← pom.gallery

Privacy Policy

Last updated September 2026

Who this covers

pom.gallery is a small, self-serve product: there's no sales team, no support inbox, and no marketing list, just a tool for building wedding photo galleries. This policy explains, plainly, what we collect, why, and what you can do about it, whether you're the person who built a gallery or a guest viewing one.

What we collect

When you create a gallery, we store the names, event date, and credit line you enter, the photos you upload, and the email address you provide at checkout. If you set a password, we store a salted hash of it, never the password itself. Guests viewing a gallery aren't asked for any personal information at all, beyond a password if the gallery's owner set one.

How we use it

Strictly to run the service: rendering your gallery, processing payment, sending the transactional emails described below, and diagnosing bugs when something breaks. We don't use your data for advertising, don't build profiles from it, don't train models on it, and don't sell or rent it to anyone. We have no marketing list and send no marketing email.

Payments

Checkout is handled entirely by Stripe. We never see or store your card details. Stripe passes us only your email and a confirmation that payment succeeded or a refund was issued; anything else you enter during checkout (billing address, card number) goes to Stripe directly and is covered by Stripe's own privacy policy, not this one.

Where your data lives

Photos are stored on Vercel Blob storage; everything else (names, dates, gallery settings) is stored in a Postgres database. Both are hosted on Vercel's infrastructure in the United States, so if you're viewing or creating a gallery from elsewhere, your data is transferred to and processed in the US.

Other services we use

Besides Stripe, we use Resend to deliver account emails (sign-in links, payment confirmations, and similar), which means your email address and the contents of those messages pass through their systems. We use Sentry for error monitoring, which only receives data related to your gallery (such as your email address or gallery link) when something actually goes wrong, so we can find and fix it. None of these are used for advertising, and none receive your payment details.

Private galleries

If your gallery is password-protected, photo links are only ever handed out to a browser that has verified the correct password via a signed session cookie. Names and other gallery details also stay out of the page title and link previews until the password has been entered.

Cookies

We set functional cookies only: one to remember that you've unlocked a private gallery, and one (only if you've signed in to a dashboard session) to keep you logged in. We don't use advertising or analytics cookies, don't run any third-party tracking scripts on the site, and don't share your data with third parties for marketing purposes. If you're redirected to Stripe to pay, Stripe may set its own cookies on its own domain during that step; those aren't ours and aren't covered by this policy.

How long we keep it

A published gallery is hosted indefinitely, as part of what you pay for. A gallery you start but never pay for is a draft: it's never publicly visible, and it and any photos uploaded to it are automatically deleted after 72 hours of inactivity. If you refund a gallery, it's taken offline immediately but its data isn't deleted automatically, since you might still want to delete it yourself, reference it, or re-publish later; deleting it (see below) removes it and its photos for good, refunded or not.

Your rights and choices

Wherever you are, you have the right to see what we hold about a gallery, correct it, export it, or delete it, and you can do every one of those things yourself, immediately, with no request or waiting period:

  • Access and correction - everything you entered is visible and editable from your dashboard.
  • Export - your original, full-resolution photos can be downloaded individually from the gallery itself at any time.
  • Deletion - permanently deletes the gallery record and every photo behind it; see below.

Because these are self-serve and immediate, there's no separate request process or form for them, and no waiting on a support team, since we don't have one; the dashboard tools above are how these rights are exercised, for every visitor regardless of location.

Children's privacy

pom.gallery is a wedding gallery product and isn't directed at children. We don't knowingly collect personal information from anyone under 16, and a gallery's guests aren't asked for personal information in the first place beyond an optional password.

Security

Every page is served over HTTPS. Passwords are never stored in plain text, only as a salted hash. Account and manage links use signed, expiring tokens rather than long-lived passwords, so a leaked link can't be reused indefinitely. No system is perfectly secure, but we design every part of this one with that goal in mind.

Changes to this policy

If this policy changes, we'll update the date at the top of this page. We don't maintain a mailing list to notify you separately, so if that matters to you, check back here occasionally.

Removing your gallery or data

You can permanently delete your gallery and every photo in it yourself, anytime, from your dashboard. For step-by-step guidance on this or anything else, see the Help Center.