Skip to content
Roll the Moment
For organizersFor guestsFAQ
Sign inCreate event

Legal

Roll the Moment Privacy Notice

EffectiveAugust 22, 2026Version 2026-08-22.1

How Roll the Moment collects, uses, shares, protects, retains, and deletes personal information and event media.

On this page

  1. 01Scope and roles
  2. 02Information we collect
  3. 03How we collect information
  4. 04How we use information
  5. 05Who can receive information
  6. 06Advertising, sale, and targeted-advertising choices
  7. 07Cookies, local storage, and advertising technologies
  8. 08Media access, retention, and deletion
  9. 09Your privacy choices and rights
  10. 10Security
  11. 11Children’s privacy
  12. 12U.S. operation and international processing
  13. 13Changes to this Notice
  14. 14Contact us

This Privacy Notice explains how Circle City Coders LLC (“Circle City Coders,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information through Roll the Moment, including its websites, event pages, photo and video tools, and related services (the “Service”).

01Scope and roles

An “Organizer” is the account holder who creates an event. A “Guest” is anyone who uses an event link, including to upload or view photos or videos. Organizers choose their invitees, distribute event links, and control whether the optional Guest gallery is enabled. Circle City Coders operates the Service and handles information as described here.

This Notice applies to the Service. A third party’s own site or service, including Stripe-hosted checkout, is also governed by that party’s privacy notice.

02Information we collect

We collect the following categories of information.

Account and authentication information

For Organizers, we collect an email address, a password hash, email-verification status, account timestamps, and records of accepted Terms and Privacy Notice versions. We do not ask for an Organizer’s name or postal address to register, use an account, or create a Free event. We process short-lived access tokens and a rotating refresh token for signed-in sessions. Password-reset and email-verification tokens are stored as one-way digests rather than readable token values.

Event and entitlement information

We collect the event name, date, time zone, event identifier, Guest-gallery setting, per-device photo and video allowances, plan and video-pack selections, capacities, retention period, upload limits, price and tax totals, lifecycle times, operational status, and related account/date eligibility records. Anyone with an event link may receive the event name, date, time zone, Guest access status and window, applicable per-device allowances and upload limits, and whether the Guest gallery is enabled.

Guest and device information

Guests do not create accounts. The browser creates a random device identifier and stores it in local storage. We associate that identifier with an event, photo and video upload counts, pending counts, and timestamps so we can enforce the separate per-device allowances and event capacities. The browser also caches per-event submitted and allowed counts for display. The Service and its infrastructure providers may process IP address, browser or device information, and request data for delivery, rate limiting, security, and troubleshooting.

Photos, videos, and related information

We collect the image file, original filename, file type, byte size, format, dimensions, orientation, assigned photo number, upload status, event and device identifiers, storage references, and timestamps.

We preserve the original uploaded file unchanged. An original may contain metadata placed there by a camera or editing tool, including EXIF data, device details, capture time, or precise location. We also create JPEG thumbnails of up to 400 pixels on the longest edge; those thumbnails are generated without the original metadata. If the Guest gallery is enabled, event-link holders can receive the original, including its embedded metadata. We do not use the Service to perform facial recognition.

For an entitled short video, we collect the original video file, file type, byte size, client-reported duration and dimensions, assigned video identifier, upload status, event and device identifiers, storage references, and timestamps. A video may contain audio and metadata about the recording, device, time, or location. The uploader’s browser creates a JPEG poster image for gallery browsing. The Service stores the submitted video and poster without transcoding, extracting frames, or analyzing the audio or visual content.

Payment and transaction information

If an Organizer creates a paid event, we send the Organizer’s account email and opaque internal account, draft, and purchase-attempt identifiers to Stripe. Stripe-hosted checkout collects the billing name and billing address needed for payment and tax, along with payment-card, device, fraud-prevention, and tax-related information. Circle City Coders may access the billing name and billing address through Stripe only as needed for payment, tax, receipts, refunds, disputes, accounting, and legal compliance. We do not collect an Organizer’s name or postal address for a Free event. Roll the Moment does not receive or store the full card number or card security code.

We receive and retain limited transaction information from Stripe, such as Stripe customer and transaction identifiers, purchase amount, currency, tax, checkout and payment state, refund or dispute state, and relevant timestamps and processing history.

Communications and support information

We process the Organizer’s email address to send account verification, password reset, event deletion reminders, and other transactional messages. An event reminder may contain the event name, deadline, and event link. If you contact us, we collect the information in your message and any material you choose to provide.

Logs and security information

We process IP addresses for rate limiting. Application logs may contain request method, route, response status, duration, request identifier, error details, and aggregate operational measurements. Our logging rules are designed to redact email addresses, event names, filenames, Guest device identifiers, authentication tokens, media capabilities, signed URLs, storage keys, Stripe identifiers and metadata, and payment-webhook content. Infrastructure providers may maintain their own security and access logs under their policies.

Advertising and consent information

When Google advertising code is present or an ad request is allowed, Google and participating advertising technology providers may collect or receive the page URL and context, IP address, browser, device, and language information, cookie or local-storage identifiers, approximate location inferred from IP address, page and ad interactions, consent and privacy-choice signals, and information used to detect invalid traffic and measure advertising. The exact information depends on the device, browser, location, advertising configuration, consent and privacy choices, and whether an ad is personalized or non-personalized.

Advertising units support the Free plan and are limited to designated Event Detail and Guest pages for Free events. They are not shown on paid-event pages, and a direct visit to a paid-event page does not cause Roll the Moment to request the AdSense script or initialize an ad unit. If you first visit an eligible Free-event page and then navigate within the same app document, Google code, cookies, or local-storage identifiers already loaded for that Free page may remain until the document or browser storage is cleared. The marketing site uses a non-executing AdSense account-verification meta tag and an authorized-seller record; those items do not request the AdSense advertising runtime.

03How we collect information

We collect information:

  • directly from Organizers and Guests when they register, configure an event, upload a photo or video, make a purchase, or contact us;
  • automatically from browsers, devices, cookies, local storage, requests, and use of the Service;
  • from an Organizer who creates an event or sends an event link;
  • from service providers such as Stripe when they return payment, refund, dispute, fraud, or tax information; and
  • from Google and participating advertising technology providers when they return consent, privacy-choice, ad-delivery, measurement, reporting, or invalid-traffic information.

04How we use information

We use personal information to:

  • create, secure, and support Organizer accounts;
  • create and operate events, enforce event windows and capacity, and provide uploads, galleries, originals, playback links, downloads, and photo exports;
  • process images and create metadata-stripped photo thumbnails; receive browser-generated video posters for gallery browsing;
  • process one-time payments, calculate tax, activate paid events, reconcile payment states, and handle approved refunds or disputes;
  • send transactional account and event messages;
  • support the Free plan by requesting and displaying ads on eligible Free-event pages;
  • select, deliver, and measure personalized or non-personalized ads as permitted by the applicable configuration, consent, privacy choices, and law; limit ad frequency; report advertising performance; and detect invalid ad traffic;
  • detect abuse, rate-limit requests, prevent fraud, investigate errors, and protect the Service and its users;
  • answer support, copyright, privacy, and legal requests;
  • maintain transaction, policy-acceptance, security, date-eligibility, and operator-audit evidence; and
  • understand aggregate Service reliability, performance, and advertising performance.

We may also use information to comply with law, enforce the Terms of Use, establish or defend legal claims, and complete a merger, financing, acquisition, bankruptcy, or sale of all or part of the Service.

05Who can receive information

Organizers and event-link holders

The Organizer can access an uploaded original and its embedded metadata from the time it is uploaded until the event cutoff. While Guest access is open, anyone with the event link can submit photos and, for entitled events, short videos. If the Guest gallery is enabled, link holders can access, play, save, or share individual originals without Organizer preapproval, including audio and metadata embedded in those files. The Service does not provide a Guest bulk-export action. Copies already obtained by another person are outside our control.

The Guest gallery is enabled by default when an event is created. The Organizer can turn it off. Event links are meant to be shared and may be forwarded, so they should not be treated as confidential credentials.

Service providers

We disclose information to providers that help us run the Service:

  • DigitalOcean provides application hosting, managed database infrastructure, and private object storage.
  • Cloudflare provides network delivery, availability, and security services.
  • Mailgun processes recipient details and transactional email content for delivery. Open and click tracking are disabled in our Mailgun configuration.
  • Stripe hosts paid checkout and provides payment, fraud-prevention, refund, dispute, and automatic-tax services.
  • Google, through Google AdSense and participating advertising technology providers, delivers and measures advertising on eligible Free-event pages, manages consent and privacy choices, limits ad frequency, detects invalid traffic, and may personalize ads when permitted. Google explains how it uses information from sites and apps that use its services in its partner-sites notice. The providers that may participate depend on the advertising configuration, location, and consent or privacy choices; the applicable consent message identifies providers where required.

These providers process information under their own contracts and privacy terms. They may process information in the United States and other countries.

Legal, safety, and business disclosures

We may disclose information when reasonably necessary to comply with law or valid legal process; protect a person’s safety, rights, or property; investigate fraud or abuse; enforce agreements; obtain professional legal, tax, accounting, insurance, or security advice; or complete a corporate transaction. We may also disclose information at your direction or with your consent.

06Advertising, sale, and targeted-advertising choices

We do not sell personal information for money. Some privacy laws define “sale,” “sharing,” or “targeted advertising” broadly. When advertising is enabled, making identifiers, page or ad activity, and related advertising information available to Google or participating advertising technology providers for personalized advertising may be considered sale, sharing, or targeted advertising under those laws.

Depending on location, advertising settings, consent, and privacy choices, Google may serve personalized ads, which can use prior activity or inferred interests, or non-personalized ads, which are based primarily on current context and general location. Non-personalized ads may still use cookies or other identifiers for purposes such as frequency capping, aggregated reporting, consent, and fraud prevention.

When advertising is enabled, we use a Google-certified consent management platform integrated with the IAB Europe Transparency & Consent Framework for visitors in the European Economic Area, the United Kingdom, and Switzerland. It identifies participating advertising providers, requests consent for storage or access and personalized advertising where required, communicates choices, and provides a way to revisit or withdraw consent. Advertising handling before or without consent follows the consent platform, Google settings, and applicable law.

When advertising is enabled, an advertising privacy message or other available control provides visitors covered by applicable U.S. state privacy laws with choices concerning sale, sharing, and targeted advertising. We recognize browser-based opt-out preference signals, including Global Privacy Control, where required by applicable law. Because there is no common standard for Do Not Track, that signal alone does not change our processing. An advertising choice does not disable technologies that are strictly necessary to provide and secure the Service; an eligible Free-event page may instead show a non-personalized or restricted ad, or no ad, depending on the applicable settings.

07Cookies, local storage, and advertising technologies

The Service uses cookies, local storage, and similar technologies:

  • Organizer session cookie. The rtm_refresh cookie keeps an Organizer signed in. In production it is Secure, HttpOnly, SameSite=Lax, limited to authentication routes, and expires after seven days. The shorter-lived access token is held in browser memory rather than persistent browser storage.
  • Guest local storage. rtm_device_id is a random identifier used to apply a per-device Guest upload limit. Per-event local-storage entries cache submitted and allowed counts. These entries remain until the browser or user clears them. Clearing them causes the browser to receive a new identifier on its next use; it does not erase the prior server record or restore event-wide capacity.
  • Cloudflare security cookies. Cloudflare may set strictly necessary security cookies, including __cf_bm, to distinguish automated traffic and protect the Service. Cloudflare states that __cf_bm expires after 30 minutes of inactivity and is generated separately for each site rather than acting as a cross-site user identifier.
  • Google advertising technologies. The marketing site uses a non-executing AdSense account-verification meta tag and an authorized-seller record; it does not itself request the AdSense advertising runtime. Eligible Free-event pages may request Google AdSense when advertising is enabled. Google and participating advertising technology providers may set or read first-party or third-party cookies, local storage, or other online identifiers to deliver personalized or non-personalized ads, remember consent and privacy choices, limit repeated ads, measure and report advertising, and detect fraud or invalid traffic. The technologies, names, and retention periods used can vary by browser, device, location, provider, settings, and choices.
  • Consent and privacy messages. The consent management platform and U.S. state privacy messages use or communicate signals that record and apply advertising consent and opt-out choices. Where a message provides a privacy-choices link, visitors can use it to revisit the available choices.

Blocking technologies that are strictly necessary may prevent authentication, uploads, or security checks from working correctly. Refusing optional advertising purposes does not prevent use of the core Service, although an eligible Free-event page may show a non-personalized or restricted ad, or no ad, depending on the applicable settings.

08Media access, retention, and deletion

For the plans described in the Terms of Use, Guest uploads and the optional Guest gallery run from 12:00 a.m. on the event date through 5:00 a.m. the following date in the event’s selected time zone. The plan’s post-event Organizer download period then runs for 2, 14, 30, or 90 calendar days in that selected time zone and ends at 5:00 a.m. on the calculated cutoff date. The Organizer can also access originals while Guest access is open. The exact schedule displayed for the event controls.

Originals, photo thumbnails, video posters, temporary upload objects, and export files are stored privately. Videos and their posters are uploaded from the browser directly to our object-storage provider using a short-lived, upload-specific authorization. Access to stored media requires Service authorization or a short-lived capability. While the Guest gallery and Guest access are open, event-link holders can use short-lived capabilities to access individual originals. The Service does not provide reusable storage credentials, permanent public media URLs, or Guest bulk exports.

At the cutoff, access to event media ends and deletion is queued. Physical cleanup is retryable and may finish later. An Organizer can delete an event early, which ends access immediately and queues cleanup. Deleting an event before Guest access opens releases that event date only if no media reservation or upload has ever existed; otherwise, the date remains used for that Organizer account. Export files expire within 48 hours or at the event cutoff, whichever occurs first.

Media deletion does not delete every related record. We retain different information according to the following criteria:

InformationRetention approach
Completed photo and video originals, thumbnails, and postersUntil early deletion or the event’s fixed media cutoff, followed by retryable cleanup.
In-progress or abandoned upload objectsWhile an upload is processed. An unfinished reservation becomes eligible for retryable cleanup after its short configured reservation period; early event deletion and the event cutoff remain outer deletion triggers.
Export artifactsUntil 48 hours after creation or the event cutoff, whichever occurs first, followed by retryable cleanup.
Guest browser identifiers and cached countsIn the browser until local storage is cleared. Server-side event/device counts may remain after scheduled media deletion to document capacity use, investigate abuse, and preserve operational and audit history.
Account and authentication recordsWhile the account is active and afterward as needed for account security, requests, disputes, and legal obligations. Expired or replaced credentials are kept only as needed for security and abuse prevention.
Event configuration and date-eligibility recordsAs needed to operate the account, preserve the activated event promise, enforce the one-event-per-date rule, document deletion, and resolve disputes. When an event is deleted before Guest access opens and no media reservation or upload has ever existed, its eligibility record is marked released so the date may be reused; a record of that release may remain. Otherwise, a minimal used-date record remains after deletion.
Billing name and address; payment, tax, refund, dispute, and accounting recordsFor paid events only, as required for transaction reconciliation, fraud prevention, accounting and tax obligations, chargebacks, legal claims, and audits. These records survive media deletion.
Policy acceptance, operator actions, security records, support messages, and logsFor as long as reasonably necessary to document consent and actions, secure and troubleshoot the Service, respond to requests, enforce agreements, and meet legal obligations.

When a purpose ends, we delete or de-identify the information unless law, a legal hold, fraud prevention, security, an unresolved dispute, or a restricted backup or provider retention cycle requires longer storage. These criteria consider the information’s amount, nature, sensitivity, risk, purpose, and applicable legal requirements.

09Your privacy choices and rights

Depending on where you live and subject to legal exceptions, you may have the right to ask us to:

  • confirm whether we process your personal information and provide access to it;
  • correct inaccurate information;
  • delete information;
  • provide certain information in a portable format;
  • restrict or object to certain processing;
  • withdraw consent where processing depends on consent; or
  • appeal a decision about a privacy request.

We do not discriminate against a person for exercising an applicable privacy right. When advertising is enabled, the consent or privacy message provides the choices available for a visitor’s location, including a way to revisit consent or an applicable sale, sharing, or targeted-advertising opt-out. Visitors may also use browser or device controls and Google’s My Ad Center; those controls do not replace a site-specific choice where one is offered.

To make a request, email [email protected] with the subject “Roll the Moment Privacy Request.” Organizers should write from the account email. Guests should provide the event link and enough information to identify the relevant upload, such as its approximate upload time or photo number; do not send highly sensitive documents in the first message.

We may need to verify your identity, authority, or relationship to the information and may deny or limit a request when permitted by law, including to protect another person’s privacy, preserve transaction or security evidence, or comply with a legal obligation. An authorized agent may submit a request where applicable law permits, but we may require proof of authority and direct verification with the person concerned. To appeal a denied request, reply to our decision with “Privacy Appeal” in the subject line.

Organizers can delete an individual event through the Service, but there is no self-service account-deletion control. An account-deletion request may result in deletion or de-identification of eligible account data while transaction, policy, date-eligibility, security, and legal records remain under the criteria above. A request cannot retrieve or erase copies of media already saved by Organizers or event-link holders.

You may also complain to the attorney general, privacy regulator, or data-protection authority where you live if that option is available to you.

10Security

We use safeguards designed for the nature of the information we process, including private object storage, access controls, password hashing, digest-only verification and reset tokens, encrypted network transport, short-lived media links, rate limits, and redaction of sensitive log fields. Stripe handles payment-card entry on its hosted checkout.

No system or transmission is completely secure. Protect event links and account credentials, use a unique password, secure your email account, and download wanted media before the event cutoff. If you believe information has been compromised, contact us promptly.

11Children’s privacy

The Service is general-audience and is not directed to children under 13. Children under 13 may not create an account, use an event link, or upload media. Organizers should not distribute event links for use by children under 13.

The Service may contain media depicting or recording children that an eligible adult or older teen uploads with appropriate authority and consent. If you believe a child under 13 has directly provided personal information through the Service, email [email protected]. We will investigate and take the steps required by applicable law, which may include disabling access or deleting the information.

12U.S. operation and international processing

Circle City Coders operates the Service from the United States. We and our providers may process information in the United States and other countries, where privacy protections may differ from those where you live. The linked provider notices describe their international-transfer practices and safeguards.

13Changes to this Notice

We may update this Notice as the Service, providers, or law changes. We will post the revised Notice with a new effective date. If a change materially alters how we use or disclose previously collected personal information, we will provide additional notice or obtain consent when required by law.

14Contact us

For privacy questions or requests:

Circle City Coders LLCAttn: Roll the Moment PrivacyIndianapolis, Indiana, United States[email protected](317) 426-0221
Back to top ↑
Roll the MomentCandid photos from everyone who was there.
HomeAboutFAQContactPrivacyTerms
Follow us

© 2026 Roll the Moment

Made for the moment by Circle City Coders