Privacy Policy
Last updated: July 2026
1. Who We Are
HaaFoto ("HaaFoto," "we," "us") operates the website haafoto.com and provides AI-powered passport, visa, and ID photo creation services. This policy explains how we collect, use, store, and protect your personal data when you use our service.
2. Data We Collect
To provide our service, we collect the following categories of data:
- Email address — Used to deliver your processed photo, send order confirmations, and provide support. We never send marketing emails without your explicit consent.
- Uploaded photos — The images you upload for processing. These are the core of our service. Standard orders are processed entirely by AI automation — no human views your photo.
- Payment information — Processed exclusively by Stripe and PayPal. We do not receive, store, or have access to your full credit card number, CVV, or bank details.
- Order metadata — Document type, locale, and photo specifications selected. Used to generate your compliant photo.
- Technical data — IP address, browser type, and device information collected via standard server logs. Used for rate limiting, fraud prevention, and service improvement.
3. Photo Processing & Storage
Photos uploaded for standard Digital orders are processed entirely by AI automation. No human views your photo during standard processing. If you select the Expert Review add-on, a trained compliance specialist reviews your photo — they see only the photo and document type, not your name or email address.
Photos are stored encrypted at rest using AES-256. Processed photos and original uploads are automatically deleted after 30 days. You can request immediate deletion at any time by contacting privacy@haafoto.com.
We do not use your uploaded photos for AI model training, marketing, or any purpose other than providing the photo processing service you requested. Photos are never sold, licensed, or shared with third parties.
4. Payment Processing
All payments are processed by Stripe and PayPal, industry-leading payment processors with PCI-DSS Level 1 certification. Your payment details are transmitted directly to their servers via encrypted connections. We never receive or store your full payment card details. Stripe and PayPal have their own privacy policies governing their use of your payment data.
5. Cookies & Analytics
We use essential session cookies required for site functionality (authentication, form submissions, locale preferences). These cookies do not track you across sites and are deleted when you close your browser.
We use Google Analytics to understand how visitors use our site. Google Analytics sets its own cookies and processes data according to Google's privacy policy. You can opt out of analytics cookies via the cookie consent banner on our site, or by using Google's opt-out browser add-on.
6. Data Sharing & Third Parties
We share data with third parties only as strictly necessary to provide our service:
- Stripe / PayPal — Payment processing
- Resend — Transactional email delivery (order confirmations, photo delivery)
- Hetzner / VPS provider — Infrastructure hosting within the EU
We do not sell, rent, trade, or otherwise share your personal data with any other third parties. We do not engage in data brokerage, targeted advertising, or user profiling.
7. Data Retention
- Uploaded photos — Deleted after 30 days (or immediately upon request)
- Order records — Retained for 6 years for tax and accounting compliance
- Email address — Retained while your account is active, deleted upon request
- Server logs — Retained for 90 days for security monitoring
8. Your Rights Under GDPR
As a data subject under the EU General Data Protection Regulation, you have the following rights:
- Right of access — Request a copy of your personal data we hold
- Right to rectification — Correct inaccurate or incomplete data
- Right to erasure — Request deletion of your data ("right to be forgotten")
- Right to restriction — Limit how we process your data
- Right to data portability — Receive your data in a structured, machine-readable format
- Right to object — Object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@haafoto.com. We will respond within 30 days as required by law.
9. Data Security
We implement industry-standard security measures: AES-256 encryption at rest, TLS 1.3 in transit, strict Content Security Policy headers, Redis-backed rate limiting against abuse, read-only production filesystems, and no-new-privileges Docker containers. Our infrastructure runs in EU data centers for GDPR compliance. Access to production systems is restricted to authorized personnel and logged.
10. Children's Privacy
Our service is not directed at children under 16. We do not knowingly collect personal data from children. Baby and infant passport photos must be uploaded by a parent or legal guardian who consents to the processing of the child's photo for the sole purpose of creating a compliant passport or ID photo.
11. Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email. Continued use of the service after changes constitutes acceptance of the updated policy.
12. Contact & Supervisory Authority
For privacy-related inquiries, contact our Data Protection Officer at privacy@haafoto.com.
You have the right to lodge a complaint with your local data protection supervisory authority. Contact your local data protection supervisory authority for privacy complaints.