Privacy Policy
Last updated: 14 September 2026
FOMO SHOOT photographs runners on public routes around Lisbon and sells them their photos. This policy explains what personal data we handle and your rights under the GDPR / RGPD. Questions: fomoshootsupport@gmail.com.
1. Who we are
FOMO SHOOT is the controller of your personal data — we decide how and why it is processed.
All privacy matters — questions, access requests, deletion requests, complaints: fomoshootsupport@gmail.com. We have not appointed a Data Protection Officer; our processing is small-scale and, as described in section 3, we keep no standing biometric database.
2. What we collect
Photographs of you taken by our photographers in public places while you were running.
If you use face search: the selfie you upload, processed in real time for that one search only (see section 3).
If you save your selfie for reuse: a copy kept only in your own browser on your own device — we never receive or store it.
Order and payment data: billing name, email, and payment confirmation from our payment provider. We never see or store full card numbers.
If you sell photos through FOMO SHOOT as a photographer: your account and profile details, your tax number (NIF) and — only when you request a payout — your bank account number (IBAN). We use these to pay you and to meet our invoicing and bookkeeping obligations (Art. 6(1)(b) and 6(1)(c) GDPR).
A removal request: the email and details (or photo IDs) you send us through the form on this page.
Technical data: IP address, browser type, and cookies (section 9).
3. Face search — how it works
Face search is entirely optional. Before you upload a selfie you must tick a separate, unticked consent box confirming you agree to biometric processing of that image (Art. 9(2)(a) GDPR). It is never pre-ticked or bundled with anything else, and we record that you gave it (time and wording), never the image.
There is always a non-biometric way to find your photos: browse by location, date and time, or scroll the full gallery for a spot. Face search is a choice, never a condition of using FOMO SHOOT.
We do NOT keep a standing, searchable database of everyone we photograph. There is no permanent face index. When you search, your selfie is compared in real time against only the photos from the location you picked, then discarded. No face template is created for people who never search.
Your search selfie is never written to our servers, storage, database, logs or backups. It exists only in memory for the seconds the comparison takes, and the biometric vector derived from it is never stored.
“Save my selfie on this device”, if you tick it, stores the selfie only in your browser’s local storage on that device. We never receive that copy. Remove it any time with “Forget” or by clearing your browser data.
4. Why we can process your data
Taking and showing photos of runners on public routes: our legitimate interest (Art. 6(1)(f)) together with the image-rights consent Portuguese law requires (Civil Code Art. 79). We publish only low-resolution, watermarked previews; full-resolution copies are released only after purchase.
Making sure only content taken in line with image and data-protection rights gets published: a legal obligation and our legitimate interest (Art. 6(1)(c) and (f)). New photographer accounts must pass a review before they can publish, and any photo that violates those rights is removed as soon as we find out, which can mean suspending the account responsible.
Comparing your selfie against our photos: your explicit consent (Art. 9(2)(a)) plus performance of the service you asked for (Art. 6(1)(b)).
Processing your purchase and delivering your photos: performance of a contract (Art. 6(1)(b)).
Invoicing and tax records: a legal obligation (Art. 6(1)(c)).
Analytics cookies: your consent (Art. 6(1)(a)), which you can withdraw at any time.
You can withdraw any consent at any time, without affecting processing already carried out.
5. Who we share data with
We use a small number of specialist service providers, each under a data-processing agreement and only for the purposes above. We do not sell your data and never share your photos for anyone else’s marketing.
A cloud storage and image-processing provider — stores the photos and runs the real-time face comparison. Data is held in the EU/EEA.
A website hosting and delivery provider.
A database provider (EU-hosted) — holds orders, removal requests and consent records. No images and no biometric data are stored there.
A payment provider — processes your payment. We never see your full card number.
An email provider — sends the email with your photos after a purchase.
Public authorities, where the law requires it.
6. International transfers
Our providers process data in the EU/EEA where possible. Where any processing occurs outside the EEA, it is covered by the European Commission’s Standard Contractual Clauses or an equivalent GDPR Chapter V safeguard.
7. How long we keep data
Unpurchased photos: deleted 30 days after they are taken.
Purchased photos: kept so you can re-download them, for as long as we are trading and you may need them.
Biometric data: none is retained. There is no face template to keep — comparison is done live and thrown away.
Order and invoice records: kept for 10 years, as Portuguese tax law requires (Código do IVA Art. 52), counted from 31 December of the year the invoice was issued. This is the transaction record only, not the photo.
Photographer tax and payout data (NIF, IBAN, payout history): kept while the account is open and afterwards for as long as Portuguese accounting and tax law requires (up to 10 years).
Consent records: kept as evidence for as long as we could need to demonstrate a lawful basis, and no longer.
Removal requests: kept until resolved plus a short period to show we acted.
8. Your rights
Under the GDPR, you always have the right to:
• Confirm whether we process data about you, and access it;
• Ask us to correct data that is incomplete, inaccurate or outdated;
• Ask us to delete, anonymise or restrict data that is unnecessary, excessive, or processed out of step with the GDPR;
• Ask us to hand over your data in a portable format, wherever technically possible;
• Object to processing — including objecting to being photographed and included in our galleries;
• Know who we share your data with (section 5), and what happens if you withhold a given consent — for face search, for instance: nothing, because there is always a non-biometric alternative (section 3);
• Withdraw any consent at any time, without affecting processing already carried out;
• Complain to the Portuguese supervisory authority, the CNPD (www.cnpd.pt), or the authority where you live. We only ask that you talk to us first — we resolve the large majority of requests within a few days, no need to escalate.
To have photos removed: use the form on this page. Include the Photo IDs (shown under each photo) if you can — it is the fastest way for us to find them — or tell us roughly where and when. Deletion removes the image and every derived copy from our storage. Because we keep no face templates, there is nothing further to purge.
We act on removal requests within 5 business days and respond to any rights request within one month (Art. 12(3) GDPR).
9. Cookies & local storage
We mostly rely on your own browser's local storage (localStorage/sessionStorage), not tracking cookies, to remember simple preferences: your language choice (for that visit only), your analytics-cookie decision, and — only if you choose to keep it — your selfie. None of this ever leaves your device or reaches us.
One strictly necessary, technical cookie keeps you signed in to the photographer dashboard. It cannot be read by scripts and only exists for photographer accounts — without it, staying signed in between visits wouldn't be possible.
Third-party analytics and marketing cookies (for example, to understand which pages work best) load only after you accept them in the cookie banner. Change your mind any time via “Cookie settings” in the footer.
You can clear all of this whenever you like in your browser's settings. Doing so ends any active session and resets your preferences, with no effect on the data we hold about you.
10. Photos of minors
If you are a parent or guardian and your child appears in one of our photos, email fomoshootsupport@gmail.com and we will remove it promptly.
11. Security
We use encryption in transit and at rest, access controls on who can view photos, and keep the number of people and systems that touch your data to a minimum. Full-resolution photos are private and served only through short-lived links after purchase.
12. Changes
We will post any updated version here with a new date, and tell purchasers by email about material changes to how we handle their data.
13. Contact
FOMO SHOOT — fomoshootsupport@gmail.com.
Supervisory authority: CNPD — Comissão Nacional de Proteção de Dados, www.cnpd.pt.
Request removal
Tell us your email and which photos to remove — paste the Photo IDs (shown under each photo), or describe roughly where and when you were photographed.
