Privacy policy

Last updated: 9 September 2026

1. Who we are

Quick Pigeon Limited ("we", "us") is the data controller for the personal data described in this notice. We are a company registered in England and Wales (company no. 17300164), registered office 1 Hosta Close, Liverpool, England, L33 1SR. You can contact us at hello@viralvenue.media. Our data protection contact is hello@viralvenue.media. We are not required to appoint a Data Protection Officer, but any privacy query sent to that address will be handled by the person responsible for data protection.

2. What personal data we collect

  • Account & authentication data — email, password (managed by AWS Cognito; never visible to us), sign-in timestamps and IP address.
  • Venue data — venue name, branding preferences, and settings you configure in your portal.
  • Guest-submitted photos — images uploaded by venue guests via the capture flow, stored on AWS S3.
  • Guest consent records— the guest's confirmation that they are 18 or over, their consent to display (and, where given, to Instagram publishing), the time of submission, and any name or Instagram handle the guest chooses to provide for a credit.
  • Billing data — subscription plan, invoice history and payment status. Card details are entered directly with Stripe and are never stored by us.
  • Marketing preferences — email address and consent record if you sign up for our mailing list.
  • Technical & usage data — device, browser, and cookie data (see our cookie policy).

3. How and why we use it (lawful basis)

PurposeLawful basis (UK GDPR Art. 6)
Create and secure your accountContract
Provide the venue portal and display featuresContract
Moderate and display guest photosContract / Legitimate interests
Publish a guest photo to the venue's InstagramConsent (given by the guest at upload)
Take payment and manage your subscriptionContract
Improve the service via usage analyticsConsent
Send marketing emailsConsent
Comply with legal and accounting obligationsLegal obligation

Where we rely on legitimate interests, our interest is in running a safe, well-moderated service for venues and their guests. Where we rely on consent, you (or the guest) can withdraw it at any time — see section 8.

4. Cookies

We use cookies and similar technologies. See our cookie policy for the full list and how to change your choices.

5. Who we share it with

We share personal data only with processors and partners who act on our instructions:

  • Amazon Web Services (AWS) — hosting, authentication (Cognito), database (DynamoDB), file storage (S3), transactional email (SES) and, on the Premium plan, automated photo moderation (Bedrock). Region: London (eu-west-2). Guest photos are stored in the UK.
  • Stripe— payment processing and subscription billing. Stripe is an independent controller of the card details you enter at checkout; see Stripe's own privacy notice.
  • Meta Platforms (Instagram)— only where a guest has consented to Instagram publishing, the approved image is sent to Meta so it can be posted to the venue's own Instagram account. Once published, the post is governed by Instagram's terms and privacy policy.

We do not sell your personal data.

6. International transfers

Where data is processed outside the UK, we rely on appropriate safeguards (UK adequacy regulations and/or the International Data Transfer Agreement / UK Addendum to the SCCs). Our systems and guest photos are hosted in the AWS London region (eu-west-2). On the Premium plan, automated moderation may run in AWS regions within the EU, which the UK adequacy regulations cover. The only other routine transfer outside the UK is to Meta when a guest has consented to Instagram publishing; that transfer relies on the UK International Data Transfer Agreement and the UK adequacy regulations, as applicable.

7. How long we keep it

  • Account data — for the life of your account and up to 90 days after closure, after which it is deleted.
  • Guest photos — 180 days after submission on the Basic plan, or 365 days on the Premium plan, unless the venue or the guest deletes the photo sooner.
  • Guest consent records — for as long as the related photo is held, plus a further 12 months so we can evidence consent if a complaint is made. Billing and invoice records — 6 years, as required by UK tax and accounting law.

8. Your rights

Under UK GDPR you have the right to: access, rectification, erasure, restriction, data portability, object to processing, and to withdraw consent at any time (without affecting prior processing). To exercise any right, contact hello@viralvenue.media.

9. Complaints

You can complain to the Information Commissioner's Office (ICO) at ico.org.uk, helpline 0303 123 1113. We would appreciate the chance to resolve concerns first via hello@viralvenue.media.

10. Changes to this notice

We may update this notice; material changes will be notified via email to your account address and a notice in the venue portal. The "Last updated" date above always reflects the current version.