Privacy policy

Last updated: 15 August 2026

Your photos are yours. Images you upload are used only to create your compliant photo. Uploads are deleted within 7 days, and the finished photo you purchased is kept for up to 30 days so you can download it again, then deleted. We do not sell your data, we do not use your photos to train any model, and we do not run facial recognition on you. How we handle the measurements taken from your face is set out separately in our biometric data policy.

1. Who is responsible

The controller under the General Data Protection Regulation, and the business responsible under US state privacy laws, is:

Sven Perlberg, trading as OnePassPhoto
Lydia-Rabinowitsch-Straße 8
10557 Berlin, Germany
Email: help@onepassphoto.com

We are a one-person business and are not required to appoint a data protection officer. Your email reaches the owner directly.

2. What we process and why

  • The photo you upload, to create and check your passport photo. Legal basis: performance of our contract with you, Art. 6(1)(b) GDPR. For the free check, taking steps at your request before entering a contract, Art. 6(1)(b) GDPR.
  • Measurements taken from your face, to place your head correctly and check the official rules. These are computed while your photo is processed and are not stored. Legal basis: Art. 6(1)(b) GDPR, and your explicit consent, Art. 9(2)(a) GDPR, to the extent this is treated as a special category of data. Details in the biometric data policy.
  • Order and payment data such as your name, email address and payment confirmation, to process your purchase, send your receipt and meet accounting and tax duties. Legal basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR.
  • Delivery address, only if you order printed photos. Legal basis: Art. 6(1)(b) GDPR.
  • Technical data such as IP address, browser and device type, to run the site securely and defend it against abuse. Legal basis: our legitimate interest in a working, secure service, Art. 6(1)(f) GDPR.
  • Usage statistics. If you allow analytics cookies we measure your visit with cookies and a device identifier. Legal basis: your consent, Art. 6(1)(a) GDPR, which you can withdraw at any time. If you do not, Google Analytics receives only a cookieless page-view signal with no identifier that could recognise you again. Legal basis: Art. 6(1)(f) GDPR.
  • Support correspondence, if you write to us, to answer you. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.

We do not use your data for advertising, we do not profile you, and we do not build a customer profile across visits.

3. Automated checking, and the human in the loop

Your photo is checked automatically against the official rules, and the software decides whether it can pass. If it cannot, you are told why and asked to retake it. This decision affects only whether we can sell you a photo, and you can always upload a different photo or write to us and ask a person to look. If you would like a human review of an automated rejection, email us and you will get one.

If you order prints, a person looks at the finished print file before it goes to the printer, so that a faulty print is never produced. That is the only routine case where a human sees your image. Otherwise nobody views your photo unless you contact us for support.

4. Your photos and the measurements from them

Processing runs on our own server in Germany. Your photo is not sent to any external image service, and no per-photo third-party API sees it. The measurements taken from your face exist in memory during processing and are not written to disk, not stored in your order and not shared with anyone. We do not build a faceprint and we do not attempt to identify you. The full detail, including the retention schedule and how we destroy data, is in the biometric data policy.

5. How long we keep things

  • Facial measurements: not retained.
  • Uploaded photo: deleted automatically within 7 days.
  • Purchased photo: deleted automatically within 30 days.
  • Order and invoice records: kept for as long as German commercial and tax law requires, which is up to 10 years for invoices and 6 years for commercial correspondence.
  • Support emails: kept while the matter is open and then for as long as needed to handle a follow-up question, normally under 2 years.
  • Consent records for cookies and for the biometric notice: kept as long as the consent is current and then for as long as we may need to prove it was given.

If you are refunded, your download is revoked and the file is dropped into the deletion sweep, so a refund shortens retention rather than extending it.

6. Who else processes your data

Each provider below acts on our instructions only, for the purpose named, under a data processing agreement:

  • Hetzner Online GmbH, Germany. Hosts the engine that processes your upload and stores your order. Data stays in the EU.
  • Cloudflare, USA and global network. Serves this website and protects it from attack. Receives request data such as your IP address.
  • Stripe, USA and Ireland. Processes your payment, and receives your payment details, billing address, delivery address and email address. Stripe is our only payment processor, and whichever method you pick at checkout runs through it. We never see or store your full card number.
  • Prodigi, United Kingdom, only if you order prints. Receives your name, delivery address, the print file and your email address if you gave one.
  • Brevo, France. Sends your receipt and download link, and receives your email address and the order details in the message.
  • Google, USA and Ireland. Provides Google Analytics. With your consent it measures your visit with cookies. Without it, it receives only a cookieless page-view signal.

Internal order alerts go to a mailbox belonging to the owner of the business. That is us reading our own mail rather than a disclosure to a third party.

We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we have never done either.

7. Transfers outside the EU

Hetzner processes in Germany, and Brevo in France, so no transfer arises there. Prodigi is in the United Kingdom, which the European Commission has found to provide an adequate level of protection, so no further safeguard is needed. Cloudflare, Stripe and Google may process in the United States. For those transfers we rely on the EU Standard Contractual Clauses together with the EU-US Data Privacy Framework where the recipient is certified under it. You can ask us for a copy of the safeguards by email.

8. Cookies and analytics

Cookies needed to run the site and your checkout are always active. Beyond those, we use Google Analytics, and its cookies are set only after you allow them in the consent banner. Until you do, Google Analytics runs in consent-denied mode: it reports a page view without setting a cookie and without an identifier that could recognise you on a later visit. The advertising signals in Google Consent Mode stay switched off whatever you choose, ad identifiers are stripped, and we use no advertising cookies and no cross-site tracking. You can change or withdraw your choice at any time through the cookie preferences on this site. The full list is on our cookie policy page.

9. Security

Traffic to the site and to the processing server is encrypted in transit. Access to the server is restricted to the owner. Download links are tied to a per-order token rather than a guessable file name, and they stop working when the retention period ends or when an order is refunded. If a breach ever puts your rights at risk, we will notify the competent supervisory authority within 72 hours and tell you directly where the law requires it.

10. Your rights if you live in the United States

We sell one product, the US passport photo, so this is the section that applies to almost everyone reading this page. Depending on your state you may have the right to know what personal information we hold about you, to get a copy of it, to have it corrected or deleted, to opt out of its sale or of targeted advertising, and to appeal if we turn a request down. We give every US customer all of these rights, whether or not your state's law obliges us to and whether or not we meet the thresholds that would make that law apply to us.

  • We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We honour Global Privacy Control signals in any case.
  • Sensitive personal information. The photo of your face and the measurements from it are sensitive. We use them only to deliver the photo you asked for, which is a purpose for which no right to limit use applies, and we never use them to infer anything about you.
  • Biometric data. See the biometric data policy, which is our published policy under Illinois law and covers Texas, Colorado and Washington as well.
  • How to ask. Email help@onepassphoto.com. We verify a request by checking that it comes from the email address on the order, and by asking for the order number. We answer within 45 days. If we refuse, we say why, and you may reply to appeal, which a person reviews.
  • Authorised agents may submit a request on your behalf with written proof that you authorised them.
  • No retaliation. Exercising a right never changes the price you pay or the service you get.

11. Why European law is in this policy at all

We only sell US passport photos and almost all of our customers are American, so it is fair to ask why the GDPR keeps appearing here. The reason is that European data protection law follows the business rather than the customer. We are a one-person business registered in Berlin, and your photo is processed on a server in Germany, so the GDPR covers that processing no matter where you live or which country's passport you are applying for.

This works in your favour. It means the protections below apply to you as an American customer just as they would to someone in Europe, including the deletion deadlines, the ban on selling your data and the limits on who we may pass it to.

12. Your rights under the GDPR

Whoever you are and wherever you live, you have the right to access your data, to have it corrected, to have it deleted, to have processing restricted, to receive it in a portable format, and to object to processing based on our legitimate interests. Where processing rests on consent, you may withdraw that consent at any time, and withdrawal does not affect what was lawful before it. To exercise any right, email help@onepassphoto.com. We answer within one month and we do not charge for it.

You may also complain to a data protection authority. Ours is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin.

13. Children

Passport photos are often of babies and children, and a parent or guardian uploads them. That is expected and allowed, and the child's data is protected by everything in this policy. Our service is not directed at children and we do not knowingly allow anyone under 13 to buy from us or to give us their own data directly. If you believe a child has contracted with us without a parent, write to us and we will delete the account and the data.

14. Do we have to collect this

You do not have to give us anything. Without a photo we cannot check or produce a passport photo, and without an email address we cannot send you your download or your receipt. There is no other consequence.

15. Changes

We update this policy as the service changes, and the date at the top always tells you the current version. If a change materially affects how we handle your photos, we will say so plainly on this page rather than editing it quietly. Questions go to help@onepassphoto.com.