Privacy Policy

    Last update: 5 June 2026

    Effective Date: 5 June 2026

    GOShare (“we”, “us”, or “our”) operated by GOSHCo values your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, share and protect data when you use our services.

    Please take a moment to read our Privacy Policy, as well as our Terms of Service. If you have any questions or concerns, feel free to email us at hello@goshco.in. If you do not agree with this Policy do not access or use our Services.

    Key points of this policy

    • We do our best to keep your data safe and secure.
    • We do not sell your photos, videos, or personal information. We only disclose information when necessary to provide the Services, comply with legal obligations, protect our rights, or with your consent.
    • We are not responsible for any media or personally identifiable content that you upload to your event portal. It is your responsibility to ensure that all media uploaded to your digital wall or shared album is lawful, appropriate, and does not infringe the rights of any third party.

    Content Ownership

    You retain ownership of all photos, videos, and other content you upload to GOShare.

    By uploading content, you grant GOShare a limited, non-exclusive license to store, process, display, transmit, and reproduce the content solely to provide the Services.

    This license ends when the content is deleted, except where retention is required by law.

    1. Definitions

    Services means our platform features, including event tools such as live gallery walls, upload portals, moderation tools, and shareable media albums.

    Website refers to the websites, applications, and services operated by GOSHCo under the GOShare brand.

    Personal Data means any information about you as a person (e.g. name, email, uploaded media, event details).

    Data refers to any information collected from users, including usage and device data.

    Processing means any operation performed on personal data (e.g. collecting, storing).

    Controller means GOSHCo, which decides how and why your data is processed.

    Processor means a third party that processes data on our behalf.

    GDPR refers to the General Data Protection Regulation (EU).

    CCPA refers to the California Consumer Privacy Act.

    Australian Privacy Act means the Privacy Act 1988 (AU).

    2. What Data We Collect

    We collect information required and processed by us, as the controller. These details are adequate, limited, and necessary for our Services.

    Event organizers may create accounts, while guests can upload media without creating an account if the event organizer provides access through a link, QR code, gallery, or shared album.

    Personal Data (provided by you)

    • Name
    • Email address
    • Uploaded content (e.g. images, videos)
    • Other information you choose to provide when using our services, such as messages, preferences, or event form inputs.

    Device and Usage Data (collected automatically)

    • IP address
    • Browser and device info
    • Media metadata, including file type and upload timestamps
    • Language and location data
    • Pages visited and actions taken

    3. Legal Basis for Processing

    We process personal data only where we have a valid legal basis for doing so, including:

    • Performance of a contract – to provide the Services you request and to fulfill our Terms of Service.
    • User consent – when you agree to receive emails, use upload links, or otherwise opt in to service features.
    • Compliance with legal obligations – to meet law enforcement, tax, or other regulatory requirements.
    • Legitimate interests – to improve the Service, secure our systems, and protect against fraud or abuse in a manner that does not override your rights.

    4. How We Use Your Data

    We use personal data to:

    • Provide and operate the Services.
    • Create and manage event galleries and albums.
    • Enable media uploads and sharing.
    • Process payments and subscriptions.
    • Send transactional notifications and support communications.
    • Improve platform performance and user experience.
    • Detect, prevent, and investigate abuse, fraud, and security incidents.
    • Comply with legal obligations.

    5. Subprocessors We Use

    To operate GOShare, we use subprocessors that may process some of your data. We only share data with these trusted services for the specific purposes they support, and we do not use them for unrelated marketing or profiling.

    We may update our subprocessors from time to time as our infrastructure and service providers evolve.

    • Cloudflare R2 – Used for storing uploaded media files and serving them via a CDN-backed public URL. This includes images, videos, and any media assets uploaded through the app.
    • Resend – Used to send transactional email notifications, invitations, and other application-related messages.
    • Razorpay – Used for processing payments and verifying subscription purchases when upgrading event plans.
    • Neon – Used to store application data including user accounts, events, media metadata, and configuration data.
    • Google Firebase – Used for storing support inquiries, contact forms, and client feedback submissions via Cloud Firestore (Google Cloud Platform).
    • Google Analytics (GA4) – Used to collect anonymized usage metrics, page views, and traffic sources to optimize platform performance and usability.
    • Vercel Analytics – Used for monitoring site speed, web vitals, and error tracking in a cookieless format.

    6. Children's Privacy

    GOShare is intended for individuals who have reached the age of majority in their jurisdiction. We do not market to, or knowingly collect data from, children under 13.

    7. How We Protect and Store Your Data

    GOShare stores application data using industry-standard services and safeguards:

    • Uploaded media files are stored in Cloudflare R2 and served through a CDN-backed public URL. Media may be accessible to individuals who possess the relevant event link, gallery link, QR code, shared album link, or access credentials provided by the event organizer.
    • The event organizer is responsible for determining who receives access links, QR codes, gallery URLs, or other credentials used to access event content.
    • User accounts, event records, media metadata, and related configuration data are stored in a PostgreSQL database accessed through Prisma.
    • Transactional emails are sent through Resend and do not store private data beyond what is required to deliver the message.
    • Contact and inquiry form submissions (such as name, email, phone, and message) are stored securely in Google Firestore (Firebase) database.

    We protect your data with secure transmission and access controls. Sensitive information is handled on the server side, and environment variables are used to keep service credentials private. Where available, we use encrypted connections between the application and our subprocessors.

    In the event of a security incident or data breach, GOShare investigates promptly, takes steps to mitigate impact, and notifies affected parties and regulators as required by law.

    8. Your Rights and Procedures

    You have the right to:

    • Access your Personal Data at any time.
    • Edit your account details, ensuring your Personal Data is up to date.
    • Request deletion of your Personal Data held by us, subject to legal, contractual, and operational retention requirements.
    • Request restrictions to your Personal Data processing.
    • Request a portable copy of your Personal Data in a commonly used, machine-readable format.

    Deletion requests may be submitted to hello@goshco.in and will be processed within a reasonable timeframe.

    Report any infringements to our policy and procedures by emailing hello@goshco.in. We will respond to your request promptly and handle your inquiry in accordance with applicable law.

    9. Cookies and Similar Technologies

    We may use cookies, local storage, and similar technologies to support:

    • User sessions.
    • Preferences.
    • Website functionality.
    • Analytics and performance.
    • Security and abuse prevention.

    You can manage cookies through your browser settings.

    10. Additional Rights

    10.1 GDPR Rights (EU Users)

    • Restrict Processing – Limit how we process your data.
    • Withdraw Consent – Withdraw consent for consent-based processing.
    • Lodge Complaints – File complaints with supervisory authorities.

    10.2 CCPA Rights (California Users)

    • Know - What personal information we collect and how it is used.
    • Delete - Request deletion of personal information.
    • Opt-Out - Opt out of sale of personal information (we do not sell personal information).
    • Non-Discrimination - Not be discriminated against for exercising these rights.

    10.3 Australian Privacy Rights

    • Access and Correction – Request access and correction of your personal information.
    • Complaints – Lodge complaints about privacy breaches with the Office of the Australian Information Commissioner (OAIC).
    • Marketing Opt-Out – Opt out of direct marketing communications.
    • Breach Notification – Be notified of eligible data breaches that may cause serious harm.

    10.4 India — DPDP Act 2023 Rights

    • Right to Access – Request a summary of personal data being processed, information about the processing activities, and identities of other controllers/processors with whom the data has been shared.
    • Right to Correction – Request correction, completion, or updating of your personal data.
    • Right to Erasure – Request deletion of personal data that is no longer necessary for the purpose for which it was collected.
    • Right to Grievance Redressal – Access a transparent and effective mechanism for resolving complaints or concerns regarding our processing of your personal data.
    • Right to Nominate – Nominate another individual to exercise your data protection rights in the event of your death or incapacity.

    11. Marketing Communications

    You can opt out of marketing communications by unsubscribing from our email list or contacting us at hello@goshco.in.

    12. International Data Transfers

    Your information may be processed in countries other than your residence. We use appropriate safeguards, contractual protections, and legally required transfer mechanisms to protect personal data when it is processed outside your country.

    13. Data Retention

    We retain your data according to your purchased plan and usage. If your plan expires or becomes inactive, we will notify you via email at least 30 days before deleting your data. This gives you the opportunity to renew or back up your content.

    We also retain records for as long as required to comply with legal obligations and to process disputes or support requests.

    14. Changes to this Policy

    We may update this Privacy Policy occasionally. If we make significant changes, we will notify you via email or on the website.

    15. Contact Us

    For any questions or concerns, contact us at:

    GOSHCo
    Chennai, Tamil Nadu, India - 603202
    Email: hello@goshco.in
    Website: https://share.goshco.in