Privacy Policy

Information we process

We process submission information (photograph, message, first name, optional surname/town, country, public-display contract version and optional official social-media-feature consent), account and authentication information, email-verification/password-reset information, payment lifecycle records, moderation/report records, favourites, public sharing and privacy-minimised engagement records. Email and account credentials are not public.

What becomes public

For future submissions, the photograph, message, first name, country, any supplied surname or town, and permanent submission number become public when approved, paid and eligible. Email remains private. Public display is intended to continue indefinitely, but valid privacy, legal, moderation, safety, technical and removal rules still apply. If content is removed, 100M suppresses the public pages and media it controls and stops new controlled promotional use; independent screenshots, downloads, browser or search caches, public archives and lawful reposts may remain outside its control. Official social-media featuring requires separate optional consent. Historic entries retain their earlier display choices.

Why and who processes data

100M is operated from England and Wales by an individual operator trading as 100M and operating 100000000.photos. That operator determines why and how customer, account, submission, support, moderation and payment-state data is used and is the data controller; use the contact page for privacy enquiries. IONOS acts as processor for hosting, MariaDB, generated media, sessions, application data, backups and email infrastructure. Microsoft acts as processor for Azure AI Content Safety text-and-image moderation. Stripe acts as processor for some services and as an independent controller for activities including fraud prevention, regulatory compliance and parts of payment operation. 100M sends Stripe the amount, currency, order/payment reference, required entry/account metadata, return URLs and idempotency information. Stripe also receives information directly from the customer and browser on Stripe-hosted Checkout, which may include payment-method details, name, email, IP/device information and other payment, fraud-prevention or regulatory information. 100M does not handle card details or store raw Stripe webhook payloads. Recipient mail providers are involved in delivering or receiving email.

On-demand message translation normally uses LibreTranslate first on infrastructure controlled by 100M. Microsoft Azure Translator remains a fallback. Only when that fallback is needed may 100M send Microsoft the public message text and language codes; it does not deliberately send account details, photographs or visitor identifiers.

Lawful bases

We use contract for account, submission, publication, payment-state and related service processing; legitimate interests for proportionate security, fraud/abuse prevention, necessary logging, moderation evidence and general enquiries; and legal obligation for tax/accounting records and data-rights handling. A more specific basis may apply to a refund or dispute record according to its purpose. Optional marketing communications use consent. We do not rely on blanket consent for the ordinary service.

Your data-protection rights

Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, portability and objection, and rights concerning applicable solely automated decisions. These rights are not absolute and exemptions or lawful retention may apply. You may complain to the UK Information Commissioner’s Office.

Make a privacy request

Complaints and dispute records

We process complaint contact details, descriptions, linked account, submission, moderation, rights, refund and payment-dispute references, staff notes, evidence summaries and outcomes to provide support, perform the contract, meet legal obligations and pursue legitimate interests in resolving and defending disputes. A narrowly scoped legal hold may temporarily retain necessary evidence, but it does not cancel a valid privacy request or justify retaining unrelated data. Records may be disclosed where legally required.

Moderation and automated decisions

Azure AI Content Safety assists moderation; it does not make an irrevocable final legal decision. Significant cases can be reviewed by a person, and you can use the contact route to ask for review or raise an objection.

Children and participation

Anyone may browse the public website and Gallery, but accounts, submissions, uploads and purchases are restricted to people aged 18 or over. We use a required self-declaration at that boundary and record its time; we do not collect date of birth or identity documents. There are no child accounts or parental-consent workflow.

Retention and controls

Subject to legal hold, an active dispute, fraud/security investigation or a longer legal requirement: published photographs, messages and associated public submission data remain while published and are removed following a valid withdrawal, deletion or removal decision; operational account/contact data is removed within 30 days after completed account deletion, except required financial, legal, security or audit records; unnecessary personal content from unpaid or abandoned submissions is deleted within 30 days after final expiry or abandonment; rejected content and moderation material is kept for up to 90 days after the final decision, with minimal moderation/audit metadata kept for two years; payment, refund and accounting records are kept for six years after the end of the relevant tax/accounting period; support correspondence is normally kept for two years after resolution, or up to six years where reasonably needed for a contractual or legal dispute; application/security logs are normally kept for 90 days, with incident records kept while needed; routine lifecycle mailbox copies are normally kept for 12 months; IONOS Web Hosting visitor diagnostics are stated by IONOS to be kept for eight weeks and automatic hosting backups to be available for up to 14 days; guest entitlement tokens last 30 days. Account controls or the contact page can be used for privacy requests. Favourites are private to the account and public statistics are aggregate.

Security, continuity, backups and succession

100M uses reasonable technical and organisational security and preservation measures, including backups where configured, without promising that every incident or loss can be prevented. If an incident or service failure occurs, we may preserve necessary evidence, restrict affected processing, investigate, restore from appropriate backups where reasonably possible, notify people or authorities where legally required, and retain only records justified by law, claims or the Retention Schedule. A lawful future transfer of the service or business to a successor would require appropriate protection of personal information, compliance with applicable controller-transfer duties and respect for customer rights; it is not authority to sell customer photographs separately from the service.

Payment and refund records

Stripe processes refund information. Account deletion or content removal does not erase financial, refund, legal or audit records that 100M must legitimately retain. Privacy removal rights and financial refund rights are separate.

Cookies, children and contact

See the Cookie Policy. Participation is for people aged 18 or over. Azure AI Content Safety receives submitted message text and generated image bytes for detection; Microsoft states that detection inputs are not stored, used to train its models or made available for Microsoft human review, and remain in the selected resource region. Stripe may process data internationally under its applicable DPA and transfer mechanisms. The footer social-media destinations are outbound links only: 100M loads no social pixel, SDK, embedded feed or tracking code before a visitor follows a link.