Legal
Privacy
What Letsseeme collects, whose it is, and everyone else who touches it. Written to be read rather than survived.
Last updated 7 September 2026. This is a plain-language policy written to describe the product as it is actually built. It is not legal advice and has not been reviewed by a lawyer, and the owner should have one review it before relying on it commercially.
In short
Your photos
The photos and video from your session are stored so they can be sent to you and shown to the people who booked the event. They are not sold, not shared with advertisers, and not used to train anything.
Your number
A phone number only ever gets in because someone typed it into a booth themselves. Reply STOP to any message and the texts stop straight away.
No face recognition
Nothing in this product scans, measures or matches a face. There is no selfie step and no faceprint, anywhere.
Your card
Card details go straight to Stripe. They never touch our systems and we could not see them if we wanted to.
Who to ask
The operator who ran the event decides what happens to your details. We hold them on that operator's behalf. Either of us can pass a request to the other.
Three kinds of people
Almost every privacy question about Letsseeme has a different answer depending on who is asking, so this page is arranged around the three people involved.
- The operator — the photo booth business that licenses the software and turns up at the venue with the iPad. They hold an account with us.
- The guest — anyone who walks up to a booth at an event. Guests have no account and never signed anything with us.
- The host — whoever booked the operator: the couple, the company, the birthday. They receive a gallery of the night afterwards.
For guest data, the operator is the controller and we are the processor. In plain words: the operator decides why guests are asked for a number, what is said to them, what is promised, how long anything is kept, and whether they are contacted again. We only hold and move that data on the operator's instructions, and we do not decide any of those things ourselves.
What that means for a guest: if you want your details changed or removed, the operator whose event you attended is the person who decides, and the fastest route. If you do not know who that was, tell us the event name and the date and we will pass it to them and to whoever else needs it. We will not ignore you because you are not the account holder.
For an operator's own account data — their name, their events, their billing — we are the controller, because those are our decisions to make.
If you are a guest
Photos and video
Every session produces the individual frames the camera took, the finished picture with the event's design on it, a small thumbnail, and, in a GIF or video mode, the clip. All of it is stored so that it can be sent to you, shown on the screen in the room if the operator turned that on, put into the host's gallery, and included in the highlight reel the host is emailed after the event.
How long it stays is a window the operator sets, and it runs on its own. Every event's full-size photos and videos are kept for the operator's retention window: 30 days after the event unless the operator changes it, and they can choose anything from 7 to 365 days. When the window ends the full-size photos and videos are deleted automatically, and small previews remain so a gallery page still shows what was there. The host is emailed reminders before the date and can download everything from their gallery until then, and the operator's current window is shown on the operator's booking page. If you want your own photos gone sooner, ask.
Your phone number or email address
If you want your photos sent to you, you type in a phone number or an email address. That is the only way either one enters the system: nothing is bought, imported, or guessed. We store it, along with any name you gave, so the photos can be sent and so the same person's sessions can be linked together on one page.
With a phone number we also store the consent record: the exact sentence you were shown, and the moment you agreed to it. That record is what makes it legitimate for the operator to write to you later, and it is what lets you be taken off a list and shown to have been.
We also keep a delivery record for each message — which channel it went by, where it went, whether it arrived, how many attempts it took, what it cost, and any error — so a failed photo can be chased rather than quietly lost.
Your number, your address and your name are kept for 24 months after the last event you attended with that operator, unless the operator sets a different window anywhere between 6 months and 5 years, and are then deleted automatically. The address on the delivery record goes with them. If you replied STOP, the opt-out record stays, for the reason given below.
Survey answers
An operator can set the booth to ask a short question after the photo. A wedding might ask for a message to the couple; a corporate client might ask for a work email or a rating. Answers are stored against your session and against the question, and the operator can export them. If a question asks for something you would rather not give, you do not have to answer it — unless the operator marked it required, in which case skipping it means skipping the survey rather than skipping the photo.
Booking requests
Every photo we send carries a link to the operator's booking page. If you use it, we store the name, email address and any phone number and notes you put in the form, the slot you asked for, and which event and which photo link brought you there — so the operator can see which nights are producing work. That request goes to the operator, not to us.
If you buy something
Guests can buy AI effects, prints and digital extras where the operator has set them up. Payment is taken by Stripe on the operator's own Stripe account. We store what was bought, the amount, our fee, Stripe's reference, and the email address or phone number given for the receipt. Card details go to Stripe directly and never reach us.
If you order a physical print, your shipping name, address, email address and phone number are passed to Printify, who make and ship it. If you buy an AI effect, your photo is sent to the image provider the operator chose. Both are covered below.
We do not do face recognition
There is no face matching anywhere in this product, and no part of it looks at a photo to work out who is in it. We built it, tried it at a Sharing Station, and took it out again: it saved a guest some scrolling, and in exchange it meant doing biometric processing that several states regulate specifically. That was not a trade worth making.
So, plainly: we never scan, measure, template or match a face. There is no selfie step, no faceprint, no match score, and no table in our database for any of it. You find your photos by looking at the wall, by opening the event's gallery, or by getting the link we texted you.
Your pass
At the bottom of your photo page there is a code. If you go back to the booth later the same night, you can hold it up instead of typing your number again, and that photo joins the rest on the same page.
It is a signed link to your record, and nothing else. It carries no name, no number and nothing about your face — the booth reads it and looks you up. The photos go to the contact details you already gave us, never to whoever is holding the phone. If somebody else shows your pass, all they can do is send you your own picture; they cannot see your photos on the booth screen and they cannot redirect them anywhere.
If you have replied STOP, your pass stops working. It does not become a way back onto a list you left.
Text messages
A guest gets a text for one reason: they typed their own number into a booth and tapped send. The message carries a link to their own photos and the words “Reply STOP to opt out”. Frequency is normally one message per photo session, plus any follow-up from the operator whose event they attended.
Reply STOP to any message and three things happen at once: the number is marked opted out, anything already queued for it is stopped before it can go, and it is excluded from every future send. Because the messages come from one shared platform number, a STOP applies across every operator on Letsseeme that number has heard from, not only the one whose event you just left. That is deliberate: someone who says stop means stop.
Reply HELP for help, or START to opt back in. Message and data rates may apply, and carriers are not liable for delayed or undelivered messages.
No mobile information is shared with third parties or affiliates for marketing or promotional purposes. A number is passed only to the carrier that delivers the message. Consent records are never sold, never shared, and never used to build a list beyond the operator the guest gave the number to.
The record of an opt-out is kept indefinitely, on purpose. It is the one piece of data we will not delete on request, because deleting it is the same as forgetting that someone asked not to be contacted — and the next time that number arrived at a booth, or the next time a list was rebuilt, they would be contacted again by accident. The record is minimal: the number, that it opted out, and when. If you would rather that record did not exist at all, tell us, and we will explain what removing it would mean before doing anything.
If you are an operator
We store your account and sign-in details, your organisation, the people you have invited to it, your events, your booths and the devices paired to them, your templates and branding, your prices, your subscription and billing state, and the health reports your iPads send us while an event is running. We use them to run the product and to show you your own numbers.
Your guest list is yours and is scoped to your organisation. No other operator can see it, and we do not use one operator's guests on behalf of another. We do not sell any of it.
The guest list you can export
From an event you can download a CSV of every guest who shared a photo at it. It contains, for each of them: name, phone number, email address, their text consent status, the timestamp of their consent, and when they were first seen. There is a second export for survey answers, which puts each guest's name, phone number and email address next to their answers.
Once that file is on your laptop it is entirely in your hands. We cannot recall it, expire it, or honour a deletion request against it. If a guest asks you to delete their details, the copy in that spreadsheet is yours to deal with.
Campaigns to past guests
On plans that include it, you can send a later email or text to guests from your own past events. The audience is a filter, not a frozen list: it is rebuilt when the campaign is scheduled and the opt-out check runs again on every single recipient at the moment of sending, so somebody who opted out in between is dropped rather than messaged. We keep a record of who was messaged, when, whether it landed, and what it cost.
If you are a host
If you booked the event, the operator holds your name, email address and any phone number on the event, and we send you a link to a gallery of the night and, where it worked, a highlight reel by email. The host gallery deliberately carries no guest contact details — it is photos, nothing else. If you paid for the full-resolution set, we store that order and the email address the receipt went to.
Before the full-size photos and videos expire you are emailed reminders, and your gallery shows the date. Everything can be downloaded from it until then; after that the small previews remain.
Who else touches it
Everything below is a company we pass data to in order to do a specific job. Each gets only what that job needs, and several are only involved at all if the operator switched the relevant feature on.
- Cloudflare — runs the software and stores every photo and video. It also holds short-lived things like booth pairing codes and the counters that stop a public form being hammered.
- Supabase — the database behind all of it, and operator sign-in.
- Twilio — text messages. Gets the phone number and the message; for a picture message, also a link to the photo. STOP replies arrive back through it.
- Resend — email. Gets the address, the subject and the message, which includes a link to the photos.
- Stripe — subscriptions, guest purchases and operator payouts. Card details go to Stripe and only to Stripe.
- fal.ai, Replicate and Google — only when a guest buys an AI effect, and only the one the operator selected. The guest's photo is sent to that provider, along with the text description of the effect, and the new image comes back.
- Printify — only when a guest orders a print. Gets the photo to print, and the shipping name, address, email address and phone number.
- Amazon Web Services — only when a highlight reel is made. The renderer is given time-limited links to the event's photos and produces the video.
These marketing pages themselves load nothing from anyone: no analytics, no fonts, no tag managers, no trackers of any kind.
Links, and how long they work
No photo in our storage is on a public address. Every image is served through a signed link that carries an expiry, and a link that has expired or been altered by a single character is refused. Pages re-sign their own images as they load, so the links you actually click are short-lived: about an hour on a gallery or a photo page, six hours on a screen or a wall that has to run unattended all night, and a week for the picture embedded in an email.
To be straight about the limit of that: the page links themselves — the one texted to a guest, and the host's gallery link — do not currently expire. They are long random values that cannot be guessed, but anyone who is forwarded one can open it. Treat a photo link like the photo. If you need one killed, ask us.
Public event galleries and the in-room slideshow are off unless an operator switches them on for that event, and an event with them off is indistinguishable from one that does not exist.
How long things are kept
- Photos and video: for the operator's retention window, 30 days after the event unless the operator changes it (7 to 365 days). Expiry is automatic: full-size photos and videos are deleted when the window ends, and small previews remain. Deleting the event or closing the account removes them sooner.
- Guest contact details and consent records: for 24 months after the guest's last event unless the operator sets a different window, anywhere between 6 months and 5 years. Deleted automatically after that, along with the address on each delivery record and on any receipt. The opt-out record (the number, that it opted out, and when) is kept, as described above.
- Opt-out records — kept indefinitely, for the reason given above.
- Orders and payments — kept after the photos they relate to are gone, because the money happened and the records have to reconcile.
- Rate-limiting counters — an IP address appears briefly in a counter that stops public forms being flooded, and it ages out on its own within minutes.
Deleting an event removes its records and its photos stop being reachable from anything we serve. Otherwise the stored files come down on the schedule above, automatically, without anyone having to ask; the small previews are the only files that outlast it.
Cookies
Letsseeme sets no cookies anywhere: not on these pages, not on a guest's photo page, not on a host gallery, and not in the operator dashboard. The dashboard keeps your sign-in in your own browser's local storage instead, which never leaves your device except as the token that proves who you are on each request.
Security
Photos are served only through signed, expiring links rather than public addresses. Each booth authenticates with its own device token, stored as a hash and revocable from the dashboard. Every database query is scoped to one organisation in application code, with the database's own row-level rules behind it as a second wall. Incoming webhooks from Stripe and Twilio are signature-checked before anything is acted on.
Making a request
Ask for a copy of what we hold about you, ask for it corrected, or ask for it deleted. Guests should ask the operator whose event they attended first, since it is their decision — but if you cannot work out who that was, give us the event name and the date and we will find them. Operators can ask us directly, through the dashboard or the address on the account.
We will not charge you for a request, we will not make you create an account to make one, and we will tell you if there is something we cannot delete and why — the opt-out record being the main one.
Contact
Questions, corrections, deletions and complaints go to hello@letsseeme.com, or through the dashboard. Post reaches us at Courtright Collective LLC, 202 Acorn Ct, Kingston Springs, TN 37082, United States.
This is a plain-language policy written to describe the product as it is actually built. It is not legal advice and has not been reviewed by a lawyer, and the owner should have one review it before relying on it commercially.
Letsseeme is a product of Courtright Collective LLC. 202 Acorn Ct, Kingston Springs, TN 37082, United States. Questions: hello@letsseeme.com · Contact