Digipic

Data Security

How we protect your data

This English translation is provided for convenience only. In case of any discrepancy, the Swedish version is legally binding.

Storage within the EU

All data – including the database, files and backups – is stored on servers within the EU/EEA. We use Hetzner (Germany/Finland) for hosting, Supabase (Sweden) for the database and Azure Blob Storage (Sweden) for media files.

Encryption

All traffic between your browser and our servers is protected with HTTPS/TLS encryption. Data at rest is encrypted by our cloud providers according to industry standards.

  • In transit: TLS 1.2+ for all communication.
  • At rest: AES-256 encryption at Azure and Supabase.

Access control

Media files can only be accessed by authorized parties. Uploads use time-limited signed URLs (SAS tokens) that expire after a short time. Event content requires a valid invite link.

Authentication

Organizer accounts are protected by Supabase Auth with support for email/password and social login (Google). Passwords are hashed and never stored in plain text.

Payment security

All payment processing is handled by Stripe, which is PCI DSS Level 1 certified. We never store your card details – they are handled entirely by Stripe.

Automatic deletion

Media files are deleted automatically when the event's storage period ends. We do not keep copies of deleted files. You can also manually delete individual files or entire events at any time.

Security questions

Questions about our data security, or want to report a vulnerability? Contact us at contact@digipic.se.