This policy explains what SmileTrack.org ("SmileTrack") collects, why, and what you can do about it.
The short version:
- Guests can contribute without an account. We collect almost nothing about them.
- Photos and messages stay up indefinitely. That is deliberate.
- Anyone can ask us to remove a photo they're in, including people who never used the service.
- We don't sell your information and we don't use facial recognition.
1. Who this covers
Guests — contribute to an event, no account. Hosts and planners — create events, may have accounts and make purchases. People in photos — may have never used SmileTrack at all, but appear in content others uploaded. Section 8 is for you.
2. What we collect
From guests (no account)
- Photos and messages you upload, including any metadata embedded in the file that survives the processing described in Section 3
- A display name you type, associated with your contributions
- Card association, if you arrived by scanning a smile card
- Technical data: IP address, browser type, and timestamps, kept in server logs for security and abuse prevention
We do not require your email, phone number, or real name.
From hosts and planners
- Name and email address
- Google account identifier, if you sign in with Google
- Event details you provide: event name, date, and guest count
- Guest names you enter for printed place cards
- Shipping address for physical orders
- Purchase records
We do not receive or store your full payment card number. Payments are processed by Stripe.
From everyone
Basic usage and error data so we can keep the service working.
3. Photo metadata
Photos from phones often carry embedded data, including GPS coordinates and the device model.
We remove embedded metadata, including GPS location, from every photo we store. The version shown in the gallery is re-encoded in your browser before it is sent, which discards the metadata entirely. The full-resolution original that a host can download is scrubbed of its embedded metadata block on arrival at our servers. Where we receive an original in a format we cannot reliably scrub, we do not keep that original at all — the gallery version is kept instead.
4. Why we collect it
- To run events and display galleries
- To connect a guest's contributions to their name so they don't retype it
- To print and ship place cards
- To process purchases
- To respond to support and removal requests
- To prevent abuse, spam, and automated access
- To meet legal obligations
We do not use your content to train machine learning models. We do not use it for advertising.
5. Who can see your content
Anyone holding the event code. Access is by code, and codes can be shared. A guest, a host, or someone who finds a lost card can view the gallery.
Hosts can view, hide, delete, and download everything in their event.
We can, to the extent needed to operate the service, investigate abuse, or respond to a removal request. We do not browse galleries otherwise.
We do not sell personal information and we do not share it with advertisers or data brokers.
We share data with service providers (Section 6), with law enforcement when legally required, and with an acquirer if the business is sold — in which case this policy continues to apply until you're notified of a change.
6. Service providers
| Provider | What they handle |
|---|---|
| Vercel | Website hosting |
| Vercel Blob | Photo and video storage |
| Stripe | Payment processing |
| Optional sign-in | |
| Web3Forms | Delivery of the sales inquiry forms on our Hosts and Planners pages |
| SMTP2GO | Transactional email |
Each has its own privacy policy.
7. How long we keep it
Event galleries do not expire. We do not delete them for non-payment, for inactivity, or after a fixed window. This is a deliberate commitment.
What that means for you: a photo you upload today may remain viewable to anyone holding that event code for years. Please upload accordingly.
Other retention:
- Server logs — retained for the period our hosting provider applies to runtime logs
- Purchase records — as long as required for tax and accounting, generally seven years
- Guest names for printing — kept with the event's card records
- Account data — until you delete your account
If we ever shut down, we will give at least 90 days' notice and a way to retrieve your content.
8. If you're in a photo and didn't put it there
You can ask us to remove it, whether or not you have ever used SmileTrack.
Send us a removal request — no account needed — or email support@smiletrack.org with the event name or code and enough description to identify the photo. We will respond within 30 days. You do not need the host's permission and we will not require you to create an account.
Removal deletes the file from our storage, including originals. We cannot recover copies already downloaded by others.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to opt out of sale or sharing — we don't do either.
California residents (CCPA/CPRA): we do not sell or share personal information as those terms are defined, and we do not knowingly collect from anyone under 16 without consent. You may exercise your rights without discrimination.
EU/UK residents (GDPR): our lawful bases are contract (running an event you participate in), legitimate interests (security, abuse prevention), and consent where required. You may object to processing, request portability, and lodge a complaint with your supervisory authority.
To exercise any right, email support@smiletrack.org.
10. Biometrics and facial recognition
We do not use facial recognition, face matching, face grouping, or any other biometric identification. We do not generate faceprints. We do not let hosts or guests search a gallery by face.
Some competing products offer this. We have chosen not to, and if that ever changes we will say so clearly and obtain consent before any such feature operates.
11. Children
SmileTrack is not directed to children under 13, and we do not knowingly collect personal information directly from them.
Children commonly appear in event photos uploaded by adults. Hosts are responsible for their guest lists and for content in their events. A parent or guardian may request removal of a photo of their child under Section 8.
12. Security
We use encryption in transit, access controls on stored content, rate limiting on code resolution, and least-privilege administrative access.
Event access is by code, not password. Codes are randomly generated and impractical to guess, but anyone holding one can view that event. Share yours carefully.
As a Massachusetts business, we maintain a written information security program consistent with 201 CMR 17.00.
No system is perfectly secure. If we experience a breach affecting your personal information, we will notify you as required by law.
13. Cookies and tracking
We use cookies and local browser storage for:
- Keeping you signed in, if you have an account
- Remembering who you are at an event, so you don't retype your display name. The cookie holds an opaque identifier; the name itself is stored on our servers
- Remembering which card you scanned
- Remembering recently visited events
We do not use advertising cookies or third-party tracking pixels.
14. Changes
We may update this policy. Material changes will be posted with a revised effective date. If a change materially affects how we handle content already uploaded, we will make a reasonable effort to notify affected hosts.
15. Contact
SmileTrack.org
PO Box 1234, Middleboro, MA 02346
support@smiletrack.org