Privacy policy

Last updated: 17 July 2026

This is an English convenience translation. The German version (privacy.de.md) is the legally authoritative one.

The most important part first

Your photos never leave your device. When you create a graphic on an event page, everything happens in your browser: your device places your photo under the frame graphic locally and saves the finished image right there with you. There is no photo upload, no server that ever sees your image, and no copy on our side. That is not a policy we have to follow, it is the architecture of the system.

Event pages set no cookies and store nothing in your browser. That is why you see no cookie banner there: there is nothing we would need your consent for.

Controller

PIRATEx GmbH
Brabanter Str. 53
50672 Cologne
Germany

Managing director: Manuel Koelman
Email: manuel@piratex.com
Phone: +49 (0) 221 / 975 892 71

Who this policy applies to

ShowUp has two groups of users. Visitors of event pages create graphics without signing up. Organizers create an account to build and manage their event pages. This policy describes what the system does with data for both groups.

The organizer is responsible for the content of their event page (texts, frames, logos, linked ticket shops). If they link their own privacy policy, it appears in the footer of their event page; otherwise the footer links this notice, which covers the technical operation of the page (see "When you visit an event page").

When you visit an event page

You need no account, no email address and no consent. The page sets no cookies, stores nothing in your browser's local storage and loads nothing from third parties. Even fonts are served from our own server.

Your photo stays on your device. The browser only downloads the organizer's frame graphics from our server; composing and saving the finished graphic happens entirely on your device.

What we count: anonymous totals. Our system registers events such as page view, photo selected, graphic downloaded, caption copied or ticket link clicked, and stores nothing but counters per event, day and event type. There are no visitor IDs, no profiles, no fingerprinting and no storage of IP addresses. Nobody can identify a person from the stored data, including us.

Our server processes your IP address only transiently, as far as technically necessary to deliver the page to you and to limit abuse. For abuse limiting (rate limiting), the system derives short-lived, salted hash values that are deleted after a short time. Raw IP addresses are never stored. The legal basis is Art. 6 (1) (f) GDPR (operating and securing the service).

When you use the ShowUp website

The pages of the platform itself, the homepage, the help pages and the organizer dashboard, use a cookieless analytics tool so we can see how the site is used and improve it. We run it on our own infrastructure (Umami, self-hosted at pirate.builders). It sets no cookies and stores nothing on your device. It records aggregate usage such as page views, the referring website and an approximate device, browser and country derived from your IP address. It builds no cross-site profile, uses no fingerprinting and does not store your raw IP address. The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in understanding and improving our own website; you can object to it at any time (Art. 21 GDPR). This applies only to the platform website. The attendee event pages load no analytics script and stay locked to their own origin.

When you have an organizer account

For an account we store three things: your email address, your name and your language setting. There is no password. To sign you in, we email you a sign-in link; the token behind it is valid once, expires after 15 minutes and is stored on our side only as a hash.

After sign-in, the platform sets a single session cookie. It is technically necessary to keep you signed in and has no tracking function. Event pages do not use it. The session ends after 30 days without activity or when you sign out.

Emails the system sends you (sign-in link, publish confirmation, event report, deletion confirmation) are kept in an outbox archive: recipient, template, language, subject, content and delivery status. This lets us trace delivery problems, and no message gets lost unnoticed.

The legal basis for all of this is Art. 6 (1) (b) GDPR: we process this data to provide the service you use.

Recipients and processors

ShowUp runs entirely on our own server in the EU: database, pages, graphics, statistics. There is exactly one external service provider: the email delivery service (SMTP relay) that carries our system emails. That is ALL-INKL.COM (Neue Medien Münnich GmbH, Germany); a data processing agreement under Art. 28 GDPR is in place with this provider. There are no other recipients. No data is transferred to third countries.

How long we keep data

We keep the anonymous daily counters indefinitely. They contain no personal data and serve as platform statistics.

Event drafts that have not been edited for 12 months are deleted; you receive a warning email first. Sign-in tokens expire after 15 minutes or after a single use.

You delete your account yourself, directly in the settings, without a support ticket. Deletion takes effect immediately and is irreversible: account, events, uploaded files, published pages and the outbox archive of your emails are removed. Only the anonymous daily counters remain, because they cannot be linked to any person.

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Access and erasure for your account are self-serve in the settings; for everything else, write to manuel@piratex.com.

You also have the right to lodge a complaint with a supervisory authority. The one responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (www.ldi.nrw.de).

Why there is no cookie banner

A consent banner is required when a page stores or reads information on your device beyond what is technically necessary, or when it processes personal data based on consent. ShowUp does neither: event pages store nothing on your device, the statistics consist of anonymous totals with no link to any person, and the platform's website analytics is cookieless and stores nothing on your device either. The platform's only cookie is the technically necessary session cookie after organizer sign-in (Section 25 (2) of the German TDDDG).

Changes to this policy

When something changes in the system that affects data, we update this policy and adjust the date at the top. Organizers with an account are informed about material changes by email.

This policy describes what the system actually does.