Privacy Policy
Last updated 21 August 2026
This Privacy Policy explains how Klik processes personal data when you use our website and the Klik service for collecting event photos, videos and messages. We have written it to be read, not just filed. Where the law gives you rights, we tell you how to use them.
1. Who we are
Klik ("Klik", "we", "us", "our") is a service operated by Front Tribe d.o.o., a limited liability company registered in Croatia under court-register (MBS) number [COURT REGISTER No.] and OIB [OIB], with its registered office at [REGISTERED ADDRESS].
For any question about this policy or your personal data, contact us at hello@klikapp.co. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; privacy requests are handled directly by the company at that address.
For the personal data we process to run our own business — host accounts, billing, security and communications with hosts — we are the "data controller" under the EU General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the GDPR (Zakon o provedbi Opće uredbe o zaštiti podataka).
2. Controller and processor — an important distinction
Klik has two different roles depending on the data:
- ·Host account & service data (e.g. a host's email, sign-in method, event settings, security logs): we are the controller and this Policy governs it.
- ·Event content uploaded by guests (photos, videos, messages and any optional name a guest types): here the host who created the event is the controller — it is their event and their guests — and Klik acts as a processor that stores and displays that content on the host's behalf, under our Terms of Service which include data-processing terms.
This means the host is responsible for having a lawful basis to collect their guests' photos and for informing their guests appropriately. Klik processes that content only to provide the service, following the host's instructions, and never sells it or uses it to train models or for advertising.
3. The personal data we process
Host account data
- ·Email address (required to create an account).
- ·Authentication data: a securely hashed password if you sign up with email/password, or your Google account identifier and basic profile (name, email) if you sign in with Google.
- ·Session data: cookies that keep you signed in (see "Cookies" below).
Event data
- ·Event name, optional event date, welcome message, chosen theme, gallery settings and the unique event link/QR code.
Guest-contributed content
- ·Photos, videos and text messages that guests choose to upload.
- ·An optional first name a guest may type. Guests do not create accounts and we do not ask them for an email, phone number or any account credential.
- ·Note: photos and videos can contain personal data about identifiable people (guests and third parties). We do not run facial recognition and do not intentionally derive biometric or other special-category data from them.
Technical and security data
- ·IP address and basic request metadata, used transiently for rate-limiting and to protect the service against abuse. We do not store IP addresses in our application database alongside uploads.
- ·Standard server logs kept for a short period for security and debugging.
Content-moderation data
- ·To keep events safe, uploaded images may be automatically screened for clearly unsafe content (for example, explicit or violent imagery) by a moderation provider. This is an automated technical check that returns a safety score; it is not used to profile the people in a photo, and no facial-recognition or identity matching is performed.
Email delivery data
- ·When we send you a transactional email (for example a password reset, a first-upload notification or an event-ended notice), your email address and the message are processed by our email provider.
We do not use advertising cookies, third-party trackers, ad pixels or cross-site analytics.
4. Why we process it, and our legal bases
Under Article 6 GDPR we rely on the following legal bases:
- ·Performance of a contract (Art. 6(1)(b)): to create and secure your account, create and run your events, store and display uploads, and send you transactional emails that are part of the service.
- ·Legitimate interests (Art. 6(1)(f)): to keep the service secure, prevent abuse and rate-limit uploads, screen uploads for clearly unsafe content, debug problems, and understand aggregate, privacy-preserving usage. You may object to processing based on legitimate interests (see "Your rights").
- ·Consent (Art. 6(1)(a)): where consent is the appropriate basis — for example, a guest choosing to upload their photos to an event is a clear affirmative act. You can withdraw consent at any time, without affecting processing that already took place.
- ·Legal obligation (Art. 6(1)(c)): where we must process data to comply with the law.
For guest-uploaded content, the host (as controller) is responsible for establishing the appropriate legal basis for collecting their guests' content and for informing their guests. Klik processes it under the host's instructions as their processor.
5. Who we share data with (sub-processors)
We do not sell personal data and we do not share it for advertising. We use a small number of carefully chosen service providers who process data on our behalf under contract:
- ·Supabase — database, file storage and authentication. Event media and account data are stored in the European Union (currently [DATA REGION]).
- ·Vercel — application hosting and content delivery (serving the website and app).
- ·Resend — delivery of transactional emails to hosts.
- ·Sightengine — automated screening of uploaded images for clearly unsafe content.
- ·Google — only if a host chooses "Continue with Google" to sign in (OAuth).
- ·Stripe — payment processing, only if and when you buy a paid plan. Card details are entered directly with Stripe and are never seen or stored by Klik.
We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety and property of Klik, our users or the public.
6. International transfers
We aim to keep personal data within the European Economic Area (EEA). Some of our sub-processors are established in the United States or operate globally. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR — such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework — to ensure your data receives an equivalent level of protection.
You can ask us for more detail about a specific transfer or safeguard by emailing hello@klikapp.co.
7. How long we keep it
- ·Event media and messages are retained for the event's storage window (30 days after the event on the free tier; longer on paid plans). After the window closes, and following a short grace period during which the host can still download, the media is deleted.
- ·Media that a host deletes is removed from the live gallery immediately and deleted from our storage within 24 hours.
- ·Host account data is kept while your account is active and deleted when you delete your account (subject to short-lived backups and any records we must keep by law).
- ·Security logs are kept only for a short period.
Deleting an event removes its media, messages and settings; this cannot be undone.
8. How we protect it
- ·Encryption in transit (TLS) for all traffic to and from the service.
- ·Row-Level Security in the database so that events and uploads are only accessible to the right parties; event links use unguessable identifiers and are never listed or indexed.
- ·Uploads are validated and size-limited; privileged keys are used only on the server and never exposed to browsers.
- ·Access to production data is limited to what is necessary to operate the service.
No online service can be guaranteed to be 100% secure, but we work to protect your data using appropriate technical and organisational measures.
9. Your rights
Subject to the conditions in the GDPR, you have the right to:
- ·Access the personal data we hold about you and receive a copy;
- ·Rectify inaccurate or incomplete data;
- ·Erasure ("be forgotten") in certain circumstances;
- ·Restrict or object to certain processing, including processing based on our legitimate interests;
- ·Data portability — receive certain data in a structured, machine-readable format;
- ·Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email hello@klikapp.co. We will respond within the time limits set by law (normally one month). We may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If you are a guest and want a photo of you removed, you can contact the host of the event directly, or contact us and we will help facilitate the request with the host who controls that event.
You also have the right to lodge a complaint with a supervisory authority. In Croatia this is the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka, AZOP — azop.hr); you may also complain to the authority in your country of residence.
10. Children
Klik is not directed at children and hosts must be adults. Event photos may nonetheless include children who are guests. The host, as controller, is responsible for any consents required in relation to minors appearing in uploaded content. If you believe a child's personal data has been uploaded without an appropriate basis, contact us and we will act on it promptly.
11. Cookies
We use only strictly-necessary cookies to keep hosts signed in. Guest upload and gallery pages set no non-essential cookies. See our Cookie Policy for details. Because these cookies are essential to provide a service you asked for, they do not require consent under the ePrivacy rules.
12. Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects about you. Upload cap and expiry checks are simple technical rules, and automated content screening only flags an upload for a host's review — a human (the host) always makes the final call. Neither is profiling.
13. Changes to this policy
We may update this Policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, notify hosts by email or in-app. Continued use of the service after an update means you accept the revised Policy.
14. Contact
Questions, requests or complaints: hello@klikapp.co. Postal: Front Tribe d.o.o., [REGISTERED ADDRESS].