shared.click

Privacy Policy

How we collect, use, and protect your personal information

Last updated: 18 September 2026

1. Introduction

This Privacy Policy explains how North Arrow Pty Ltd ("we," "us," or "our") collects, uses, and protects your personal information when you use the shared.click photo-sharing service ("Service").

Change of operator. shared.click was previously operated by Maiwald Solutions (Berlin, Germany). The Service and the personal information associated with it were transferred to North Arrow Pty Ltd in September 2026. North Arrow Pty Ltd is now the entity responsible for that information. Where your data was hosted has not changed: it remains stored in the European Union.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, for users in the EU and UK, the General Data Protection Regulation (GDPR) and UK GDPR.

2. Who is responsible

Responsible entity / controller: North Arrow Pty Ltd (ACN 700 669 530, ABN 71 700 669 530)

Address: 100 Taylors Road, Mount Macedon, Victoria 3441, Australia

Contact: [email protected]

3. Information We Collect

3.1 Photos and Media

  • Photos and videos you upload to our Service
  • EXIF data contained in uploaded images (including location data, if present)
  • File metadata (size, format, upload timestamp)

3.2 User Information

  • Authentication information (when using OAuth providers like Google)
  • User profile information (name, email, profile picture)
  • Event participation data (events created or accessed)

3.3 Technical Information

  • IP address and browser information
  • Device information (type, operating system)
  • Usage analytics and performance data
  • Session information and cookies

3.4 Content Reports

When a user submits a content report via the Report button in the event gallery, we store a salted hash of the reporter's IP address solely to prevent duplicate and automated reports. We do not store the raw IP address, and the hash cannot be linked back to a person without the original IP. If the reporter is signed in, we also record their user ID so our moderation team can distinguish reports from known users. The optional reason text submitted with a report is stored to help our moderation team assess the report. Legal basis (where GDPR applies): legitimate interest in preventing abuse of the reporting mechanism (Article 6(1)(f)).

Important Privacy Notice
Photos uploaded to events are accessible to anyone with the event link. This means photos are effectively public to anyone who has been shared the link.

4. Legal Basis for Processing (where GDPR applies)

  • Consent (Article 6(1)(a)): when you upload photos and create accounts
  • Contract Performance (Article 6(1)(b)): to provide the photo-sharing service
  • Legitimate Interest (Article 6(1)(f)): for service improvement, security, and enforcement of fair use policies

5. How We Use Your Information

  • Store and display your photos in event galleries
  • Enable photo sharing and downloading within events
  • Authenticate users and manage event access
  • Send notifications about event activity (if enabled)
  • Send occasional product updates and service-related communications (you can unsubscribe at any time)
  • Improve our Service through analytics
  • Ensure security and prevent abuse
  • Monitor bandwidth and usage patterns to enforce fair use policies
  • Detect, prevent, and address abuse, fraud, or technical issues
  • Comply with legal obligations

6. Data Sharing and Third Parties

6.1 Service Providers

We use the following third-party services that may process your data:

  • Supabase: database and file storage (data stored in the EU region, on AWS infrastructure)
  • Hetzner (Germany): application servers
  • Cloudflare: security and content delivery
  • OAuth Providers: for authentication (Google, etc.)
  • PostHog (EU): product analytics to understand how the Service is used (data stored in the EU region)
  • Stripe: payment processing — we do not store full payment card details

We require these providers to protect the information and to use it only to provide their service to us. We do not sell personal information.

6.2 Public Access

Important
Photos in event galleries are accessible to anyone with the event link. By uploading photos, you consent to this level of access.

6.3 Legal Requirements

We may disclose your information if required by law, legal process, or to protect the rights, property, or safety of our Service, users, or others.

7. Data Retention

Our retention periods vary based on your subscription plan and the type of data:

7.1 Photos and Media

Free Plan:

  • Event content is accessible for 30 days from event creation
  • After the 30-day period, access is restricted and content may be deleted at our discretion
  • We may delete content immediately in case of Terms violations

Paid Plans:

  • Retention periods vary by subscription tier; see our pricing page for details
  • Content remains accessible for the duration of your active subscription
  • Upon subscription cancellation or expiration, retention reverts to free plan terms

All Plans:

  • Content is deleted upon user request or account deletion
  • We recommend downloading important photos as backup

7.2 Other Data

  • User accounts: retained until account deletion is requested
  • Usage and bandwidth data: retained for the duration of your account plus 12 months for billing and abuse prevention purposes
  • Analytics data: anonymised and retained for up to 2 years
  • Log data: retained for up to 1 year for security purposes

8. Your Rights

You can ask us to:

  • Tell you what personal information we hold about you and give you a copy (access)
  • Correct information that is wrong, incomplete or out of date (rectification)
  • Delete your personal information (erasure)
  • Restrict or object to processing, including for direct marketing
  • Export your data in a portable format
  • Withdraw consent at any time

To exercise these rights, contact [email protected]. We will respond within one month. There is no cost, and we may need to verify your identity first.

If we refuse a request, we will tell you why in writing and explain how to complain.

9. Data Security

We protect your data with encryption in transit and at rest, per-role database credentials with row-level security, multi-factor authentication enforced on all administrative systems, a database segregated from our other products, and automated daily backups with 7-day retention stored separately from production; uploaded media is stored on replicated cloud storage. Access is limited to the founders under least-privilege practices, and stored credentials are encrypted with keys held outside the database. Payments are processed by Stripe; we hold no payment card data.

No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

10. International Data Transfers

Your photos and account data are stored within the European Union. We are an Australian company, so limited personal information (such as account and billing records) may be accessed from Australia, and some service providers may process data in other countries. Where European data is transferred outside the EU, we use appropriate safeguards such as Standard Contractual Clauses or adequacy decisions. We take reasonable steps to ensure all recipients handle personal information consistently with the Australian Privacy Principles.

11. Cookies and Tracking

We use the following types of cookies:

  • Essential cookies: required for the Service to function
  • Authentication cookies: to keep you logged in
  • Analytics (PostHog): to understand how the Service is used, including page views, feature usage, and user journeys; data is processed in the EU

You can manage cookie preferences in your browser settings, though this may affect Service functionality.

12. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided personal information, please contact us.

13. Data Breaches

If a data breach occurs that is likely to result in serious harm, we will assess it promptly and, where the Australian Notifiable Data Breaches scheme requires, notify affected individuals and the Office of the Australian Information Commissioner. Where European data is affected, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users without undue delay.

14. Complaints

If you are unhappy with how we have handled your personal information, contact us at [email protected] so we can try to resolve it.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, if you are in the EU or UK, to the data protection supervisory authority in your country of residence.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date and, for significant changes, through additional notice methods.

16. Contact Us

For any privacy-related questions or to exercise your rights, please contact us:

North Arrow Pty Ltd

100 Taylors Road, Mount Macedon, Victoria 3441, Australia

[email protected]