Privacy

What we hold, and for how long.

Last updated September 19, 2026. Get This Shot is run by Matano Enterprises LLC. This explains the information used by our website and iPhone app.

Guests

A guest never makes an account and is never asked for one. When someone scans an event code we create a record for them and put a cookie on their phone so the same device is recognised next time. That record holds a name and a table if they chose to give one, both optional and both editable. We also associate their contributions, favorites, hunt progress, and safety reports with an event-specific guest identifier.

We do not ask for a guest's email address, phone number or date of birth, and we have no way to contact a guest. We do not use advertising or analytics trackers, and there is no third-party script on any guest screen.

Photos, clips and messages

What a guest adds goes to the host's album for that event. We store the original exactly as it arrived and generate two smaller copies for display. We read the capture time and the dimensions from the file so the album can sort itself.

Photos also get an automatic quality check for blur and for near-duplicates. It runs on our own servers, produces a score, and decides only whether a photo waits for the host to look at it. Nothing is sent to a third party for this, and it is not face recognition: we do not detect, group, match or identify faces, and we hold no biometric data of any kind.

A fifteen-second message is only ever shown to the host of that event. It does not appear in the album, on the leaderboard, or on a venue screen. The number of messages is public; the messages are not.

Who can see an album

Anyone holding the event link can see that event's album. The code is eight characters and is not guessable in practice, but it is a link: whoever it is shared with can open it. A host can add a passcode. We ask search engines not to index album, card or event pages, and we set a no-index header on them.

Hosts

A host account holds an email address, optionally a name, and if they sign in with Apple or Google, the account identifier that provider gives us. We use the email address to send sign-in links and notices about their own events. We do not send marketing to it or sell it. Our service providers process it only to operate the service. Hosts may also save a profile photo, event details, and custom hunt prompts.

How long we keep things

Hosting runs 90 days for a free event and a year for a paid one. We email the host thirty days and seven days before it ends. On the date the album comes off the web and nothing is deleted. For a further year we keep the files, and the host can ask us at any point in that year to put the album back. After that year we delete them, and deletion means the files are removed from our storage rather than hidden.

Downloading everything at full size is free on every tier and available the whole time, so the end of hosting is never the moment somebody loses their photos.

A host can remove individual photos from the album. Deleted photos may remain in recovery storage for up to 30 days.

Deleting your account

Use Delete account in your web profile or the app’s Me tab. We remove your account, hosted albums and their photos within 30 days, and revoke linked Apple authorization. We may ask you to sign in with Apple again to securely complete that revocation. Restricted database backups expire within 90 days. Required payment records may remain with our payment provider. Guests can contact us to request removal of their contributions.

Who we use

Cloudflare hosts the service and stores the files. Resend sends our email. Stripe handles payments; card details go to Stripe and never reach us. Apple and Google also handle authentication when you choose their sign-in options. Google Analytics and Microsoft Clarity measure how our public pages are used, as described below.

Service activity and security

We retain purchase and refund records to apply event plans and handle billing. Payment card details are entered on Stripe's checkout, outside the app; we do not store card numbers.

We use IP-based, short-lived request counters to limit abuse, along with server request timing, status codes, and error information to keep the service working. Diagnostic records can include internal account or event identifiers. We do not use these records for advertising. When enabled, website error reports are sent to Sentry. Event codes and access tokens are removed from those reports, and we do not intentionally include guest names or contributed photos or videos.

How you found us

When you arrive through one of our short links, such as getthisshot.com/ig from a link in one of our profiles, we store that one word in a cookie on your device for 30 days. The cookie holds only the word, for example "ig". It carries no identifier, no account, and nothing taken from your device or your visit, so it cannot tell you apart from anyone else who arrived the same way and cannot follow you to another website. If you later create a host account, we copy that word onto the account once, so we know which link brought new hosts. It is never used for advertising and never shared.

We also count page views with Cloudflare Web Analytics on our public marketing pages only, never on an event, album or host page. It sets no cookie and does not identify visitors.

Counting visits

On our public marketing and legal pages, the ones anybody can reach without an event link, we use Google Analytics. It sets cookies in your browser and sends Google the address of the page you opened, an approximate location worked out from your IP address, and what kind of device and browser you are on. We do not use it for advertising and none of its advertising features are switched on.

On those same pages we also use Microsoft Clarity, which records how the page was used: where you clicked, how far you scrolled, how the pointer moved, and the same sort of page, device and approximate location detail. Those recordings are played back and added up so we can see where a page confuses people. It sets cookies. Text you type is masked before it leaves your browser, so what reaches Microsoft is the shape of a visit rather than its contents, and we do not use it for advertising.

Neither is on any other page. Event, album, hunt, message, host and back office pages carry no analytics and are never recorded. An event link is the key to that album, and we are not handing that key to anybody, Google or Microsoft included. That is the same rule our error reports already follow.

If you would rather not be counted, most browsers can block these scripts, Google publishes an opt out add on at tools.google.com/dlpage/gaoptout, and Microsoft explains Clarity and how to opt out at clarity.microsoft.com/terms. Browsers set to Global Privacy Control are honoured on these pages.

Asking us for something

Write to hello@getthisshot.com and we will act on it. That includes a host asking for their account and every event on it to be deleted, and a guest asking us to remove a photo of them or a record we hold about them. A guest who was at an event and wants something gone should say which event and roughly when, because with no account there is nothing else for us to look them up by.

Children

Get This Shot is for the person running an event, who we expect to be an adult. Guests at an event may be any age, which is exactly why nothing here profiles a guest, targets advertising, or does anything with faces.

Changes

If this changes in a way that matters we will tell hosts by email rather than quietly editing the date at the top.