Privacy Policy

Effective date: July 25, 2026 · Last updated: August 18, 2026

This Privacy Policy explains how Brooklyn RoJo Technology Consulting (“Crowd Archive,” “we,” “us,” or “our”) collects, uses, and shares information when you use the Crowd Archive website at crowdarchive.com, the Crowd Archive web app at app.crowdarchive.com, and the Crowd Archive iOS app (together, the “Service”).

1. The short version

Crowd Archive helps event owners collect photos and videos from the people who attended their events. When you contribute media, the files themselves travel from your device into a Google Drive folder that the event owner controls. We do not run a separate media store that keeps copies of your photos and videos; the content lives in the owner’s Drive. What we do keep on our own servers is information about that content (a “manifest”) and the account information needed to run the Service. This policy covers all of it.

2. Information we collect

a) Information you give us directly

WhatWhen
Name, email, phone number, and Instagram handleWhen you submit the contact / early-access form on our website. (This form is delivered through Google Forms.)
Name, email, phone number, mailing address, Instagram handle, company name, and websiteWhen you apply to our reseller (“For the Pros”) program. These details are stored on our servers and used only to review and manage your application.
Your email address and any details you provideWhen you email us, request access, or request more contributor capacity.

b) Information from signing in with Google

The Service uses Google Sign-In. When you sign in, Google provides us with your email address and a unique Google account identifier. What else we ask for depends on how you use the Service:

You approve every Google permission on Google’s consent screen and can revoke access at any time in your Google Account settings.

c) Information about the media you contribute (“manifest” data)

When you scan your device and choose media to contribute, and when an owner’s archive is built, we store records describing that activity on our servers (Google Firebase / Google Cloud). These records can include:

CategoryExamples
Media metadataFile name, capture date and time, media type, pixel dimensions, and (where present in the photo) GPS latitude/longitude and altitude, plus the computed distance from the event venue.
AttributionThe contributor’s email address, recorded with each contributed file (also written into the Google Drive file’s description as “Contributed by [email] via Crowd Archive”).
Event & archive infoEvent names, venues, dates, coordinates, invite codes, the owner’s email, and Google Drive folder identifiers.
Account & billingYour subscription tier, seat count, status, and the identifiers assigned by our payment processor (Square). We never receive or store your full card number.
Usage / diagnosticsBasic events such as sign-in, scan-complete, and upload-complete, tied to your email; a short device/browser description; and app version.
Location note. The matching feature relies on the location and time information already embedded in your photos by your own camera — not on live tracking of your device. The Service does not follow your real-time location.

d) The photos and videos themselves

The media files you choose to contribute are uploaded from your device to the event owner’s Google Drive. Once there, the event owner controls that Drive folder and its contents. The owner — not Crowd Archive — decides how that media is stored, used, shared, and retained within their Drive. See Section 6.

e) The optional Google Photos gallery (for owners)

Owners can turn on a mirrored gallery when creating an archive. With the owner's explicit consent on Google's screen, the Service uploads the archive's contributed event photos into the owner's own Google Photos library and creates one album per event to hold them. The permissions we request allow the Service only to add photos and albums, and to organize the albums it created — placing photos in time order and writing a caption that credits the contributor (their chosen name or social handles, never their email) and names the event. The Service cannot see, change, share, or delete anything else in the owner's Google Photos library, and it has no sharing controls — sharing an album is always the owner's own action inside Google Photos. To keep the gallery working while the owner is offline, the owner's Photos authorization credential is stored on our servers in the same encrypted vault as the Drive credential, and the connection can be revoked at any time from the owner's Google Account security settings.

Google user data — Limited Use. Crowd Archive's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the archive and gallery features described here; we do not sell it, we do not use it for advertising, and no human reads it except with your consent, for security, or where the law requires.

3. How we use information

We use the information above to: operate the matching, contribution, and archive features; associate your contributions with the right archive and credit them to you; enforce plan limits and process subscriptions through Square; send service notices (such as billing and application decisions — payment receipts come from Square); respond to you; keep the Service secure and working; maintain backups; and understand overall usage so we can improve. We do not sell your personal information.

4. How information is shared

WhoWhy
Event ownersMedia you contribute goes into the owner’s Google Drive, credited to your email. Owners can see who contributed and manage their archive.
Google (Sign-In, Drive, Cloud, Firebase, Places)Authentication, media storage in your/owner Drives, our database and hosting, our service email, and venue search. Google’s handling is governed by Google’s privacy policy.
SquarePayment processing for subscriptions and the reseller program. Square handles your card details directly under Square’s privacy policy.
NetlifyHosting of our websites.
Legal / safetyIf required by law, or to protect the rights, safety, and security of our users or the Service.

5. Data retention & backups

We keep manifest and account information for as long as your account or the relevant archive is active, and as needed to run the Service, resolve disputes, and meet legal obligations. We take a nightly backup of our database to Google Cloud Storage; backup copies may persist for a period after data is changed or deleted. The media files live in Google Drive and are retained according to the owner’s choices and Google’s policies.

6. Your choices and rights

7. Children

The Service is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it. (Owners collecting media at events with minors are responsible for obtaining any consents their own use requires.)

8. Security

We use reputable infrastructure providers (Google Cloud/Firebase, Square, Netlify) and transmit data over encrypted connections (HTTPS). Sensitive credentials — like an owner’s Drive connection — are stored encrypted, in server-only storage that applications and other users cannot read. No system is perfectly secure; if we become aware of a breach affecting your information, we will notify you as required by law.

9. International users

We operate in the United States, and information is processed there and by our providers. By using the Service you understand your information may be processed in the U.S. and other countries.

10. Changes to this policy

We may update this policy. We will post the new version here and update the “Last updated” date; material changes will be communicated as required by law.

11. Contact

Questions? Email hello@crowdarchive.comBrooklyn RoJo Technology Consulting, 355 7th Avenue, 2, Brooklyn, NY 11215.