MyMemoryLogSupport

Privacy policy

How MyMemoryLog handles account, order, gallery and QR-visit information.

Updated 4 October 2026

Controller and contact

KOVAK D.O.O., PERUZZIJEVA ULICA 102, 1000 LJUBLJANA, Slovenia, is the controller for the personal data described here. Contact support@mymemorylog.com with privacy questions or requests.

Information used to provide the service

We process account and contact details, authentication information, addresses, order and payment references, gallery ownership, uploaded memories and artwork, and messages you send to support. The information needed to create your account, fulfil an order or operate your gallery is used to perform the relevant contract. Without required details we may be unable to provide that part of the service.

Service and security records can include event times, resource and actor identifiers, authentication identity and IP addresses. Financial records are also used to meet applicable accounting and legal obligations. We use service and security information to investigate problems, protect accounts and handle disputes.

Uploads can contain information about other people and embedded metadata such as photo location data. Consider what you share and remove metadata you do not want viewers to receive before uploading.

Gallery visibility

An unlocked gallery can be viewed by anyone who has its QR or shared link. Galleries are unlisted and set not to be indexed by search engines. This does not prevent someone forwarding a link or saving content. Share only what you are comfortable making available to link holders.

Gallery files use access-checked viewing and download links. A locked gallery's ordinary links do not serve its files. Excess files removed by an upgrade refund are available through a separate owner-only retrieval page. Copies already downloaded are outside our control.

Cookies and QR visits

The website uses cookies for sign-in, cart continuity, caching, language choice, pending registration and resuming Pin activation. These have different lifetimes: up to seven days for sign-in and cart cookies, one day for cache and pending registration, one hour for activation continuation, and 365 days for language preference.

A QR redirect records the visit time, destination, device category, browser and operating-system names, and referring website hostname even when optional visitor recognition is declined. Those redirect records do not contain your IP address or account identity; separate service and security logs may contain them.

Optional repeat-visitor recognition uses a browser identifier only after you choose to allow it. The QR consent preference and, when allowed, visitor identifier cookies last up to 400 days. You can change that choice. Withdrawing consent removes the visitor cookie from that browser; it does not automatically erase earlier server records. Contact us to request erasure where applicable.

The gallery keeps unsaved layout changes in browser session storage until they are saved, discarded or the tab session ends. No uploaded media payload is stored in that draft.

Service providers and advertising

Amazon Web Services S3 is configured to store media in the Frankfurt region, and Amazon SES is configured to deliver account verification and password-reset emails. Order delivery uses Pošta Slovenije. These providers receive the information needed for their respective services.

Where Stripe is used at checkout, it processes payment details and we receive payment references and status. Stripe's own privacy information explains its processing. A payment-method label alone does not mean that every payment method is available.

Google advertising is currently disabled. MyMemoryLog does not load Google advertising scripts or make advertising requests. Any future advertising requires updated disclosures and applicable consent controls; paid galleries remain ad-free.

Storage and requests

We retain gallery information to provide the service. Locked gallery content has a minimum two-year retention commitment from locking, subject to a valid erasure request or other legal requirement. Two years is not an automatic deletion deadline. Earlier QR visit records are not automatically deleted when you change the browser consent preference.

You may request access, correction, erasure, restriction or portability of personal data and object to processing where the relevant conditions apply. You may withdraw consent at any time without affecting prior lawful processing. These requests remain available while a gallery is locked and do not require renewal.

We respond to rights requests without undue delay and normally within one month. If the law permits an extension because of complexity or the number of requests, we explain it within that first month. You may complain to Slovenia's Information Commissioner, Informacijski pooblaščenec.

QR browser recognition

Optionally recognize this browser when opening pin links to count returning browsers. This cookie is separate from your account. Pin links always work without it.

Refusing removes this browser’s ID cookie. It does not delete earlier records. We still record basic redirect metadata without this cookie.

Browser recognition is off in this browser.

Request access to or erasure of earlier records
Privacy policy — MyMemoryLog