Privacy Policy

Last updated: 16 August 2026
Draft — not yet legally reviewed. This page describes how Snapdrop actually works today, in plain language, but it hasn't been reviewed by a lawyer and should be before you rely on it for real GDPR/legal compliance.

Snapdrop ("we", "us") provides a service that lets print and copy shops ("shop owners", "you") receive photos from their customers via a QR code. This policy explains what data we collect and why, for both shop owners and their customers.

1. Data we collect from shop owners

2. Data we collect from your customers

Customers using the QR code to upload photos do not create an account and are not tracked. Specifically:

3. How we use this data

4. Where data is stored

Data is stored on our hosting provider's servers. Uploaded photos are stored as files; account and order data is stored in a database. Both are deleted according to the retention rules above.

5. Third parties we use

We don't share your data with anyone else.

6. For Pro subscribers — payment processing

This section only applies if you subscribe to the Pro plan — it doesn't affect free accounts or your customers, since customers never provide payment details to us at all.

We use Stripe to process your subscription payment. Stripe holds your billing information directly — your email, name, billing address, and payment method — we never see or store your full card details ourselves. Stripe's own privacy policy governs how it handles the data it holds directly.

If you cancel or your account is deleted, we ask Stripe to delete what it can from your customer record. Stripe generally retains the underlying transaction records (invoices, receipts, payment history) regardless, since payment processors have their own legal obligation to keep financial records for tax and accounting purposes for a number of years — this sits outside our own data retention practices described elsewhere in this policy, and isn't something we can override on your behalf.

7. Your rights

As a shop owner, you can delete individual orders at any time from your dashboard, and can request deletion of your entire account. Since your customers don't have accounts with us, their main protection is that their photos are automatically deleted after your plan's retention period.

8. Cookies

The customer-facing upload page uses no cookies at all. The shop owner dashboard and staff portal use a session cookie required to keep you signed in, and (if you choose "remember this device") a longer-lived device-trust cookie to skip two-factor authentication on devices you've already verified. Neither is used for tracking or advertising.

9. Contact

Shawcando Consulting
Ardbaun, Thurles, County Tipperary, Ireland
support@shawcando.com