Who controls your information
Eimantas Alkevicius, trading as PixMedium, is the data controller for information processed to operate this service. The controller’s address is:
59 Jellicoe Road
Great Yarmouth
NR30 4AN
United Kingdom
Privacy questions, complaints and data-rights requests can be sent to [email protected].
Information we process
- Account email addresses and the short-lived one-time sign-in codes used to log in. If you choose Google sign-in, Google provides PixMedium with your verified email address.
- Your profile details (display name, handle, bio and links) where you choose to complete them.
- Gallery names, short-lived client sign-in codes (stored hashed), legacy server-generated shared access codes, photographs, favourites, likes and — on event galleries — reports and moderation state.
- A random first-party browser identifier used, in hashed form, for gallery-scoped abuse prevention on event uploads.
- Basic technical information produced by the web server, such as request time, IP address and browser information, where hosting logs retain it, and short-lived hashed rate-limit records.
- For paid plans: billing contact details, billing country, transaction and subscription identifiers, payment status and limited payment-method details (such as card brand and last four digits). PixMedium does not receive or store the full card number or security code.
PixMedium does not run optional website analytics or advertising/cross-site tracking. If that ever changes, this policy will be updated and a consent prompt added first.
How information is used
We process account, gallery and security information where necessary to provide the service, protect users and operate PixMedium. We rely on legitimate interests for proportionate security, abuse prevention, service administration and reliability. Billing information is processed to take and manage payment for paid plans.
Photographs and metadata
PixMedium creates processed JPEG versions and thumbnails for display, removing embedded EXIF metadata from those copies. Client galleries can also retain the uploaded original for original-quality downloads; event galleries keep only the processed version. Files are deleted with their gallery according to the retention rules below.
Retention
Event galleries do not expire: their content is retained until you delete the gallery or your account, subject only to the storage included in your plan. Client galleries are retained on the same basis. An expiry date set on a client gallery closes viewer access on that date; it does not delete the photographs, which are retained until you delete the gallery or your account.
The one exception is a dormant free account. If a free account has not been signed in to for twelve months we will email the account address at least twice, and if it remains unused we may then remove the account and its content. Accounts on a paid plan are not removed for inactivity while the plan is active.
Some security, moderation, delivery, backup or hosting records may remain for a limited period afterwards. Gallery-scoped hashed device restrictions may remain after a reported photo is deleted so the restriction cannot be bypassed by deleting that photo.
Service providers and sharing
PixMedium uses service providers for website hosting, database infrastructure, object storage, backups and email delivery, Stripe for subscription and payment processing, and Google as an identity provider only when you choose Google sign-in. Fonts, icons, frontend libraries and QR codes are served directly by PixMedium. We do not sell personal information; it is shared only as needed to provide the service, respond to your sharing choices, protect PixMedium and its users, obtain professional advice, or comply with law.
Where your information is stored
The PixMedium website, its database and its database backups run on servers located in Manchester, United Kingdom, provided by Hostinger.
Uploaded photographs and other media are stored separately in Cloudflare R2 object storage under its European Union jurisdiction, which means those objects are held within EU data centres rather than being placed in any region worldwide. Media is stored in a private bucket and is served only through short-lived signed links, never from a publicly listable location.
Some of our providers are companies established outside the United Kingdom and the European Economic Area — Cloudflare and Stripe are United States companies, and Google is used only if you choose Google sign-in. Where a provider processes personal information outside the UK or EEA, that transfer relies on the safeguards in the provider’s data-processing terms, such as the UK International Data Transfer Addendum or Standard Contractual Clauses. Storing objects within a jurisdiction does not by itself remove a provider from the reach of the laws of the country in which it is established.
If you need written detail about storage locations or a data-processing agreement for your own clients, email [email protected].
Your choices
You can ask about access, correction, deletion, restriction, portability or objection, or raise a privacy concern, by emailing [email protected]. These rights depend on the circumstances and applicable law. You may also complain to the UK Information Commissioner’s Office if you believe your data-protection rights have not been respected.