Privacy
Privacy policy
Effective July 7, 2026
This policy explains what Rholl collects, why, and the choices you have. Rholl is operated by [Rholl entity name]. It is written to be read; if anything is unclear, write to hello@rholl.app.
1. What we collect
Hosts. When you create an account we store your email address, the name you give us, and an optional profile photo, along with the events you create and the settings you choose for them.
Guests. Guests do not create accounts. When a guest joins an event we store the first name they give, an email address only if they choose to leave one, and a random identifier created for that event and saved in their browser. That identifier ties a guest’s roll to their device within a single event. It is not a tracking profile and is not used to follow anyone across events or across the web.
Photos. We store the photos guests shoot at an event, both the original frames and the developed versions, with basic details such as when a frame was taken and its dimensions.
Payments. Payments are handled by Polar, our merchant of record. Polar collects your payment details; card numbers never touch Rholl. We store references to what was bought, such as an order id and the plan a studio is on.
Technical. Like most services, we receive basic technical information when you use Rholl, such as IP address and browser type, in server logs. When something breaks, our error monitoring records what went wrong along with technical context. We do not build advertising profiles.
2. How we use it
To run the service: develop rolls, open albums, send the emails you asked for, process purchases, and keep each event’s data separate and secure. To respond when you write to us. And to protect the service: we keep short-lived request counters that slow scripted abuse of the guest actions. We do not sell personal information and we do not use your photos or your information for advertising.
3. Who processes it
Rholl runs on a small set of processors, each receiving only what it needs to do its job:
- Supabase, for the database, sign-in, and photo storage
- Vercel, for hosting and serving the site
- Polar, for payments, as merchant of record
- Resend, for transactional email from hello@rholl.app
- Sentry, for error monitoring
Rholl does not run third-party product analytics today. If we ever enable an analytics provider, we will name it here, describe what it sees, and update the cookie section below before it goes live.
4. What we share
We do not sell personal data. We share it only with the processors above, when you ask us to, or when the law requires it. Albums are shared by their hosts: anyone with an event’s album link can see the developed album once it opens, which is how the product is meant to work. Hosts decide who receives that link.
5. Retention
Events and photos stay in your account until you delete them or delete your account. Deleting your account removes your events, the photos in them, and your profile. Guest names, emails, and device identifiers live with the event they belong to and are removed with it. Abuse counters expire on their own within days. Error and email delivery records expire on their providers’ standard schedules, and copies in encrypted backups clear on a short delay after deletion.
6. Your rights and choices
Hosts can download a copy of their account data and delete their account, both from settings. Deletion is permanent. Guests can unsubscribe from album emails with one click in any of those emails, and any photo in an album can be reported from the album itself.
Wherever you live, you can also write to hello@rholl.app to ask what we hold about you, to correct it, or to have it deleted. If your home gives you formal privacy rights, for example in the EEA, the UK, or California, these are the mechanisms through which we honor access, portability, correction, and erasure requests.
7. Children
Rholl accounts are for adults, and the service is not directed to children under 13. We do not knowingly collect personal information from children online. Children may appear in photos taken at an event, as they do in any wedding album; hosts decide what their album holds, and we remove content on request at hello@rholl.app.
8. Cookies
Rholl uses only the cookies it needs to work: session cookies that keep hosts signed in and one that remembers which workspace a host is managing. There are no advertising cookies and no analytics cookies today; if that changes, this policy will say so first. A guest’s device also holds the per-event identifier described above, stored in the browser.
9. Where data lives
Our processors store data in the United States. If you use Rholl from somewhere else, your information is transferred to and processed in the United States, and this policy applies to it wherever it is processed.
10. Changes
We will update this policy as Rholl changes, and the effective date above will move when we do. If a change meaningfully reduces your rights, we will tell hosts by email before it takes effect.
11. Contact
hello@rholl.app reaches a person. The terms of service live at rholl.app/legal/terms.