ToastWall
Privacy Policy
Last updated: September 4, 2026
This Privacy Policy explains what ToastWall (“we”, “us”) collects, why we collect it, how long we keep it, and who processes it on our behalf. By using toastwall.com, you acknowledge this policy. For contract terms, see our Terms of Service.
1. Age requirement (COPPA)
The Service is intended for users 13 years of age and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us data, contact privacy@toastwall.com and we will delete it.
2. What we collect
- Google account: Google account identifiers and email when you Sign in with Google. Hosts use this to manage events. Guests use the same Google identity only for album Download and Visited Albums / History. Join, upload, like, and Contribute stay Event Code based and do not require Google. Hosts who export to Google Photos also grant an extra Photos permission (see section 5). Legacy events may still have an old organizer password hash until claimed; we do not store plaintext passwords.
- Event data: event title, URL slug, theme, settings, and Event Code (used for private guest and venue access; not marketed as a “token” to users).
- Guest data: optional nickname; device cookies that identify this phone for one event; Event Code access cookies; an anonymous like cookie used for album likes; and Visited Albums / History rows when you are signed in and view or download from an album.
- Uploads: photos, videos, and text guests submit, plus related metadata (time, toast prompt, file type/size). We may read capture-time metadata to order the album. We do not productize location EXIF.
- Downloads: guest album Download serves a privacy-scrubbed high-res file (GPS and other identifying EXIF stripped). Host ZIP / Download all keeps full originals for the host archive.
- Payments: when checkout is enabled, Stripe processes card data on their hosted checkout. We receive payment status, Checkout Session / PaymentIntent ids, and related metadata, not full card numbers. If a Stripe promotion code reduces the total to $0, Stripe does not collect a card for that checkout.
- Technical logs: basic request and error logs needed to operate and secure the Service (IP address, user agent, and similar diagnostics may be processed by our hosting provider).
We do not require email signup for guests. Help form submissions go to our support inbox. If you leave an interest note when create access is invite-only, we collect the email you enter so we can reply.
3. Why we collect it
- Operate the event screen, album, moderation, and guest flows
- Keep events private via Event Codes on public links
- Let hosts manage events, download album ZIPs, and (when Export is available on Media) copy selected photos into their Google Photos
- Let signed-in users download album items and use Visited Albums / History
- Operate anonymous album likes
- Process pay-to-open checkout (and Stripe promotion codes when issued)
- Respond to Help and interest notes
- Prevent abuse, debug issues, and improve Early Access
- Comply with law and respond to deletion or DMCA requests
4. Retention after Event over
After a host marks Event over, we keep event media and the album for up to 30 days. Hosts should download the album ZIP in that window. A prepared ZIP file is kept about 14 days (ZIP expiry does not by itself remove the live album during the album window). We do not promise long-term archival. When retention enforcement is enabled, media may be purged after the window. Events still in progress are not auto-deleted solely for that reason. Early Access may gently extend availability until purge is enforced. That is not a forever-storage promise. Cookie identifiers expire on the schedules described in our product (typically days, not years).
5. Google Photos export (hosts)
After Event over, a host can pick photos on Media and send them to Google Photos. We create or reuse an album titled ToastWall - your event name on that host’s Google account. Guests cannot export. ZIP download is separate and still the full-original archive.
What we access. Sign-in uses your Google account id and email. Export asks Google for one extra permission: create albums our app owns and add photos to them (Photos Library append-only). We do not ask to browse the rest of your library, and we do not delete items in Google Photos.
How we use it. Only to create or reuse that album and upload the photos you selected. Uploads are privacy-scrubbed JPEGs (GPS and other identifying EXIF stripped), the same stripping we do for guest Download. We do not use this data for ads, lending, or anything besides that export.
Who it is shared with. The files go to Google as content in the host’s Photos account, under the host license in our Terms. Event media already lives with our processors (Cloudflare). Stripe is not part of export. We do not sell this data, give it to advertisers or data brokers, or send it to other companies to train their AI.
How we protect it. The site is served over HTTPS. If we store a Google refresh token so you do not have to approve export every time, it is encrypted on the host record. We keep the album id we created so later exports can add to the same album.
How long it lasts. Photos on ToastWall follow the Event over window in section 4. Copies that already landed in Google Photos stay there until the host deletes them in Google. Purging ToastWall media does not delete those copies. To drop our Photos access, disconnect ToastWall in your Google account and email privacy@toastwall.com.
Raw or derived user data we receive from Google Photos APIs is used only to provide this export. We do not use it to develop, improve, or train AI or ML models. That use follows the Google User Data Policy, including the Limited Use requirements.
6. Sharing and third-party processors
We use infrastructure processors to host the app and store media. Current categories include:
- Cloudflare: application hosting (Workers), database (D1), and object storage (R2) for media files
- Google: authentication (Sign in with Google) for hosts and for album Download / Visited Albums; Photos Library (append-only) when a host exports, as described in section 5
- Stripe: payment processor for hosted card checkout for pay-to-open (and $0 completion when a free promotion code applies)
Processors act on our instructions to provide the Service. We do not sell personal information. We may disclose data if required by law or to protect the Service and users.
7. Cookies and similar technologies
We use essential cookies: host session (Google, also used for album Download and Visited Albums), guest identity for an event, Event Code access so private links keep working after the first open, and an anonymous like cookie for album likes. These are not advertising cookies. Blocking cookies may prevent joining an event or liking album items.
8. Your choices (GDPR / CCPA)
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, and to opt out of certain processing. Guests can delete their own uploads in-product where available. Anyone can request deletion by emailing privacy@toastwall.com with a link to the content or enough detail to locate it. We aim to complete deletion requests within 30 days. California residents may also contact us to exercise CCPA rights; we do not sell personal information as defined by CCPA.
9. Consent
Hosts accept our Terms when creating an event. Guests consent when they add their name: they are 13 or older; uploads may appear on the screen and album; and the host of that event may keep and use those uploads to show and promote the event, as described in the Terms. That consent is stored once for the guest, not on every upload.
10. Security
We use ordinary web safeguards for Early Access: HTTPS, Google host auth, hashed legacy passwords where still present, Event Codes on public links. Photos export tokens are encrypted at rest as described in section 5. No method of transmission or storage is 100% secure.
11. International transfers
The Service is hosted on global cloud infrastructure. If you access it from outside the United States, your data may be processed in the United States or other countries where our processors operate.
12. Changes
We may update this policy. The “Last updated” date will change when we do. Continued use after updates means you acknowledge the revised policy.
13. Contact
Privacy and deletion requests: privacy@toastwall.com.