What HM Camera is
HM Camera is an event photo app used by event operators to capture, brand, and deliver media to their guests. This policy covers the HM Camera app and the honeymotion.workers.dev gallery service.
What we collect, and why
Operator email address: received during account sign-in and used to identify and support the operator's HM Camera account.
Apple user ID: Sign in with Apple provides a stable identifier so the same Apple ID returns to the same HM Camera account. We do not use it for advertising or tracking.
Guest name: shown on your private gallery page and used to label your photos.
Guest email address: used only to send you your photos. Your address is stored with your registration both on the operator's device and in HM Camera's event database, so that whichever device the operator is holding when your photo is ready can actually deliver it to you. It is passed to an email delivery service (HM Camera's own, or the operator's provider) solely to deliver your media. Deleting a guest erases the stored address along with their photos. Addresses that permanently fail or opt out are kept on a do-not-send list so we never email them again. Never sold, never used for marketing or advertising.
Photos: the media captured of you at the event, stored so your private gallery link works.
Purchase history: when an operator buys an email top-up pack, we store Apple's transaction identifier, original transaction identifier, product, purchase date, and status with the operator's account. We use this only to grant the emails once, recover an unfinished purchase, and handle refunds.
QR scan counts: when event QR codes are scanned we record the time, approximate country, and browser type to show operators how their signage performs. No precise location, no identity.
What we don't do
No advertising. No cross-app tracking. No selling or renting data. Gallery pages are unlisted, excluded from search engines, and reachable only by their unique code.
Where data lives
Account records, galleries, guest registration details, purchase records, and media are hosted on Cloudflare infrastructure. Transactional email is delivered through Resend or the event operator's configured email provider. These providers process data only to operate HM Camera's storage, delivery, and account features.
Retention and deletion
Guest registration details and media are kept while the event operator needs the event and its private galleries. Event operators can delete a guest, which removes that guest's event record and stored media. Guests may request deletion from their event operator or contact us directly.
Operators can request account deletion inside the app at Settings › Danger Zone › Delete Account. This starts permanent deletion of the cloud account and its account-linked events, guests, stored media, sign-in identity, and purchase records. A failed deletion leaves the operator signed in so it can be retried instead of reporting success prematurely.
Email addresses that bounced, complained, or opted out remain on a do-not-send list so HM Camera continues honoring that choice and protects the shared sending service. QR scan records contain no scanner identity. We may retain records when required for security, fraud prevention, dispute handling, or legal compliance.
Contact
support@hmcamera.com