How we collect, use, and protect your personal information
Last updated: 18 September 2026
This Privacy Policy explains how North Arrow Pty Ltd ("we," "us," or "our") collects, uses, and protects your personal information when you use the shared.click photo-sharing service ("Service").
Change of operator. shared.click was previously operated by Maiwald Solutions (Berlin, Germany). The Service and the personal information associated with it were transferred to North Arrow Pty Ltd in September 2026. North Arrow Pty Ltd is now the entity responsible for that information. Where your data was hosted has not changed: it remains stored in the European Union.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, for users in the EU and UK, the General Data Protection Regulation (GDPR) and UK GDPR.
Responsible entity / controller: North Arrow Pty Ltd (ACN 700 669 530, ABN 71 700 669 530)
Address: 100 Taylors Road, Mount Macedon, Victoria 3441, Australia
Contact: [email protected]
When a user submits a content report via the Report button in the event gallery, we store a salted hash of the reporter's IP address solely to prevent duplicate and automated reports. We do not store the raw IP address, and the hash cannot be linked back to a person without the original IP. If the reporter is signed in, we also record their user ID so our moderation team can distinguish reports from known users. The optional reason text submitted with a report is stored to help our moderation team assess the report. Legal basis (where GDPR applies): legitimate interest in preventing abuse of the reporting mechanism (Article 6(1)(f)).
We use the following third-party services that may process your data:
We require these providers to protect the information and to use it only to provide their service to us. We do not sell personal information.
We may disclose your information if required by law, legal process, or to protect the rights, property, or safety of our Service, users, or others.
Our retention periods vary based on your subscription plan and the type of data:
Free Plan:
Paid Plans:
All Plans:
You can ask us to:
To exercise these rights, contact [email protected]. We will respond within one month. There is no cost, and we may need to verify your identity first.
If we refuse a request, we will tell you why in writing and explain how to complain.
We protect your data with encryption in transit and at rest, per-role database credentials with row-level security, multi-factor authentication enforced on all administrative systems, a database segregated from our other products, and automated daily backups with 7-day retention stored separately from production; uploaded media is stored on replicated cloud storage. Access is limited to the founders under least-privilege practices, and stored credentials are encrypted with keys held outside the database. Payments are processed by Stripe; we hold no payment card data.
No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Your photos and account data are stored within the European Union. We are an Australian company, so limited personal information (such as account and billing records) may be accessed from Australia, and some service providers may process data in other countries. Where European data is transferred outside the EU, we use appropriate safeguards such as Standard Contractual Clauses or adequacy decisions. We take reasonable steps to ensure all recipients handle personal information consistently with the Australian Privacy Principles.
We use the following types of cookies:
You can manage cookie preferences in your browser settings, though this may affect Service functionality.
Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided personal information, please contact us.
If a data breach occurs that is likely to result in serious harm, we will assess it promptly and, where the Australian Notifiable Data Breaches scheme requires, notify affected individuals and the Office of the Australian Information Commissioner. Where European data is affected, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users without undue delay.
If you are unhappy with how we have handled your personal information, contact us at [email protected] so we can try to resolve it.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, if you are in the EU or UK, to the data protection supervisory authority in your country of residence.
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date and, for significant changes, through additional notice methods.
For any privacy-related questions or to exercise your rights, please contact us: