Data Privacy Covenant

Privacy Policy

Last Updated: September 7, 2026 · Privacy principles governing life's greatest celebrations, ephemeral biometric facial discovery, and Google user data protection.

The Privacy Covenant

1. Zero Ad-Brokering & Zero Tracking

We never sell, rent, or monetize your personal information or private celebration photos to third-party advertisers, data brokers, or behavioral tracking networks.

2. Affirmative Biometric Consent

AI face search requires an explicit affirmative selfie capture. Facial vectors are mathematical numbers used exclusively to help you find your own photos, never for public identification.

3. Instant 1-Click Biometric Erasure

You retain full control over your biometric data. You can delete your facial vector and search history at any time with a single tap from your profile or the gallery.

4. Zero-Friction Guest Experience

Attendees are never forced to download an app, create an account, or share personal phone numbers to celebrate, capture candids, or view memories.

1. Overview & Regulatory Compliance

SLING (“SLING”, “we”, “our”, or “us”) provides an elevated digital collective archive and computational camera experience for weddings and milestone celebrations. This Privacy Policy outlines how we collect, process, and protect information when you visit our website, host a celebration, or attend as a guest.

We design our privacy physics from first principles to comply with the world's leading biometric and data protection frameworks:

  • India Digital Personal Data Protection (DPDP) Act, 2023: Lawful, purpose-limited processing with clear consent architecture and accessible grievance redressal mechanisms.
  • General Data Protection Regulation (GDPR - Art. 9): Elevated safeguards for special category biometric data processed solely under explicit affirmative consent.
  • United States Privacy Standards: California Consumer Privacy Act (CCPA/CPRA) and Illinois Biometric Information Privacy Act (BIPA) standards for transparency, notice, and non-sale of consumer data.

2. Biometric Find Me AI & Facial Vector Lifecycle

Our optional “Find Me” feature allows guests to find all photos of themselves across hundreds of celebration moments without scrolling manually through the entire gallery. Here is exactly how it works:

Affirmative Consent First

We will never scan your face without your explicit, voluntary action. To use Find Me, you must tap “Find My Photos”, review the biometric consent notice, and take a real-time verification selfie.

Mathematical Vectors, Not Human Faces

When you submit a verification selfie, our secure vision engine converts the geometric facial features into an encrypted mathematical coordinate string (a 128-dimensional or 512-dimensional numerical vector embedding). Your original selfie is not saved as a public photo.

Scoped Exclusively to One Celebration

Facial vectors are strictly isolated to that specific celebration's photo collection. We never cross-reference faces across different events, never build global facial profiles, and never share vectors with external third parties.

Instant 1-Click Permanent Erasure

You can permanently delete your facial vector and all associated search history at any moment by clicking “Clear My Face Data” in the gallery or your profile. Once initiated, all biometric records are immediately purged from our servers.

Automated Expiration

All event facial vectors are automatically and permanently destroyed when the host's cloud storage vault duration expires.

Google API Services Disclosure

3. Google Sign-In & OAuth Data-Use Disclosures

To provide organizers and hosts with a fast, passwordless login experience, we support Google Sign-In (OAuth 2.0 / Google 1-Tap). We adhere to strict standards regarding Google user data:

Information Accessed

When you choose to authenticate via Google, we request access solely to your basic, public Google account profile: your full name, primary email address, and profile picture avatar. We do not request access to your Google Drive, Gmail, Google Photos, contacts, calendar, or any other sensitive scopes.

Purpose of Processing

We process this Google account information strictly to create and authenticate your Host Studio management account, verify celebration ownership, and send essential transactional receipts and event access credentials.

Strict Limitations on Sharing & Use

  • No Third-Party Transfer: We do not transfer, sell, or disclose your Google user data to any external parties or advertising networks.
  • No Generalized AI Training: Google user data is never used to train generalized artificial intelligence or machine learning models.
  • No Commercial Exploitation: Google user data is never used for serving advertisements or behavioral re-targeting.

Google API Services User Data Policy Compliance

Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking Access

You can revoke our access to your Google account at any time by visiting your Google Account Security Settings at myaccount.google.com/permissions.

4. Data Retention & Storage Vault Lifecycle

All celebration media is preserved in cloud storage vaults for the explicit duration of the host's chosen package:

  • Taste Tier: 14 days storage vault.
  • Intimate Tier: 6 months storage vault.
  • Celebration Tier: 12 months (1 full year) storage vault.
  • Festival Tier: 12 months storage vault.
  • Bespoke Tier: Custom storage duration, agreed per engagement.

Hosts are notified in advance of vault expiration with the option to download their complete master archive or extend their preservation period. Upon vault expiration, all event media and associated face search indices are permanently purged from active production servers.

5. Technical Security & Infrastructure

We employ enterprise-grade cryptographic and infrastructural safeguards to keep your celebration safe:

  • Encryption in Transit & at Rest: All media transfers are encrypted using TLS 1.3. Cloud storage objects are encrypted using AES-256 standards.
  • Host PIN Authentication: Management actions (moderation, downloads, event settings) are guarded by multi-factor PIN verification and encrypted session tokens.
  • Zero Search Engine Indexing: All celebration albums, attendee candids, and guest views are permanently blocked from public search engines with strict disallow-all robots directives.

6. Data Fiduciary & Statutory Grievance Redressal

In accordance with Section 8 of the Digital Personal Data Protection Act, 2023 and Rule 5(6) of the Consumer Protection (E-Commerce) Rules, 2020, our designated Data Protection & Grievance Redressal channels are published below:

Statutory Grievance Officer Disclosure

Grievance Desk & Administrative Inquiries: hello@sling.photo

Redressal Timeline: All grievances and privacy inquiries received are formally acknowledged within 48 hours and resolved within 30 days of receipt.

© 2026 SLING. All rights reserved.