Skip to content
TakPhoto

Privacy Policy

Exactly what TakPhoto collects, why, where it is processed, how long it is kept, who else touches it, and how to have it deleted in one click.

Written by TakPhoto

Draft — this text is waiting for legal review before launch.

This page has not been translated into this language yet, so it is shown in English. The English version is the reference.

This policy describes what happens to your data when you use TakPhoto. It is written to be read, not to be survived, and it describes what the system actually does — if you find a sentence here that the product contradicts, tell us and we will fix one of the two.

The controller of your data is <OWNER_NAME>, an individual trader established in Türkiye, reachable at <SUPPORT_EMAIL>.

What we collect

  • Your photo, and the files we make from it: the straightened original, the cut-out mask and the finished digital file and print sheets.
  • Your email address, when you ask us to send the result, when you sign in, or when you open a support ticket.
  • The country your request comes from, derived from your IP address by our CDN. We use the country only to suggest the right documents and the right currency; we do not store your IP address with your order.
  • Technical data about the request — a timestamp, the status of the order, the error code if something failed. Our error reporting is configured to send no personal data at all.
  • What you send us on purpose: the text of a support ticket, an optional screenshot, and the browser information box you can tick or untick before sending it.

That is the whole list. We never ask for your name, your phone number, your address or your date of birth, and we do not keep payment card details — they never reach our servers.

What we remove before anything is stored

The moment your photo arrives we strip its metadata: GPS coordinates, camera and phone model, timestamps, colour profiles, everything EXIF, ICC and XMP carry. What we store is the image, not where and on what you took it. The files we give back carry no metadata either.

Why we process it

  • To do what you asked: produce a photo that fits the document you chose. This is the performance of our contract with you.
  • To take payment and issue an invoice — a legal obligation, handled by Paddle as the seller of record.
  • To keep the service standing: rate limits, the bot check, and error reports, which is our legitimate interest in not being knocked over.
  • To answer your message, when you write to us.

We do not profile you, we do not advertise to you, and nothing here is based on your consent alone except the cookieless product analytics described below, which you can stop by blocking the script.

Where it is processed

On our own servers in the European Union: a DigitalOcean data centre in Frankfurt, Germany (fra1), with the files in DigitalOcean Spaces object storage in the same region, in a private bucket reachable only through short-lived signed links. Nothing is processed outside the EU, and your photo is never sent to an external AI service — the models run on our machines.

How long we keep it

What How long
A paid order, its photo and its files 30 days from the order, then deleted automatically
An order that was never paid 24 hours, then deleted automatically
Any order you delete yourself Deleted immediately, from the database and the storage at once
Support tickets 12 months, so we can see a repeat problem
Invoices and payment records (held by Paddle) As long as tax law requires, typically 10 years

Thirty days is a deliberate choice, not a convenience: it is long enough to re-crop a photo for a second document or re-download it after a lost phone, and short enough that a leak years from now cannot contain your face. Studios can set their own retention between 30 and 730 days for their customers' orders; API keys default to keeping nothing at all.

We do not share it and we do not train on it

Your photo is never sold, never published, never shown to another customer, and never handed to a third party for their own purposes. We do not use your photo — or the result — to train, fine-tune or evaluate any model, ours or anybody else's. There is no "improve the service" exception hidden in a subclause.

Who else touches your data

These are our processors: each one does a single job for us under a contract, and none of them may use your data for their own purposes.

Processor What it does What it sees
DigitalOcean Hosting and object storage, Frankfurt The photo and the order record
Paddle Seller of record for web payments Your email, the amount, your billing country and your payment details — never your photo
Apple / Google Seller of record for in-app purchases The purchase, under their own privacy policies
Mailtrap (Railsware) Sends the emails you ask for Your email address and the message
Cloudflare CDN, protection and the anti-bot check The request, the IP address, the country
Sentry Error reports Technical error data with personal data switched off (send_default_pii=False) — no photos, no email addresses
PostHog Product analytics in cookieless mode Page views and events, no cookies, no identifiers we can link back to you

Your rights

Wherever you live, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to our processing it. Under the GDPR (EU/EEA and the UK), the KVKK (Türkiye) and the CCPA (California) those rights are explicit, and the CCPA's "do not sell my personal information" right is satisfied by our simply never selling it.

You do not have to write to anyone to use the two that matter most:

  • Delete everything now — the delete button on the order page, or "delete my account and all my data" in your account. It is immediate and irreversible.
  • Get a copy — "export my data" in your account returns your order records as JSON straight away; the images themselves are downloadable from each order page.

If you would rather write, <SUPPORT_EMAIL> reaches us, and we answer a rights request within 30 days — usually the same day, because the system does most of it by itself. If you are not satisfied, you may complain to your local data protection authority, or to the Turkish authority (KVKK) where our establishment is.

Children

The service is for adults. A parent or guardian may of course make a passport photo for their child — that is one of the things it is for — and the child's photo is treated exactly like any other: same retention, same deletion, same refusal to share or train on it. We do not knowingly let a child open an account, and we collect nothing about a child beyond the photo an adult uploads.

Cookies and local storage

We set no tracking cookies, no advertising cookies, and no language cookie. The only cookie is the session cookie that exists while you are signed in to an account, a studio dashboard or the admin panel. Everything else the site remembers lives in your own browser's storage and never reaches us. The cookies page lists every single key by name and says what it is for.

Security

Photos live in a private bucket and are served only through links that expire in fifteen minutes. Order links are 32 random bytes and are stored hashed, so a copy of our database does not open anybody's order. Payments are confirmed only by a signed webhook from the payment provider, never by the browser. Administrative accounts require a second factor. The full control list is in our security documentation, and we run the pre-launch checks described there before every release.

Changes

If we change this policy the date at the top changes with it, and a material change is announced on the site — and by email, if you have an account — before it takes effect.

Contact

Any question about your data, and any rights request: <SUPPORT_EMAIL>.