Start for free

Badges and data privacy: where do your guests' photos end up?

As soon as guests and speakers are asked to upload a photo for their badge, the data-privacy question comes up, at the latest from your own legal team. What helps most then is a simple rule: data that is never collected in the first place, you have to neither protect nor explain. This page shows which data actually arises with badges from OneClickBadge. Whether everything fits for your event as a whole is something you settle with your data-protection advisors; the technical basis for it is here.

The principle: what never arises, you don't have to protect

The usual route to images for event marketing collects data at every turn: portraits come in by email, sit in a folder, travel to the agency, and in the end no one remembers where all the copies are dozing. Each of these stops is a data flow you have to explain, secure and eventually clean up again.

Data minimization flips the logic around: the tool is built so the most sensitive data never reaches you at all. For a badge that means, in concrete terms, that each person places their own photo and publishes the result themselves. You design the badge and send out a link, and you never get to see your guests' faces.

The concrete answer: the badge is made in the browser

When a guest opens your link and picks their photo, that photo is sent to no server. Even removing the background, demanding enough that you might suspect an upload, runs on the person's own device. The finished badge is rendered locally and downloaded straight as a file, and with the animated badge the video export happens in the browser too.

The face only becomes public once the person loads the finished image into their post themselves, on their own channel, by their own decision. For your guests' most common question there is an answer that fits in one sentence: your photo stays on your device.

1
Pick a photo
Stays in the browser, no upload.
2
The device does the work
Background removal and rendering run locally.
3
Post it yourself
Only your own post makes the image public.

The one exception: the name on the certificate

With the attendance certificate, one spot looks different, and it deserves to be named honestly: the name a person writes onto their certificate, we store on the server, because otherwise their personal certificate page would no longer be reachable once they close the tab. There is no photo on the certificate.

The publicly verifiable credential behind it, an assertion following Open Badges 2.0, gets by without an email address or other direct contact details; the name sits on the linked certificate page, where the person entered it themselves. And if a certificate ever has to be withdrawn, the credential link reports the revocation. How the standard works in detail is here.

What is left for you as the organizer

You never touch your guests' photos: no collecting by email, no folder of portraits, no handing them to service providers. On our servers sits your event design, meaning template, colors and text, and for the certificate the entered name for the credential page. The details are laid out transparently in the privacy policy.

So what mostly remains of the whole data-privacy topic is what sits with you anyway: your own communication. How to turn the self-posted images into reach for your event is shown in the guide to promoting your event.

Related

Frequently asked questions

Is OneClickBadge GDPR-compliant?
The architecture is built for data minimization: badge photos are not uploaded, recipients need no account, and for the certificate only the entered name is stored. A blanket guarantee of compliance is something no tool can give you, though, because the full picture also includes your own processes, from the invitation email to the registration list. Which data we process is set out in full in the privacy policy.
Does OneClickBadge store your guests' finished badges?
No. The personalized badge is rendered in the browser and downloaded directly. On our servers sits the organizer's design, meaning the template, colors and text of the event, and for the certificate additionally the entered name for the credential page.
Doesn't background removal need a server?
No, it runs on the person's device right in the browser, just like the video export of the animated badge. The photo does not leave the browser even for the background removal, it just takes a moment longer than a click depending on the device.
Does the badge page set cookies?
Not on the badge page itself: the badge is made in the browser, with no account and no login for recipients that a profile could be pinned to. We set no tracking or advertising cookies anywhere. Protection against automated access (Cloudflare Turnstile) runs only in two places, when creating an event and when redeeming a certificate, and there it may set technically necessary cookies. On the way from the link to the finished badge, your guests never meet it.

Sources