Legal
Privacy Policy
गोपनीयता नीति
Tasveer shows a wedding guest the photographs they appear in. Doing that means handling a person's face, which is the most personal thing this product touches — so this page says exactly what is taken, what is kept, where it sits, for how long, and how to end it. The commercial terms are separate, in the terms & conditions.
In effect from 1 September 2026 · Digital Personal Data Protection Act, 2023
01Who this policy is from
Tasveer is operated by Ubilo, a sole proprietorship established in India. This policy covers the Tasveer website, the photographer's dashboard, the couple's pages and the guest galleries at /w/… links.
Two relationships, not one. For a wedding's photographs and the guests in them, the photography studio is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 — it holds the relationship with the couple and their guests, and it decides that the wedding is delivered this way. We act as its Data Processor, on its instructions. For the studio's own account — the email address it signs in with, its studio name, what it has bought — we are the Data Fiduciary ourselves.
The practical meaning for a guest: you can raise anything here with us directly and we will act on it, and you may also raise it with the studio whose wedding it is. Neither of us will send you to the other.
02What we hold, and about whom
We collect as little as the product can work with, and none of it is bought from anyone else.
If you are a guest at a wedding
There is no account, no password and no OTP. You scan a code, agree to the notice, and take one selfie. This is the whole of what exists about you afterwards:
- A face signature
- A set of numbers derived from your selfie, held by our face-recognition provider so that photographs uploaded later can still find you. Not a photograph, and it cannot be turned back into one. See clause 3.
- A session cookie
- A random token in your browser that stands for you at this one wedding. Only its one-way hash is stored on our side, so what we hold cannot be used to open your gallery.
- Your name, if you give one
- Optional. Used to address you in the gallery and in an email. Nothing depends on it being real.
- Your email address, if you give one
- Optional, and used for one thing: sending you the link back to your own gallery. It is erased the moment you delete your data.
- The photographs matched to you
- The list of which photographs your face was found in, and how confident the match was — which is what the gallery is.
- Your consent record
- Which questions you were asked, in which language, which version of the notice was on screen, what you answered and when. This is the evidence that the processing was lawful.
- Your own activity
- How many selfies you have sent, when you last opened the gallery, what you downloaded, which browsers hold a live link, and any photograph you asked to have taken down.
- Your language and data-saver choice
- Two settings kept in cookies on your own device so the gallery opens the way you left it.
Not collected: your phone's contacts, its location, its other applications, any identifier that follows you off this site, or anything at all about you at another photographer's wedding.
If you are a photographer or studio
Your email address and password — held by our authentication provider, hashed, never visible to us in the clear — your studio name and optional logo, your GSTIN if you give one, the weddings you create (couple name, venue, date, functions), the photographs you upload, and the record of what you have bought and been granted.
If you are a couple or a host
The email address a studio invited you at, and the account you create when you accept. A host sees their own wedding; they do not see what it cost.
Collected automatically
Our hosting and database providers keep ordinary server logs — the request, the time, the response — for a short period, for security and for finding faults. To stop a link being hammered, a counter is kept against a truncated one-way hash of the requesting IP address; the address itself is not written down, and the hash cannot be turned back into it.
There is no analytics, advertising or tracking software on any page of this site. No third-party pixel, no advertising network, no session recorder, no cross-site identifier. What we know about how the product is used is a daily count of how many times each gallery was opened, which has nobody's identity in it.
03Your selfie and your face signature
Your selfie is never stored. It is sent once over an encrypted connection, compared against the faces already found in this wedding's photographs, and discarded. It is not written to our database, not written to our photograph storage, and not kept in any log.
What persists instead is a face signature: a set of numbers derived from your face and held in this wedding's collection at our face-recognition provider, AWS, in Mumbai. It exists so that a photograph uploaded three days after your selfie can still be matched to you. It is not a photograph and cannot be turned back into one.
- It belongs to one wedding. Each wedding has its own collection, and your browser holds a separate credential for each gallery you open. A guest at two weddings is two unrelated strangers, and nothing on our side can connect them.
- It is never sold, shared or licensed. Not to advertisers, not to data brokers, not to another studio, not to anyone.
- It is never used to train a model — ours or anyone else's. Neither are the photographs.
- It is never used to identify you anywhere else. We do not run searches across weddings, we do not build a profile of a person across events, and we have no product that would.
- It never reaches our error reports or analytics. Face data is excluded from the diagnostics the application sends, by design and not by redaction.
- You can delete it in one tap from the gallery itself, at any time, without asking anyone — see clause 10 — and it is deleted automatically at the end of the retention period shown on the consent screen.
The consent screen you saw before the camera opened is the notice for this processing. Face search is the only thing you must agree to in order to use a gallery; being sent your link on WhatsApp and hearing from the studio again are separate questions, asked separately, and answering no to either changes nothing about your photographs.
04Why we may process it
Your consent is the basis for processing a guest's face. It is asked for before anything is taken, in your own language, in specific terms, unbundled from the optional questions, and it can be withdrawn at any moment from the gallery — which deletes what it permitted rather than merely stopping future use.
The contract is the basis for a studio's account and the weddings under it: we cannot deliver a service somebody bought without holding what they created.
A legal obligation is the basis for keeping payment and tax records for as long as Indian law requires, and for records of consent — which are only useful as evidence if they outlive the processing they authorised.
06What we never do
To say it once, plainly, in one place. We do not:
- sell or rent personal data, in any form, to anyone;
- show advertising, or allow anyone else to advertise here;
- use faces or photographs to train machine-learning models, ours or anyone else's;
- match a face across two weddings, or build a record of a person across events;
- let one studio see another's weddings, guests, photographs or counts;
- keep your selfie, or send face data to any analytics, logging or error-reporting service;
- alter your photographs — an original comes out byte for byte as it went in.
08Our processors, and where data sits
These are every company that processes data on our behalf, what each one is for, and where it holds it. The face signatures and the database are in India.
- Amazon Web Services — Face recognition (Mumbai, India)
- Supabase — Database and accounts (Mumbai, India)
- Cloudflare R2 — Photograph storage (Asia-Pacific)
- Vercel — Application hosting (Global edge network)
- Razorpay — Payments (India)
- Resend — Transactional email (Global)
Payment details — card numbers, UPI handles, net-banking credentials — are entered on Razorpay's own hosted form under its own privacy policy. We never see or store them. What reaches us is whether a payment succeeded and its reference.
Where a processor holds data outside India, it is under contractual terms requiring protection equivalent to this policy, and the transfer is permitted under the Digital Personal Data Protection Act, 2023.
09How long it is kept
Nothing is kept because it might be useful one day. Each thing has a reason to exist and goes when the reason does.
- Face signature
- Until you delete it, or the end of the wedding's retention period — whichever comes first. The default is 90 days from the event; a studio may set anything from 1 to 365 days, and the number for your wedding is shown on the consent screen before you agree to anything.
- Matches and gallery links
- Deleted with the face signature, immediately, in the same operation.
- Your email address
- Erased when you delete your data, when the wedding is purged, or at the end of the retention period.
- The photographs themselves
- They belong to the studio, not to us, and stay for as long as the studio keeps the wedding. Deleting your face data does not remove you from the album — clause 10 says what to do about that.
- Consent and audit records
- Kept after a deletion, on purpose: they are the proof that you consented, and later that you withdrew. They hold no face data, no email address and no list of photographs.
- A studio account
- For as long as the account is open. Closing it deletes the weddings, photographs and face data under it.
Deletion is real, not a flag: face signatures are removed from the provider's collection first and our own record of them second, so a failure in the middle leaves nothing stranded that we could no longer name. Copies may survive briefly in our providers' encrypted backups before those are rotated out.
10Your rights, and the one tap
Under the Digital Personal Data Protection Act, 2023 you may ask what we hold about you, have it corrected or completed, have it erased, withdraw a consent you gave, nominate someone to exercise these rights if you cannot, and complain about how any of it was handled.
A guest does not have to ask us for any of this. Open your gallery and tap Your face data. That screen lists everything held about you at that wedding — the counts, the dates, the date it deletes itself — and the button under it removes your face signature, the list of photographs matched to you, your email address and every gallery link we have sent you. It takes effect immediately, and it cannot be undone.
The photographs stay. They belong to the photographer and remain in the wedding album, because withdrawing consent to a face search is not the same as asking a studio to destroy its work. If you want a photograph of you removed from a wedding, use Report this photograph in the gallery, or ask the studio — that decision is theirs, and clause 1 explains why.
For anything else — a studio account, an email address, a request you cannot make from a gallery — write to support@tasveer.online. We answer within 30 days and usually within one working day. We may need to check that a request comes from the person it is about, and we will never ask you for a password to do it.
11Children
Tasveer is not directed at children, and a Tasveer account may only be created by an adult. A guest gallery is intended to be used by adults; a child should not take a selfie to open one without a parent or guardian's agreement, and we do not knowingly process a child's face data without it.
Children appear in wedding photographs, of course. Those photographs belong to the studio and to its relationship with the family. What we do not do — for a child or for anyone — is track behaviour, monitor activity, or target advertising, all of which the Act forbids for children and none of which exists in this product for anybody.
If you believe a child's face data has been processed here without that agreement, write to support@tasveer.online and we will delete it. We do not require proof before deleting.
12How it is protected
Everything travels over an encrypted connection, and our database, photograph storage and face collections are encrypted at rest by the providers named in clause 8. Beyond that, the protections that matter most here are structural:
- a guest's credential is stored only as a one-way hash, so what we hold cannot be replayed against the site;
- every photograph is served by a link that is minted for one viewer and expires within minutes, and an original is only ever signed for a guest it was actually matched to;
- a wedding's data is reachable only by the studio that owns it, enforced by the database itself rather than by each page remembering to check;
- face data is excluded from diagnostics, logs and error reports.
No system is beyond failure. If a breach affects your personal data we will report it to the Data Protection Board of India and tell the people affected, as the Act requires, with what happened and what to do about it.
13Changes to this policy
We may change this policy when the product changes or the law does. The date at the top of the page is when the current version took effect.
If a change materially affects how a guest's face data is handled, the consent notice itself is re-versioned and consent is asked for again — a guest is never moved onto new terms by a page they did not read. Material changes for studios are sent by email to the account address before they take effect.
14Grievances and contact
Write to support@tasveer.online about anything on this page — a request about your data, a question, or a complaint. It reaches a person, not a queue.
We acknowledge a grievance within 48 hours and aim to resolve it within 30 days. If you are not satisfied with how we have handled it, you may complain to the Data Protection Board of India.
If you are a guest, you may also raise anything with the studio that photographed the wedding — its name is at the bottom of your gallery.