UPhoto Privacy Policy

1. Effective Date

Effective: March 1, 2026. This Privacy Policy explains how UPHOTO PTE. LTD. ("UPhoto", "we") collects, uses, discloses and protects your personal data when you use our websites, software and services (the "Services"), in accordance with the Singapore Personal Data Protection Act 2012 (PDPA).

2. What We Collect

Account information: name, email, phone number, payment info and address provided at sign-up, upgrade or two-factor setup.

Your Content: photos, videos and album data you upload, plus related metadata (file size, upload time, collaborators, activity).

Usage information: actions such as sharing, editing, viewing and creating.

Device information: IP address, browser/device type, OS, mobile network, crash reports.

Location information: approximate location derived from GPS, IP address, Wi-Fi and activity.

Biometric information: where you use face/body recognition features, we extract facial and body features, key points and gestures from content you actively provide. This is sensitive personal data; we process it only with your explicit consent and for the specific feature you enable.

Cookies and similar technologies: to provide, improve and protect the Services.

3. Purposes & Legal Basis

We collect and use your data only for purposes you have been notified of and have consented to:

(a) to provide and operate the Services (storage, live-streaming, AI enhancement, sharing);

(b) to verify accounts and ensure security;

(c) to communicate with you about the Services and, where permitted, send optional marketing (you may opt out any time);

(d) to develop and improve the Services;

(e) to comply with legal obligations.

We will not use your data for new, unrelated purposes without obtaining your consent.

4. Sharing & Disclosure

We do not sell your personal data. We may share it with:

(a) trusted service providers (cloud, CDN, payment) acting on our instructions;

(b) other UPhoto group companies where infrastructure is shared;

(c) other users, where you choose to make content available;

(d) third-party apps you connect via our APIs;

(e) your organisation administrator, if you use a Business Team account;

(f) authorities, where disclosure is reasonably necessary to comply with law, protect safety or prevent fraud.

5. International Transfer

Our primary servers are located in Singapore. Where we transfer your personal data outside Singapore (including to group companies or processors), we will ensure the recipient provides a standard of protection comparable to the PDPA, such as through contractual safeguards consistent with the PDPC's Model Contractual Clauses, before the transfer occurs.

6. Security

We maintain technical and organisational measures — including encryption in transit and at rest, access controls, two-factor authentication and continuous vulnerability testing — to protect your personal data against unauthorised access, collection, use or disclosure. Biometric data is stored securely and is not directly accessible or shareable by you or third parties.

7. Retention

We retain your personal data only for as long as necessary to provide the Services or to meet legal obligations. On account deletion, we initiate deletion of your stored data after 7 days. Biometric data is retained for 7 days from upload by default and auto-deleted thereafter, unless you choose a different period for subsequently uploaded content.

8. Your Rights

Subject to the PDPA, you have the right to:

(a) access the personal data we hold about you and how it was used or disclosed in the past year;

(b) request correction of inaccurate data;

(c) withdraw your consent at any time, where processing is based on consent (withdrawal does not affect prior lawful processing);

(d) request the transmission of your data to another organisation in a commonly used machine-readable format where the data portability obligation applies;

(e) object to or limit certain processing.

To exercise any right, contact our Data Protection Officer at service@uphoto.cc; we will respond within a reasonable time.

9. Data Breach Notification

If a data breach affects your personal data and is likely to result in significant harm to you, or affects 500 or more individuals, we will notify the Personal Data Protection Commission (PDPC) and affected individuals as soon as practicable, in accordance with the PDPA and the Notification of Data Breaches Regulations 2021.

10. Children

Where the Services are used by or for minors (e.g., at events), we rely on the consent of a parent or legal guardian for the collection and processing of the minor's personal data, as described in Section 3 of the User Agreement. We do not knowingly collect personal data from a child without such consent.

11. Data Protection Officer

UPhoto has designated a Data Protection Officer (DPO) accountable for PDPA compliance. Contact: service@uphoto.cc

12. Changes

We may update this Policy from time to time. Material changes will be notified in-app or by email in advance. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.