Privacy Policy

Last updated 16 September 2026

The short version

  • We never sell your data. Not to anyone, ever.
  • The face scan is optional, and we delete your selfie within 30 days.
  • Photos are stored privately, never in a public folder.
  • Ask us to delete anything about you and we will: privacy@supalime.com.

Facial recognition (Find My Photos)

This is the most sensitive thing we handle, so it goes first.

Using it is optional. Every gallery can be browsed in full without it.

Face data is computed from the photographs themselves, whether or not you ever open the gallery. When a photographer adds photographs to a gallery with this feature switched on, every face in them is turned into a list of 128 numbers, because otherwise there is nothing for a search to match against. If you were photographed at an event and never followed the link, that has still happened. We would rather tell you than let you assume otherwise.

You can ask us to delete the face data taken from photographs of you, whether or not you have ever opened the gallery: privacy@supalime.com.

What happens to the selfie you take. Your browser turns the face it finds into a list of 128 numbers, and sends us both that list and the selfie itself. We compare the numbers against the gallery to find your photographs. We keep the selfie and the numbers for up to 30 days, or until the gallery closes if that comes first, and then we delete them. Deleting the gallery deletes them straight away. You can ask us to delete them sooner at any time.

We store those number-lists for the photographs already in the gallery, so the matching works. They are a mathematical summary, not a picture, and a face cannot be reconstructed from them. They are still personal data and we treat them as such.

They are used for one thing only: finding photographs within the gallery they came from. Never to identify you elsewhere, never across galleries, never for advertising.

They are deleted when the gallery is deleted. To have them removed sooner, email us.

If you are a guest viewing a gallery

The photographer who made the gallery decides what goes in it and who can open it. We hold it on their behalf.

Some galleries ask for your name, email or phone before they open. That is collected for the photographer, and they decide what they do with it.

We record page visits, photo views, downloads, shares and face scans, so the photographer can see how their gallery is being used.

If you gave your details to open the gallery, these records are linked to you by name. The photographer can see that a particular guest opened the gallery, which photographs they looked at, what they downloaded, what they shared and whether they ran a face scan. This is not anonymous counting, and we would rather say so plainly than describe it as statistics.

We also record your IP address and which browser you used, against the same events. An IP address is personal data on its own, so it is listed here even though the photographer is never shown it. We use it to tell one visitor from another and to investigate abuse.

If you did not give your details, these records are not linked to a name.

If you have a photographer account

We collect your name, email, phone, company and country to run your account, sign you in, and take payment.

Card details go straight to Stripe and never touch our servers. If you sign in with an email code or with Google, we store no password at all.

How long we keep things

Photographs stay until you delete them, the gallery expires, or the account is closed.

Free accounts: if the photographer does not sign in for six months, we email them three times over three months and then remove the galleries. Signing in at any point stops this. For a further month after a gallery goes dark it can still be restored by signing in.

Paid accounts are never removed for inactivity while the subscription is active.

If a gallery matters to you, download your photographs. Once removed we cannot get them back.

Where your data is held

Our database is in Singapore. Photographs are held in the Asia Pacific region in a private store, served only over links that expire after a few hours. They are never in a public folder.

We use established service providers for hosting, storage and payments. Some operate globally; where data is processed outside Singapore we rely on their standard contractual protections. For the current list of providers, email privacy@supalime.com.

Your rights

Under Singapore's Personal Data Protection Act you can ask us what we hold about you, correct it, withdraw consent, or have it deleted.

Email privacy@supalime.com. We respond within 30 days.

If you are a guest, we may need to pass your request to the photographer who owns the gallery, since it is their data. We will tell you when we do and who they are.

If you are not satisfied, you can complain to the Personal Data Protection Commission at pdpc.gov.sg.

Who is responsible for your data

Supalime is operated from Singapore. Our Data Protection Officer is Alfred Tan.

Questions about this policy, requests about your own data, and complaints all reach the DPO at privacy@supalime.com.

Cookies

Only what is needed to keep you signed in and to remember your session within a gallery. No advertising or third-party tracking cookies.