Legal
Privacy Policy
Last updated: 17 September 2026
Blinzel is a photo and video gallery for celebrations. In short: all photos are stored exclusively in the EU, there are no ads, no analytics cookies and no sharing with third parties for their own purposes. In detail:
1. Controller
Hakan Bayindir Breslauerstraße 19b 54516 Wittlich Deutschland Email: hallo@blinzel.de
2. Hosting (Vercel)
The website and application are hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. The application runs in the Frankfurt region (fra1). When you visit, technically necessary access data (IP address, time, requested page, browser type) is processed in server logs and deleted after a short period.
The legal basis is our legitimate interest in secure and stable operation (Art. 6 (1) (f) GDPR). A data processing agreement is in place with Vercel; for potential access from the USA, the EU standard contractual clauses and Vercel's certification under the EU-US Data Privacy Framework apply.
3. Database (Neon)
Account and event data (the host's email address, event title and date, settings, media metadata such as file name, size, guest name, guestbook message, orders) is stored in a Postgres database operated by Neon Inc., 209 Orange Street, Wilmington, DE 19801, USA, in the Frankfurt region (AWS eu-central-1). A data processing agreement is in place; the data does not leave the EU.
4. Photos and videos (Cloudflare R2)
Uploaded photos and videos and the previews generated from them are stored with Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, in R2 object storage with EU jurisdiction — files are stored exclusively on servers within the European Union. Uploads go directly from the guest's device via time-limited signed addresses; gallery views also use such short-lived links. A data processing agreement is in place.
5. Emails (Resend)
Sign-in links, order confirmations, notices about the guest limit and the reveal in disposable-camera mode, and reminders before the retention period ends are sent via Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). Email address, subject and message content are processed. The legal basis is performance of the contract (Art. 6 (1) (b) GDPR); a data processing agreement with EU standard contractual clauses is in place.
6. Payment (Stripe)
Paid plans are billed via Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. You enter payment data (card details, payment method) directly with Stripe; we only receive the payment status, amount, email address and a link to the invoice. Stripe issues the invoice on our behalf. The legal basis is performance of the contract (Art. 6 (1) (b) GDPR); invoice data is retained for ten years under tax law (Art. 6 (1) (c) GDPR). Stripe's privacy notice is available at stripe.com/privacy.
7. Analytics (PostHog, cookieless)
To understand which pages are used, we use PostHog's EU cloud (PostHog Inc., servers in Frankfurt) — deliberately without cookies and without persistent identifiers: nothing is stored in your browser and a visitor is not recognised across page views. We record the page viewed, the referring page, browser and device type, and the IP address to determine an approximate location; PostHog does not store the IP address permanently.
The legal basis is our legitimate interest in improving the service (Art. 6 (1) (f) GDPR). Since no information is stored on or read from your device, no consent under § 25 TDDDG is required.
8. Host account and sign-in
Hosts sign in with their email address; we send a single-use sign-in link (valid for 15 minutes). After clicking, we set a technically necessary session cookie (“blinzel_session”, 30 days) containing only a random session identifier. There are no passwords. The legal basis is performance of the contract (Art. 6 (1) (b) GDPR); the cookie is required for the service you expressly requested (§ 25 (2) no. 2 TDDDG).
9. Guests: uploading without an account
Guests do not need an account. The event link (an unguessable address from the QR code) is the access to the gallery. On the first visit, the browser generates a random device identifier and stores it, together with the optionally entered name and the upload queue, in the browser's local storage (localStorage/IndexedDB). The identifier is sent with each upload so that we can count guests per event, resume interrupted uploads and, in disposable-camera mode, count shots per device. It does not identify a person and is not shared with other services.
This storage is required for the service you expressly requested (§ 25 (2) no. 2 TDDDG). Uploaded photos, videos, guest name and guestbook message are visible to everyone who has the event link. The host is responsible for their event's gallery; we process its content on the host's behalf. Guests should only upload pictures whose subjects agree to them appearing in the gallery.
10. Camera access in disposable-camera mode
If the host has enabled disposable-camera mode, the browser asks for permission to use the camera. The camera image is shown locally in the browser only; a single photo is created and uploaded to the gallery only when you press the shutter. Without pressing the shutter, no image leaves your device. You can revoke the permission at any time in your browser settings.
11. Public demo event
The homepage links to a public demo event that anyone can try without signing up. Everything uploaded there is visible to all demo visitors and is deleted automatically no later than 24 hours after upload. Please do not upload private pictures there.
12. Retention
Photos, videos and previews of an event are stored for 12 months from the event date and then deleted automatically; the host is reminded by email beforehand and can download everything as a ZIP. Account data is stored as long as the account exists. Order and invoice data is subject to statutory retention periods (ten years). Server logs are deleted after a short period.
13. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). To exercise these rights, write to hallo@blinzel.de. You may also lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate.
Guests who want pictures removed from a gallery can most easily contact the event's host, who can hide or delete any picture. Of course we help directly as well.
14. Changes
We update this policy when our services or the legal situation change. The version published here applies.