1. Scope
This Privacy Policy explains how Perpetual Media Ltd. (“Momently,” “we,” “us,” or “our”) handles personal information when organisers purchase, create, and manage events; guests upload photos; wedding professionals apply to or use the affiliate pilot; visitors follow affiliate referral links; or anyone visits or uses our service.
The event organiser decides whom to invite and what guest link or QR code to share. Contact the organiser first for event-specific questions or removal requests; you may also contact us.
2. Information we collect
Information you provide
We collect event and partner names, wedding date, chosen event link, organiser email address, display names, uploaded photos and related file metadata, management-key authentication data, and communications sent to support. We record the version and time at which a purchaser accepts our Terms of Service and Privacy Policy at Checkout.
Creating a paid event requires an organiser email address. We use it to deliver the wedding studio link and management key and to send essential notices about that event. Please use an address you own or are authorised to use. We do not send marketing email unless you separately ask us to.
An affiliate applicant provides their name, business name, email address, public website or social-profile URL, two-letter country code, and acknowledgement of the displayed pilot rules and this policy. The affiliate account may later contain application and account status, an affiliate code, provider-issued payout readiness or account references when configured, and program communications. The application does not ask for bank-account or card credentials.
Payment and commission information
Stripe processes payment details directly through Stripe Checkout. We do not collect or store your full card number or card security code. We receive limited transaction information from Stripe, such as Checkout session identifiers, payment status, amount, currency, tax totals where applicable, and the email address used at Checkout. Stripe’s handling of payment data is governed by the Stripe Privacy Policy.
When an order is attributed to an affiliate, the affiliate ledger records internal order and attribution identifiers, the code and attribution source, payment totals and status, refund or dispute status, commission calculations and adjustments, payout state, and audit events. The affiliate order record uses a one-way hash rather than the purchaser email address. For supported Stripe events, the ledger records event identity, type, processing status, timing, and a payload digest for replay auditing rather than retaining the raw webhook payload. The affiliate portal displays anonymised order references and program amounts or states, not purchaser identity, wedding-management credentials, or event media.
Information collected automatically
When you use the service, we may collect device and browser details, approximate location derived from IP address, request timestamps, pages or features used, error and performance data, and security logs. We use essential cookies, local browser storage, and similar technologies to maintain a guest session, remember a management credential on the device where you save it, keep a random Checkout browser identifier that prevents duplicate Checkout submissions, prevent abuse, and operate core features.
Opening a valid affiliate referral link records the affiliate and code identifiers, click and attribution-expiry times, landing path, referring hostname if the browser supplies it, a suspected-automated-traffic indicator, and a one-way hash of an opaque browser token. The referral-click record does not store the source IP address or purchaser identity. A signed, HTTP-only, same-site first-party cookie can retain the referral candidate for up to 30 days so it can be checked at Checkout.
Affiliate email sign-in creates records for one-time sign-in links and portal sessions, including one-way token hashes and creation, expiry, use, last-seen, or revocation times. The raw credential is not stored in those records.
With your permission, Google Analytics collects information about site visits and interactions, including pages viewed, approximate location, browser and device information, and referral data. Analytics storage is denied by default until you choose “Allow analytics.” Your choice is saved in local browser storage and can be reset by clearing site data. Google explains its handling of this data in the Google Privacy Policy.
To protect the former unauthenticated event-creation route from email abuse, legacy records may contain a one-way salted hash of the creating IP address. We do not store the source IP address itself. Current paid Checkout uses Stripe confirmation rather than an unauthenticated email-triggering route.
3. How we use information
We use information to process payment; create and operate events; review affiliate applications; authenticate affiliate portal sessions; record and resolve referral attribution; calculate, adjust, report, and audit commission; calculate and enforce photo and hosting limits; process, store, display, and delete uploads; authenticate organisers; provide support; maintain reliability and security; detect fraud or misuse; comply with legal obligations; and communicate essential service, payment, affiliate-account, commission, expiry, or policy updates.
Guest photos and display names may be shown on the event’s live slideshow and to people with a shared event link. We do not sell personal information or use private wedding photos for targeted advertising.
4. Legal bases
Where data-protection law requires a legal basis, we rely on performance of our contract with a purchaser to provide Checkout and the event service; legitimate interests in securing the service, preventing fraud, and supporting customers; compliance with legal obligations; and consent where appropriate. Service emails are not direct marketing. You may withdraw consent where consent is the basis, without affecting earlier lawful processing.
6. Retention
For a paid Momently wedding, event photos, guest sessions, and incomplete uploads are available through the expiry date shown during Checkout and in the studio, normally 12 months after the wedding date. After that date, the service blocks event access and a scheduled cleanup removes photos, guest-session records, and incomplete uploads from our active systems. Storage-provider backups may persist for a limited additional period before their normal deletion cycle completes.
Affiliate sign-in links and sessions have recorded expiry and revocation states. Scheduled affiliate maintenance is designed to replace browser-token correlation and clear landing-path and referring-host fields for referral touches seven days after their attribution window expires; financial attribution facts remain. Affiliate application, attribution, commission, payout, and audit records are retained to operate and secure the pilot and to document financial activity. The exact deletion and statutory-retention schedules for affiliate and accounting records must be confirmed for supported jurisdictions before public applications or payouts open.
We may retain minimal event, payment, acceptance, and support records after photo deletion when reasonably necessary for accounting, tax, dispute, fraud-prevention, legal, or support purposes. The exact statutory retention schedule and backup period must be confirmed for the jurisdictions in which we operate before launch. Stripe retains transaction records under its own policies.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; obtain a portable copy; withdraw consent; or appeal a decision. You may also have the right to complain to a data-protection authority.
Contributors can remove their own photos where that functionality is available. Affiliate applicants and affiliates may contact us about their application, portal, or program records. For other requests, email us with enough detail to identify the relevant account, event, or content. We may need to verify your identity and may retain information where required by law.
8. Security
We use reasonable technical and organisational safeguards designed to protect information, including access controls, secure transport, signed media links, one-way credential hashes, tenant-scoped affiliate queries, and Stripe’s hosted payment form. No online service can guarantee absolute security. Keep management keys private and use care when sharing event links.
The guest-session, affiliate-referral, and affiliate-portal cookies are HTTP-only and same-site. The temporary browser cookie that lets the purchaser recover their management key after returning from Stripe is limited to the Checkout flow. A management key you choose to save in your browser’s local storage remains there until you remove it or clear browser data.
9. International transfers
Our providers may process information in countries other than your own. Where required, we use recognised safeguards for international transfers, such as contractual protections or adequacy decisions. Specific provider locations and transfer mechanisms should be confirmed before launch.
10. Children
The service is not directed to children who are below the age at which they may consent to online data processing in their location. Event organisers should supervise children’s participation and obtain any permissions required before uploading images of minors.
11. Changes to this policy
We may update this policy as the service or law changes. We will revise the effective date and provide additional notice when required. Material changes will apply prospectively unless the law permits otherwise.
12. Contact
For privacy questions or requests, email support@momently.live or write to Perpetual Media Ltd., [business address to be confirmed before launch]. If required, add your privacy representative or data protection officer here: [privacy contact details to be confirmed before launch].
