

How other platforms do it. How we do it.

This is the whole difference.

The common approach

Match by face

A guest uploads a selfie. The platform turns that face into a mathematical template, a faceprint, and compares it against every face in every photo from the event.

It genuinely works, and it works at festival scale. That is why big events use it. The cost is that a biometric identifier now exists for every guest who was scanned, and often for people who simply walked through the frame and never asked to be in anything.

selfie → faceprint → searched against every photo

PopStudio

Match by code

A guest scans one printed sign while queuing, types their name and email, and gets a five-character code with a QR on their phone.

At the front of the line the operator scans that code, shoots, and taps Done. The code is the join. It is issued to one person, held by that person, and shown by that person. No face is measured at any point in the chain.

K4M9T → scanned at the station → those photos, that inbox

Biometric privacy law

The rules you step around, not through

Privacy regulators in a growing number of places now treat face matching as a category of its own. Where those rules apply, running a tool that does automated facial recognition typically means real work for whoever deploys it:

  • A privacy impact assessment before you switch it on.
  • A proportionality test. Is the benefit worth the privacy cost, and is there a less intrusive way to get the same result?
  • Explicit notice to the people being processed, in plain language, where they will actually see it.
  • Consent, because biometric data is commonly classed as sensitive information that cannot be collected without it.

That is a sensible bar for anyone building a face database. It is also a bar a volunteer running a Friday youth night should not have to clear.

Where PopStudio sits

PopStudio performs no biometric processing, so none of that applies to it. There is no assessment to file, no proportionality argument to construct, and no biometric notice to write, because there is no biometric anything.

You still have ordinary privacy obligations. Tell people what you are collecting, keep it safe, use it only for what you said. Those apply to any event photography. Biometric rules are the extra layer, and choosing a non-biometric tool is how you step around that layer rather than through it.

Rules for young people are the other half, and they sit with you as the organiser. If permission is needed before you photograph a child, you obtain it your way, before the event.

This is information, not legal advice. We are a photography platform, not your lawyer. Privacy law differs by country and changes over time. If your organisation has a specific obligation, take proper advice on it.

Consent

Nobody is in the system by accident

Check-in is the consent. It is a deliberate act, taken on the guest's own phone, before any photo exists.

01

They choose to scan

One static QR sign near the queue. Reading a sign is not consent; scanning it is a choice.

02

They enter their own details

Name and email, typed by the guest. We never buy, guess or import a guest list.

03

They get a code

Five characters plus a QR. Showing it at the station is the second, in-person confirmation.

04

No code, no match

A guest who never joins the queue is never matched to anything. There is no "find me in the crowd".

Children & young people

You decide who is photographed. We never ask an age.

PopStudio has no minor path, no age question and no parental-consent step. It cannot tell a fourteen-year-old from a forty-year-old, and it does not try. Every guest gives a name and an email, and their photos go to that address.

That means consent sits where it always really sat: with the organisation running the event. You are the one collecting the information and taking the photographs; we process it as your agent, under the Terms of Service. If your safeguarding policy or the law where you operate requires a parent's permission before you photograph a young person, you obtain it your way, before the event.

What the product does guarantee is narrower and checkable. Nobody is photographed unless they chose to join the queue and showed their code. Nothing biometric is collected, so no face is measured and no age is estimated. Photos go to the address that guest typed, and to no gallery. Every delivery email carries a delete button that works, and everything expires on the retention clock whether or not anyone remembers.

If a parent wants photos of their child sent to their own inbox, they can simply use their own email address when they joined the queue. That is a choice they make at the sign, not a mode you configure.

Retention

Photos do not live here forever

Every photo has an expiry from the moment it is taken, and every guest has a delete button they do not need our permission to use.

The clock

Default retention is 30 days. You can set 7, 30, 90 or 365 to suit your organisation's own policy. The free test drive keeps photos for 7 days.

The purge

A job runs daily and deletes everything past its date. After that the guest's photo page says "Photos expired", a plain answer, not a broken grid of missing images.

The button

Every guest photo page carries a delete button. Tapping it removes the stored objects. No email to us, no waiting, no form.

What "deleted" actually means

The stored files are removed. Both the original camera file and the developed version, and the database rows that pointed at them go too. It is not a hidden flag or a trash folder we keep. One honest caveat: a group photo belongs to everyone in it, so it survives until the last participant deletes it. One person's deletion removes it from their page and their copy; it does not delete other people's copies out from under them.

The full list

What we collect, exactly

Not a summary. This is the list.

CollectedWhyNever collected
Name So the operator can call the right guest forward and the email reads like a human wrote it. Faceprints, no face is ever measured.
Email address It is the delivery address. That is its only job. Biometric templates or embeddings of any kind.
A five-character code, issued when they joined the queue It is how photos are joined to the right guest. Nothing else does that job. Age, or anything about it. We never ask, and we never infer.
The photos They are the product. They are what the guest came for. Advertising or analytics trackers on the guest photo page.
Timestamps. Check-in, capture, delivery To run the queue, honour retention, and answer "did mine send?" Location, contacts, or anything else on the guest's phone.

Guest data is never sold, never rented, and never passed to an advertiser. It is used to deliver photos to the person who asked for them, and for nothing else.

Infrastructure

Where it lives

Storage

Photos are stored on Cloudflare R2, encrypted in transit and at rest.

Access

Your team sees your own events, and nobody else's. We do not browse customer photos. Staff access exists only to keep the service running and to fix something when you ask us to.

Sub-processors

Cloudflare for hosting, database and photo storage, and an email delivery provider to send the link. That is the list. There is no analytics vendor and no ad network in it.

PopStudio is operated by System Advance Limited. Full detail, including where the company is registered and which law governs the agreement, is in the Privacy Policy.

If you are a guest

You joined the queue, and you want your photos changed or gone

You do not need us for that. The delete button on your own photo page does it. If the link never arrived, or you want to know what is held about you, the guest help page walks through both.

Guest help →

Ask us

Send us the hard question

Board papers, a school policy review, a privacy officer with a checklist. Send it through. We would rather answer a pointed question before your event than a complaint after it. Real answers from the people who built the system.

Ask a privacy question