Taggix

Privacy Policy

Last updated: 2026-09-02

Data controller: Davide Finzi Carraro, a natural person established in Italy. Certified electronic domicile (PEC): davidefinzicarraro@pec.it. Data-protection contact: privacy@taggix.app.

1. Introduction and scope

This Privacy Policy explains how the Operator collects, uses, and protects personal data when you use Taggix (the “Service”). It applies to Users and, where relevant, to people depicted in uploaded photos.

2. Data controller

The controller of your personal data is Davide Finzi Carraro, a natural person established in Italy. Certified electronic domicile (PEC): davidefinzicarraro@pec.it. You can reach us about any data-protection matter at privacy@taggix.app.

No Data Protection Officer has been appointed.

3. Data we collect

Account data: email address, display name, password hash, and language preference.

Consent data: the record of the terms, privacy, and marketing choices you make, kept in an append-only ledger, and your current marketing preference.

Content and embedded personal data: photos you upload, which may depict identifiable people, and the identifiers detected in them — such as bib or sail numbers (via OCR) and AprilTag codes — together with the Universal Tags used to match Participants.

Pro data: for accredited photographers, the professional contact details you choose to publish.

Credits and activity data: your Credit balance and transactions, Matches, reviews, and similar activity needed to run the Service.

Usage, device, and log data: technical information needed to operate and secure the Service, including the IP address and browser user-agent recorded when you create your account, sign in, upload photos, download photos, or create a public share link.

Removal requests: if you use the removal-request form on a shared photo page, we record what you tell us, the email address you choose to give (optional), and the IP address the request came from. You do not need an account to send one. We use this to review the request, to reply to you if you gave us an address, and to detect repeated abuse of the form, based on our legitimate interests (Art. 6(1)(f) GDPR).

Event-hosting requests: if you ask us to host an event, we record the contact details you provide (name, email address, and a phone number if you give one), the organization you represent (its name, and your role in it and its website if you give them), and the details of the event itself (its name, kind, period, location, the number of participants you expect, and any notes you add). We use this to assess the request, to reply to you, and to set the event up if we accept it, in order to take steps at your request before entering into a contract and then to perform it (Art. 6(1)(b) GDPR).

4. Purposes and lawful bases

We process data to provide the Service and perform our contract with you (Art. 6(1)(b) GDPR); to keep the Service secure, prevent abuse, and promote Taggix, based on our legitimate interests (Art. 6(1)(f)); to send marketing email only where you have given consent (Art. 6(1)(a)); and to comply with legal obligations (Art. 6(1)(c)).

5. The reversed-sharing model and depicted persons

Taggix works by letting photographers upload event media and matching it to Participants. As a result, a photo may contain personal data of a person who is not a User.

We process that data to operate the matching Service, relying on our legitimate interests and on the uploader’s responsibility to have the right to upload it. Any depicted person may object to this processing or request removal — see “Your rights” and “Rights of depicted persons who are not Users” below.

6. OCR and tag detection — what it is and isn’t

To suggest Matches, the Service reads identifiers from images using optical character recognition (for example, bib or sail numbers) and detects AprilTags. This is rule-based matching on identifiers and tags. The Service does not perform facial recognition and does not process biometric data to uniquely identify individuals.

7. Recipients and processors

We use a small number of service providers (processors) who act on our instructions: Google Cloud provides hosting and media storage in EU regions under a data-processing agreement and standard contractual clauses; Resend delivers transactional email (such as password-reset and notification messages).

We do not sell your personal data.

8. International transfers

We store media in EU regions. Where any transfer of personal data outside the EEA occurs, it is protected by appropriate safeguards such as the European Commission’s standard contractual clauses.

9. Retention

We keep personal data for as long as your account is active and as needed to provide the Service and meet legal obligations, after which we delete or anonymize it. The periods and criteria below apply per category.

Account data (email, display name, password hash, language preference): for the life of your account. When you close your account we delete your profile and linked sign-in identities, and replace your account record with a non-identifying record retained only to preserve the integrity of records we must keep.

Photos and media: for the life of your account. If you close your account, photos that other Users have already confirmed into their personal galleries are retained as part of those Users' galleries; photos with no confirmed match are deleted, together with the identifiers detected in them.

Detected identifiers (OCR readings and AprilTag detections): for as long as the associated photo exists.

Matching and activity data (match suggestions, reviews, gallery items, Universal Tags, event memberships, notifications): for the life of your account.

Sign-in sessions: up to 14 days, and deleted when you sign out, reset your password, or close your account.

Password-reset tokens: 1 hour. Email-verification tokens: 24 hours. Both are stored hashed.

Roster invitations: accounts created from an event roster and never claimed are deleted after 60 days.

Event-hosting requests: for as long as your account is active and we need them to assess the request and run any event that results. They are deleted when you close your account.

Server and security logs: 30 days, held by our hosting provider.

Public share links: when you share a photo, we store a link record — the photo, a hashed token, and when you created it — until you stop sharing it. Stopping the share, removing the photo from your gallery, or closing your account disables the link immediately. Note that disabling the link cannot remove an image you have already posted elsewhere.

Security and attribution records (the IP address and browser user-agent recorded when an account is created, when it is signed into, when photos are uploaded or downloaded, and when a public share link is created): 12 months, after which they are automatically deleted. We keep these to secure the Service, prevent abuse, and be able to respond to reports of unlawful content (Art. 6(1)(f) GDPR, supported by our obligations under the Digital Services Act). If you close your account, these records are retained for the remainder of that 12-month period for the establishment, exercise, or defence of legal claims (Art. 17(3)(e) GDPR), and are deleted at the end of it.

Removal requests sent through the form on a shared photo page: the email address and IP address of the person who sent the request are erased 12 months after we review it. The request itself, and the decision we took, are kept for the establishment, exercise, or defence of legal claims (Art. 17(3)(e) GDPR), because they are evidence in a dispute about another person's content. A request is also deleted outright if the share link it concerns disappears — for example when the person who shared the photo closes their account.

Consent records: retained after account closure as proof of the consents and acceptances you gave, as required by our accountability obligations (Art. 7(1) GDPR).

Moderation cases, content reports, and administrative audit logs: retained for the establishment, exercise, or defence of legal claims and to prevent abuse (Art. 17(3)(b) and (e) GDPR), for as long as necessary for those purposes.

10. Your rights

You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time (for example, for marketing) without affecting prior processing. To exercise these rights, contact us using the details below.

If you have an account, you can also access and download a copy of your personal data, and delete your account, directly from your profile settings, without needing to contact us.

You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali.

11. Rights of depicted persons who are not Users

If you appear in a photo on Taggix but do not have an account, you can still object to the processing of your image or request its removal. We will handle your request as required by applicable law.

If you were shown the photo through a public share link (an address beginning /s/), the quickest route is the removal-request form on that page: it identifies the exact photo for us. You can also contact the Operator directly using the details below, whether or not you have a link. Sending a request does not take the photo down by itself — a person reviews it and decides — because a link can be forwarded to anyone, and an automatic takedown would let any recipient remove any shared photo.

12. Children’s privacy

The Service is not intended for children under 16, or the higher minimum digital-consent age in your country. We do not knowingly collect their personal data; if we learn that we have, we will delete it.

13. Security

We protect personal data with measures including hashed passwords (scrypt), signed session tokens, watermarked delivery of photos to non-uploaders, EU-region storage, and access controls. No system is perfectly secure, but we work to protect your data.

14. Cookies

We use a small number of cookies. A strictly necessary cookie keeps you signed in, and a consent cookie remembers your cookie choices; these do not require consent.

With your consent, we use Google Analytics (provided by Google) to understand how the service is used. It sets analytics cookies and is loaded only after you accept analytics cookies in our cookie banner. We use IP anonymisation and do not use advertising cookies.

You can change or withdraw your choice at any time using the “Cookie preferences” link in the site footer or, when signed in, from your profile.

15. Automated decision-making

Match suggestions are produced by rule-based detection of identifiers and tags. We do not carry out automated decision-making that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR.

16. Data breaches

If a personal-data breach occurs that is likely to present a risk to your rights, we will notify the competent supervisory authority and, where required, affected individuals, in line with the GDPR.

17. Changes to this policy

We may update this policy. For material changes, we will require you to review and accept the updated version before continuing to use the Service.

18. Contact and complaints

Contact: privacy@taggix.app, or by certified electronic mail at davidefinzicarraro@pec.it. No Data Protection Officer has been appointed. You may also lodge a complaint with the Garante per la protezione dei dati personali (Italy) or your local supervisory authority.