Migumento Create album

Privacy notice

What data we process, what for, who else sees it — and what we deliberately don’t do.

Verbindlich ist die deutschsprachige Fassung (de-CH) dieses Dokuments. Diese Übersetzung dient nur dem Verständnis. The German-language version (de-CH) of this document is the binding one. This translation is provided to aid understanding only. Deutsche Fassung

1 · Who is responsible

Responsible for processing your personal data within the meaning of the Swiss Data Protection Act (DSG) is:

Michael Bolliger
Earhart-Strasse 19
8152 Glattpark (Opfikon)
Switzerland
info@migumento.com

We’re a sole proprietorship and have no data protection officer. Every enquiry goes straight to the address above and is answered by the person named there.

2 · What data we process

As a host

As a guest

When something breaks

Technical, on every request

3 · What stays on your device, and the two cookies

Most of what Migumento remembers sits locally on your device and is never sent to a server: the identifier your browser recognises your own uploads by, which albums have new photos since your last visit, your colour and display settings, and uploads still waiting in the queue.

One exception, since ‘Viewed’ came along: which individual photos you’ve opened is sent to the server — see section 2. ‘Which albums are new to me’, by contrast, stays purely local; that’s a different thing and doesn’t leave your device.

Your favourites are on the server too, and deliberately so: for the list to be the same on all your devices, and for you to be able to download exactly those photos, the server has to know which ones they are. Even so, only the person who created it can read it. There’s a copy on your device as well, so that the stars are there from the first moment instead of appearing afterwards.

Two small cookies do travel along with every request, because the server needs them to draw the first page correctly instead of correcting it again straight away:

Both apply to this one event only, contain no identifier for you and serve no analysis. They aren’t tracking cookies, they come from nobody but us, and that’s why there’s no cookie banner here. You get rid of them and everything else by clearing the website data in your browser.

4 · Location data in your photos

A camera writes invisible extra details into every photo — the time, the camera model, and on many phones the coordinates of the place it was taken. We do not remove those details: they are part of the shot, and anyone who downloads their event later should get back exactly the file that was taken — with the real time and everything that belongs to it.

But that also means: anyone who has access to an event and downloads an original can read from it where the photo was taken. If you don’t want that, switch location recording off in your camera app before you take photos. On the website itself no location is ever shown and no map is drawn.

With videos this holds for the original only. The version that plays in the app is one we re-encode ourselves — and in the process the device’s extra details fall away, the coordinates included. So anyone who only watches a video sees no location; anyone who downloads the original does.

5 · Payments

Payment goes through Stripe. Card numbers, TWINT details and everything comparable are collected and processed by Stripe directly — we never see them and we store them nowhere. All that comes back to us is: that a payment succeeded, for what amount, and a reference number.

The provider is Stripe Payments Europe Ltd., Ireland, for European payments, with Stripe, Inc. (USA) as its parent company. Their privacy notice: stripe.com/privacy.

If your billing address is outside Switzerland, Stripe is the merchant of record for the purchase (Link, LLC) and is independently responsible for that payment — it collects your billing details for itself, issues the receipt and needs them for its own tax obligations.

6 · Who else processes the data

As few as possible, and all of them as processors — they may process the data only for us, not for their own purposes.

One exception: with a billing address outside Switzerland, Stripe is not a processor for the payment itself but, as the merchant of record, independently responsible (see section 5).

WhoWhat forWhere
Hetzner Online GmbH The server the application runs on — and the backup copy of the original files, which is not publicly accessible Nuremberg and Falkenstein, Germany
Supabase Inc. Database and storage for photos and videos EU / USA
Stripe Payments Europe Ltd. Payment processing Ireland / USA
Scaleway SAS Sending our emails Paris, France
BunnyWay d.o.o. (bunny.net) Delivering the photos over a content delivery network — for which the photos are cached at edge locations Ljubljana, Slovenia (edge locations in the EU)

Where data reaches the USA in the process, we rely on the European Commission’s standard contractual clauses and the Federal Council’s adequacy decision on the Swiss-U.S. Data Privacy Framework. We don’t sell data and we don’t pass it on to anyone who isn’t listed here — unless the law obliges us to.

7 · What we don’t do

8 · How long we keep things

9 · Your rights

You have the right of access to the data we process about you, the right to have wrong details corrected, to deletion, to being given your data in a common format, and to object to processing. An email to info@migumento.com is enough — we need no form and no reason for it.

If you can be seen in a photo at an event and would rather not be, write to us as well. You need neither the link to the event nor the host’s consent for that.

You can also complain to the Federal Data Protection and Information Commissioner (EDÖB / FDPIC) in Bern.

10 · Security

Everything runs over encrypted connections (TLS) and nothing else. An event is reachable through a long link that can’t be guessed; anyone who doesn’t have it doesn’t get in. Original files are handed out only through short-lived, individually signed links. The Manage link and the guest link are separate — one can be shared without giving the other away.

But that also means: whoever has the link is in. Don’t pass the Manage link on.

We review our code continuously — automated and AI-assisted — and every change goes through a fixed run of tests and checks before it is published. That is care, not a guarantee: absolute security doesn’t exist on the internet, and so we don’t promise it either. What that means for liability is in section 12 of the Terms and Conditions.

11 · Changes

We adapt this notice when something about the product changes. The version published here is the one that applies; the date below says when it was last changed.

Last updated: 26 August 2026