Privacy Policy




PRIVACY NOTICE

Effective Date: July 14, 2021

Last Updated: August 4, 2026

When you visit our website https://memzo.ai (the "Website"), use our mobile application (the "App"), and more generally, use any of our services (the "Services", which include the Website and App), we appreciate that you are trusting us with your personal information. We take your privacy very seriously.

In this privacy notice, we seek to explain to you in the clearest way possible what information we collect, how we use it, and what rights you have in relation to it. We hope you take some time to read through it carefully, as it is important. If there are any terms in this privacy notice that you do not agree with, please discontinue use of our Services immediately.

This privacy notice applies to all information collected through our Services (which, as described above, includes our Website and App), as well as any related services, sales, marketing, or events.

TABLE OF CONTENTS

  1. RELATIONSHIP & ROLES IN OUR SAAS ECOSYSTEM
  2. WHAT INFORMATION DO WE COLLECT?
  3. HOW DO WE USE YOUR INFORMATION?
  4. THIRD-PARTY SUB-PROCESSORS & SERVICE PROVIDERS
  5. COOKIES, TRACKING & SESSION ANALYTICS
  6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
  7. WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?
  8. HOW LONG DO WE KEEP YOUR INFORMATION? (RETENTION & PURGE)
  9. HOW DO WE KEEP YOUR INFORMATION SAFE?
  10. WHAT ARE YOUR PRIVACY RIGHTS? (DPDPA / GDPR)
  11. CONTROLS FOR DO-NOT-TRACK FEATURES
  12. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS? (CCPA/CPRA)
  13. CHILDREN'S PRIVACY & EDUCATIONAL DATA (COPPA & FERPA)
  14. DO WE MAKE UPDATES TO THIS NOTICE?
  15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE? (GRIEVANCE OFFICER)
  16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. RELATIONSHIP & ROLES IN OUR SAAS ECOSYSTEM

In Short:

The Event Organizer/Photographer is in charge of event photos and must get your permission. You control your selfie and account. Memzo provides the technology across our Website and App to match your face to your photos safely.

In Detail

Under modern global data privacy frameworks (including India's DPDPA 2023, GDPR, and CCPA/CPRA), legal responsibilities across our SaaS platform are defined as follows:

  • Event Photo Distributors (Organizers / Photographers): Act as the Data Fiduciary or Data Controller. They determine the purpose of processing, upload event photos, select the distribution model (Free vs. Paid), and are legally required to secure explicit consent from participants prior to uploading their media or utilizing facial recognition.
  • Event Participants (End-Users / Guests): Act as the Data Principal or Data Subject. They utilize our Services to find, view, or purchase their photos using a face-scan selfie.
  • Memzo: Acts as the Data Processor (or Data Fiduciary via delegation). We process personal data strictly according to the features chosen by the Distributor and the specific choices made by the Participant.

2. WHAT INFORMATION DO WE COLLECT?

In Short:

We collect information you give us (like name, email, phone, selfie), photo media, and technical data automatically collected by your device (IP address, device info, cookies). Facial scans are generated only with your explicit opt-in consent.

In Detail

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us, or otherwise contact us.

Data Category

Specific Elements Collected & Stored

Legal Basis for Processing

Account Data

Full Name, Email Address, Mobile Number, Username.

Contractual Performance / Account Setup.

Media Data

Original Event Photos uploaded by the Distributor, and original Selfies uploaded by the Participant.

Distributor’s Consent / Participant Consent.

Biometric Data

Facial Recognition Templates derived from Participant selfies and Event Photos.

Explicit, Separate Opt-In Consent requested at the time of selfie capture.

Financial Data

Transaction history and billing details (Processed entirely via secure gateways like Razorpay, Stripe).

Contractual Performance / Legal & Tax Compliance.

Automatically Collected Data

IP Address, browser/device type, operating system, log & usage data (Processed via tools like Microsoft Clarity).

Legitimate Business Interests / System Optimization.

3. HOW DO WE USE YOUR INFORMATION?

In Short:

We use your data to help you find your photos using AI matching, fulfill orders, protect our platform, communicate with you, and comply with the law.

In Detail

We process your information for purposes based on legitimate business interests, the performance of our contract with you, compliance with our legal obligations, and/or your consent:

  • Facial Recognition & Photo Matching: To match your uploaded selfie against event photos uploaded by Distributors.
  • Facilitating Account Creation & Authentication: To manage your account and allow secure logins via phone OTPs or email.
  • Fulfilling Purchase Orders: To handle financial transactions for paid event photo unlocks.
  • Service Feedback & Customer Support: To respond to user inquiries and troubleshoot issues.
  • Administrative Communications: To send product updates, security alerts, transaction receipts, and administrative notifications.

4. THIRD-PARTY SUB-PROCESSORS & SERVICE PROVIDERS

In Short:

We share specific data with trusted third-party providers to power our platform—such as AWS for cloud hosting, Razorpay/Stripe for payment processing, Sinch/Twilio/MSG91 for OTP communications, SendGrid for emails, and Microsoft Clarity for app optimization. We never sell your personal data or facial templates.

In Detail

To deliver our Services smoothly across Web and Mobile App, we engage third-party service providers ("Sub-processors") who process data on our behalf under strict contractual data protection agreements:

  • Cloud Infrastructure & Hosting: We utilize Amazon Web Services (AWS) for secure database management, facial vector storage, and server hosting in regional data centers.
  • Payment Processing: Financial transactions for paid event photo unlocks are processed via PCI-DSS compliant gateways, including Razorpay and Stripe. Memzo does not store credit/debit card numbers or sensitive financial credentials on its own servers.
  • SMS & OTP Communication: Mobile number verification, OTP dispatch, and transactional SMS alerts are routed through enterprise communication gateways including Sinch, Twilio, and MSG91.
  • Email Communication: System communications, purchase receipts, and password resets are delivered via SendGrid (Twilio).
  • Analytics & Session Monitoring: We use tools like Microsoft Clarity to analyze how users interact with our Website and App through anonymized heatmaps and session metrics. This helps us troubleshoot performance bottlenecks and improve user interface design.

We ensure that all sub-processors maintain technical and organizational safeguards aligned with India's DPDPA 2023, GDPR, and CCPA standards.

5. COOKIES, TRACKING & SESSION ANALYTICS

In Short:

We use cookies and analytics tools (like Microsoft Clarity) to keep you logged in, analyze user flows, and ensure our app works properly.

In Detail

We use cookies, web beacons, and session recording technology (including Microsoft Clarity) to automatically capture behavioral data, device diagnostics, and page engagement metrics.

  • Essential Cookies: Required for basic site navigation, account authentication, and security.
  • Analytics & Performance Tracking: Used to monitor system performance, screen recording flows for bug diagnostics via Microsoft Clarity, and user navigation patterns.
  • Managing Cookies: You can adjust your device or browser settings to block cookies or clear session storage. However, blocking essential cookies may disrupt automatic photo-matching services or account login functions.

6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short:

If you log in using a social media account (like Google or Facebook), we receive basic profile info based on your social network settings.

In Detail

If you choose to register or log in to our Services using a third-party social media account, we may receive certain profile information about you from your social media provider (such as your name, email address, profile picture, and user ID). We use the information we receive only for the purposes that are described in this privacy notice or that are otherwise made clear to you on the relevant Services.

7. WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?

In Short:

We are not responsible for the safety of any information you share with third-party providers who advertise or link to our Services.

In Detail

The Services may contain advertisements or links to third-party websites, online services, or mobile applications. We cannot guarantee the safety and privacy of data you provide to any third parties. Any data collected by third parties is not covered by this privacy notice. We are not responsible for the content or privacy and security practices and policies of any third parties.

8. HOW LONG DO WE KEEP YOUR INFORMATION? (RETENTION & PURGE)

In Short:

  • Free Events: You can delete your selfie, profile, and face data anytime from your dashboard.
  • Paid Events: Photo data is automatically and completely purged 2 years after event creation. Transaction records are kept as required by tax laws.

In Detail

Memzo’s data lifecycle is dynamically tied to the nature of the event established by the Distributor and individual actions taken by Participants:

A. Free Distribution Events (Public / Complimentary Access)

  • Participant Autonomy: Participants have full self-service control over their personal data.
  • Immediate Deletion Mechanism: A Participant may delete their user profile, contact information, and matching facial vectors directly from their App or Website dashboard interface.
  • Result: All personal identifiers, and matching data are permanently purged from active production servers instantly upon execution.

B. Paid Distribution Events (Commercial / Pay-to-Unlock Access)

  • Distributor & Transactional Overrides: Data deletion cannot be executed unilaterally by a Participant due to financial tracking, purchase history integrity, and contractual obligations with the Event Distributor.
  • Automated Expiration: All stored data (including original event photos, selfies, metadata, and transactional linkages) is automatically and entirely purged from Memzo’s servers exactly two (2) years after the event creation date.
  • Distributor-Initiated Deletion: Event Distributors (Data Controllers) may request or execute a manual event termination and complete data wipe prior to the 2-year timeline, processed within 30 days.
  • Tax & Financial Retention: Identifiable data linked to successful financial transactions will be legally retained under statutory tax and financial reporting obligations.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short:

Your photos, selfies, and face scans are encrypted in cloud storage on AWS. When deleted, backup copies are completely erased within 90 days.

In Detail

We deploy technical and organizational security measures to protect stored media and biometric profiles across our cloud infrastructure:

  • Storage Encryption: Original images and selfies are stored in secure, encrypted cloud buckets governed by strict, role-based access controls.
  • Backup Synchronization: When a deletion event is triggered (via Participant deletion in Free Events, Distributor Request, or the 2-Year Paid Expiry), the erasure instruction cascades across all production environments, replica sets, and encrypted cold backups within a maximum window of 90 days.

10. WHAT ARE YOUR PRIVACY RIGHTS? (DPDPA / GDPR)

In Short:

You can review, update, download, or request deletion of your personal data at any time by emailing support@memzo.ai.

In Detail

Subject to applicable jurisdictional laws (such as Sections 11–14 of India's DPDPA 2023 or Chapter 3 of the GDPR), you possess the following rights:

  • Right to Access & Summary: Request a summary of your personal data being processed and a history of sharing activities.
  • Right to Correction & Erasure: Correct inaccuracies or demand complete erasure of your selfies and account data (subject to Paid Distribution rules in Section 8).
  • Right to Withdraw Consent: Withdraw your biometric consent at any moment, which will instantly cease photo-matching services for your profile.
  • Right to Grievance Redressal: File a complaint regarding platform processing activities.

11. CONTROLS FOR DO-NOT-TRACK FEATURES

In Short:

Most web browsers include a Do-Not-Track ("DNT") feature. Because there is no uniform standard, we currently do not respond to DNT browser signals.

In Detail

Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.

12. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS? (CCPA/CPRA)

In Short:

Yes, California residents have specific rights regarding personal information, including the right to know what data is collected, request deletion, and opt-out of data sales. Memzo does not sell or share your personal data or facial recognition templates.

In Detail

Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), California residents have specific rights regarding their Personal Information:

  • Right to Know and Access: You have the right to request information about the categories and specific pieces of personal information we have collected, used, and disclosed about you over the past 12 months.
  • Right to Request Deletion: You can request the erasure of your personal information, subject to certain legal exceptions (such as financial transaction records for paid photo downloads).
  • Right to Correct Inaccurate Data: You can request that we rectify inaccurate personal data maintained in your account.
  • Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
  • No Sale or Sharing of Biometric Data: Memzo does not "sell" or "share" (for cross-context behavioral advertising) your personal data, selfies, or facial recognition templates as defined under California law.

To exercise your California privacy rights, please contact us at support@memzo.ai.

13. CHILDREN'S PRIVACY & EDUCATIONAL DATA (COPPA & FERPA)

In Short:

We do not knowingly collect data directly from children under 13 without parental or school consent. When Memzo is used for school or university events, Event Distributors (schools/photographers) are legally responsible for obtaining mandatory parental consent under COPPA and FERPA.

In Detail

A. COPPA (Children’s Online Privacy Protection Act)

  • Under 13 Protection: Memzo’s Services are not directed to children under 13 years of age. We do not knowingly collect personal data or biometric information from children under 13 without verifiable parental or guardian consent.
  • Distributor Responsibility: Event Photo Distributors (photographers and organizers) utilizing Memzo at events involving minors are strictly contractually required to obtain verifiable parental consent prior to uploading media or enabling facial recognition features.
  • Parental Rights: If a parent or guardian discovers that their child under 13 has provided us with personal information without consent, they may contact us at support@memzo.ai to request immediate deletion of the account, selfie, and facial recognition data.

B. FERPA (Family Educational Rights and Privacy Act)

  • School & Campus Events: When Memzo is used by educational institutions or third-party photographers contracted by schools/universities to distribute school event, sports, or graduation photos, the school or event distributor acts as the primary Data Controller.
  • Service Provider Role: To the extent that photos or directory information qualify as "Education Records" under FERPA, Memzo acts solely as a "School Official" or service provider with a legitimate educational interest, processing data under the direct control and instruction of the educational institution. Memzo never uses student media or biometric data for independent marketing, profiling, or commercial advertising.

14. DO WE MAKE UPDATES TO THIS NOTICE?

In Short:

Yes, we will update this notice as necessary to stay compliant with relevant laws (such as new DPDPA guidelines).

In Detail

We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.

15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE? (GRIEVANCE OFFICER)

In Short:

Have questions or complaints? Contact our Grievance Redressal Officer in Hyderabad, India, or email us directly.

In Detail

In compliance with the Digital Personal Data Protection Act (DPDPA), 2023, the Company has designated a dedicated Grievance Redressal mechanism. For any privacy inquiries, data deletion bottlenecks, or formal complaints, contact our Grievance Officer directly:

Attn: Data Protection Officer / Grievance Officer

Entity: Oneglint Media Solutions Private Limited

Address: #Plot No 4, Survey no- 124, Road no 15D, Industrial Park, IDA Nacharam, Hyderabad, Telangana 500076, India

Email: support@memzo.ai

16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

In Short:

You can manage your data directly inside the Memzo App or Web Dashboard, or by submitting a support request to support@memzo.ai.

In Detail

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it in some circumstances.

To request to review, update, or delete your personal information, please visit your account profile settings inside the App or Website dashboard, or submit a request by emailing support@memzo.ai. We will respond to your request within 30 days.