Back to registration · Legal Notice
Privacy Policy
Version: 2026-08-18
1. Controller
Thomas Michael Mueller is responsible for the customer portal at RAWCaptureBooth. You can contact us at hello@rawcapturebooth.app or via https://rawcapturebooth.app.
2. Scope of this policy
This Privacy Policy applies to the registration, login and use of the RAWCaptureBooth customer portal. It covers the processing of account data, device assignments, remote actions initiated through the portal, session information and technical server logs.
It also covers the optional remote access to the user interface of a photobooth described in section 5. That feature is not required in order to use the portal.
3. Data processed when you register or use the portal
- account data such as name, email address, password hash, account creation timestamp and the language used during registration;
- proof that you acknowledged this Privacy Policy and accepted the portal terms, including the applicable versions and timestamps;
- session and authentication data required to keep you signed in, including the technically necessary session cookie "rcb_customer_portal";
- device assignments, custom device labels, status information sent by linked photobooths and cockpit clients, and actions you trigger through the portal such as commands or on-device messages;
- records of remote access sessions you open (timestamp, account identifier, name, device name, hostname and IP address), if and to the extent you use the optional remote access;
- the cookie "rcb_access", which is set on the address of the photobooth when you open a remote access session and which carries your time-limited access credential;
- technical communication data such as IP address, request time, browser or client metadata and error logs that are required for secure operation and troubleshooting.
4. Purposes and legal bases
- Art. 6(1)(b) GDPR: to create and operate your portal account, authenticate you, link devices to your account and provide the requested management features;
- Art. 6(1)(c) GDPR: if and to the extent retention or disclosure is required by law;
- Art. 6(1)(f) GDPR: to protect the portal against misuse, secure the infrastructure, investigate incidents, document important operational events including the record of opened remote access sessions, and defend legal claims.
5. Remote access to a photobooth (optional)
Remote access is an additional feature and is not required in order to use the portal. Without it, device status, commands and on-device messages remain fully available. It is set up per device and only if you actively set it up.
Once set up, the user interface of the photobooth is made reachable through a tunnel operated by Cloudflare, Inc. When you open a session, the portal issues a time-limited access credential; a gatekeeper service running on Cloudflare verifies it and sets the cookie "rcb_access" on the address of the photobooth. All traffic of that interface passes through Cloudflare's network, and transport encryption terminates there.
Every session you open is logged: timestamp, account identifier, name, device name, hostname and IP address. The purpose of that record is to be able to establish who accessed a photobooth and when. It is limited to a fixed number of the most recent entries; older entries are removed automatically.
The user interface of a photobooth may display pictures of guests. The operator of the photobooth, not the portal, is the controller for those pictures. If you use remote access, you must inform your guests about this route and satisfy yourself that you have a legal basis for it.
If you remove remote access for a device, the tunnel and the address are torn down and the interface is no longer reachable this way. Existing log entries are retained as evidence on the basis of Art. 6(1)(f) GDPR.
6. Recipients
Your data is processed within the portal infrastructure. Where technically necessary, hosting, backup or infrastructure service providers may receive access as processors. Data is only disclosed to third parties if this is required for portal operation, legal compliance or enforcement of claims.
For the optional remote access described in section 5, we use Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, as a processor. The basis is Cloudflare's Data Processing Addendum, which forms part of the agreement for Cloudflare's services.
7. International transfers
The portal is intended to operate within the EU/EEA. If services are used from outside the EU/EEA in individual cases, this should only happen where an adequate protection level or appropriate safeguards are in place.
If you use the optional remote access, personal data is transferred to Cloudflare, Inc. in the United States. Cloudflare states that it is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision (Art. 45 GDPR). In addition, Cloudflare's Data Processing Addendum incorporates the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), which remain in place as a basis should the adequacy decision cease to apply.
8. Retention periods
- Account master data is stored for as long as your customer account exists.
- Information on accepted legal texts is stored for as long as needed to document contract conclusion and compliance.
- Session data is deleted automatically when the session ends or expires.
- The record of opened remote access sessions is limited to a fixed number of the most recent entries; older entries are removed automatically.
- Operational logs and command data are stored only for as long as required for portal operation, support or security purposes, unless longer retention is legally required.
9. Is providing data mandatory?
Registration requires at least a valid email address and a password. Without this data, we cannot create or manage a customer portal account for you.
Remote access to a photobooth is voluntary. If you do not set it up, you can continue to use the portal with all of its other features.
10. Automated decision-making
The portal does not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
11. Your rights
Subject to the applicable legal requirements, you have the right to access, rectification, erasure, restriction of processing, data portability and objection.
You also have the right to lodge a complaint with a supervisory authority. If no more specific authority applies, you can contact Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg at https://www.baden-wuerttemberg.datenschutz.de/.
12. Security and updates
We use technical and organizational measures to protect portal data against unauthorized access, manipulation and loss. If processing changes materially, this Privacy Policy will be updated accordingly.