Privacy policy
Last updated: September 26, 2026
In short
- We do not store uploaded files. They are transferred directly from participants’ devices to the organizer’s Google Drive.
- EventUpload can only access the Google Drive folders and files it created itself – not the rest of your Drive.
- We use no tracking, no analytics tools and no advertising.
- Our servers and databases are located in Frankfurt (EU).
1. Controller
Aigner Software e. U.
Owner: Matthias Manuel Aigner
Hauptplatz 23
4190 Bad Leonfelden
Austria
Email: [email protected]
2. Scope
EventUpload lets organizers create an upload page. Other people (“participants”) can use it to upload files, which are stored directly in the organizer’s Google Drive. This policy explains which personal data is processed in the process.
3. Organizer data
When you sign in with Google, we process:
- Google account data: name, email address, profile picture and Google account ID – for sign-in and your account.
- Google Drive authorization: an access token (refresh token), stored encrypted, so uploads into your Drive work even when you are offline.
- Upload page settings: title, texts, colors, logo, page address, ID and name of the Drive folder.
- Statistics: number of uploads and files and the transferred data volume per upload page.
Legal basis: performance of the contract of use (Art. 6(1)(b) GDPR).
4. Participant (uploader) data
- Files: are transferred directly from the browser to Google Drive and stored in the organizer’s Drive. They do not pass through our servers and are neither stored nor viewed by us.
- File information: file name, size and type – to prepare the upload and to check that the file has arrived.
- Name (optional): if the organizer asks for it, the name is prepended to the file name and stored in the file description in Drive.
- Technical data: IP address and browser information for abuse prevention (Cloudflare Turnstile, see below) and in server logs.
For uploaded files and names, the respective organizer is the controller under the GDPR; we transfer them on the organizer’s behalf (Art. 28 GDPR). Please direct questions about uploaded files to the organizer of the upload page. We are the controller for technical data needed for operation and security (legitimate interest, Art. 6(1)(f) GDPR).
5. Access to Google accounts and Google Drive
When you sign in, EventUpload requests the following Google permissions:
openid,email,profile– to sign you in with your Google account.drive.file– so EventUpload can create a folder in your Google Drive for each upload page, store participants’ files in it and check that a file has arrived.
With drive.file, EventUpload can only access files and folders it created itself. It can neither see nor modify any other files in your Google Drive.
EventUpload’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google data solely to provide EventUpload’s features.
- We do not sell it, do not share it with third parties (except the technical service providers listed below) and do not use it for advertising.
- Humans do not read this data unless you explicitly agree, it is necessary for security purposes, or it is required by law.
- We do not use it to train AI models.
You can revoke access at any time in the dashboard (“Disconnect”) or in your Google account under third-party apps. The stored token is then deleted or becomes invalid.
6. Service providers (processors)
- Google Cloud / Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland): website hosting, sign-in (Firebase Authentication), database (Cloud Firestore), server functions (Cloud Functions), logo storage (Cloud Storage) and server logs. Database, server functions and storage are located in the europe-west3 (Frankfurt) region.
- Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA): website delivery and protection (CDN, DNS) and Cloudflare Turnstile on upload pages to prevent automated uploads (bots). Turnstile processes technical data such as IP address and browser characteristics for this.
Data processing agreements are in place with these providers. Where data may be transferred to the USA, this is based on the EU-US Data Privacy Framework or EU Standard Contractual Clauses (Art. 45, 46 GDPR).
Google Drive itself is the organizer’s storage. Files stored there are governed by the terms between the organizer and Google.
7. Retention
- Account data and settings: until you ask us to delete your account.
- Google Drive token: until you disconnect or revoke access at Google.
- Upload records (file names, sizes, optional name) for statistics: at most 14 days.
- Intermediate sign-in data: at most 10 minutes.
- Server logs: usually 30 days.
- Uploaded files: not stored by us; they remain in the organizer’s Google Drive until the organizer deletes them.
If you delete an upload page, the files in your Google Drive are kept.
8. Cookies and local storage
We only use technically necessary storage:
- A
__sessioncookie during Google sign-in (at most 10 minutes) to protect the sign-in against abuse. - Your dashboard sign-in is stored in the browser (Firebase Authentication IndexedDB) so you stay signed in.
- Cloudflare Turnstile may store technically necessary data in the browser on upload pages.
We use no analytics, tracking or advertising cookies – which is why there is no cookie banner.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Just email us at [email protected]. We usually respond within one month. We also delete your account on request by email.
You may also lodge a complaint with a supervisory authority; in Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, [email protected], dsb.gv.at.
10. Security
- All connections are encrypted (HTTPS/TLS).
- Google Drive tokens are additionally encrypted with AES-256; the key is kept separately in Google Secret Manager.
- Security rules restrict data access to the respective account.
- Participants only receive upload permission for individual files – no access to the Drive or to other people’s files.
11. Changes
We update this privacy policy when EventUpload or the legal situation changes. The version published here applies.