Clients, Visitors & Photographers
This Privacy Policy explains how YesMoment.co (“YesMoment,” “we,” “us,” or “our”) collects, uses, stores, shares, transfers and protects personal data when you visit YesMoment.co, create an account, create or view a photographer profile, submit or respond to a photography request, use a Request Room, send or receive an offer, make or receive a booking, make a payment, communicate through the Platform, contact support or otherwise interact with our services.
This Policy applies to website visitors, prospective clients, clients, photographers, photography businesses, account holders and other individuals whose personal data is processed through the YesMoment marketplace (collectively, the “Platform”).
By using the Platform, you acknowledge that this Privacy Policy has been made available to you. Where applicable law requires separate consent for a particular processing activity, we will request that consent separately.
Data Controller: YesMoment.co
Location: Istanbul, Türkiye
General Contact:
info@yesmoment.co
Privacy Requests:
info@yesmoment.co
YesMoment operates an online photography marketplace connecting individuals seeking photography services (“Clients”) with independent photographers and photography businesses (“Photographers”) in destinations around the world.
For personal data for which YesMoment determines the purposes and means of processing, YesMoment acts as the data controller.
Photographers using the Platform are independent service providers. Once a Photographer independently receives and processes personal data for the performance of their own photography services, legal obligations, business records, photograph delivery or direct communications, that Photographer may act as a separate independent data controller for those processing activities.
YesMoment serves Clients and Photographers located in Europe and other jurisdictions. Where the European Union General Data Protection Regulation (“GDPR”) applies to our processing activities, we process personal data in accordance with the applicable requirements of the GDPR.
This may apply even where YesMoment operates from outside the European Economic Area (“EEA”), including where our services are offered to individuals located in the European Union.
Where applicable law requires YesMoment to designate a representative within the European Union, the applicable representative's identity and contact information will be made available through this Policy or another legally appropriate notice.
The information we process depends on how you use YesMoment. We may collect information directly from you, automatically from your interaction with the Platform, from another Platform user involved in a request or booking, and from service providers supporting the transaction.
We may process:
When a Client submits a photography request, we may process information such as:
If you use YesMoment as a Photographer, we may process:
We may process information relating to:
We may process and retain communications connected with the Platform, including:
Communications may be retained or reviewed where reasonably necessary to operate the Platform, facilitate bookings, provide support, investigate suspected fraud, enforce our agreements, protect Users, establish what was agreed between a Client and Photographer, resolve disputes, respond to chargebacks, or protect YesMoment's legal rights.
Where a booking payment is made through YesMoment, payment processing may be performed by an independent payment-service provider.
Full payment-card numbers, card security codes and similar sensitive card credentials are generally entered into the payment provider's payment environment and are not intended to be stored by YesMoment.
We may nevertheless receive, generate and retain transaction-related information including:
We may use these records to confirm bookings, maintain transaction history, prevent fraud and duplicate payments, investigate payment issues, respond to chargebacks, reconcile transactions, provide support, enforce our agreements and comply with legal, accounting or regulatory obligations.
YesMoment may provide private Request Rooms, booking pages or similar interfaces connected to an individual request or booking.
Information displayed or processed may include:
Request Rooms may use unique tokens, URLs or technical identifiers. Users are responsible for not intentionally sharing private booking links, access tokens or account credentials with unauthorized persons.
We may retain technical records associated with these interfaces for security, fraud prevention, transaction integrity, dispute resolution and protection of our legal interests.
Certain information may be generated automatically when you interact with YesMoment.
This may include:
We may use such information to secure the Platform, investigate unauthorized activity, prevent fraud, diagnose technical problems, protect transaction integrity, understand Platform performance and establish evidence relevant to requests, bookings, payments or disputes.
Where technical information can reasonably be linked to an identifiable person, we treat it as personal data where required by applicable law.
Photographers may upload, link to or provide photographs, videos, portfolio material, profile images and other creative content for display through YesMoment.
Such content may itself contain personal data, including images of identifiable individuals.
Photographers are responsible for ensuring that they have an appropriate legal basis, permission, license, model release or other authority required to provide and use such content through the Platform.
YesMoment may process portfolio content for the operation of Photographer profiles, marketplace functionality, technical formatting, promotion of Photographer listings, Platform marketing and other uses permitted by the Photographer's applicable marketplace agreement.
We may remove or restrict content where we receive a legitimate privacy, copyright, image-right or other legal complaint.
We may process personal data for purposes including:
Where GDPR applies, the legal basis we rely on depends on the particular processing activity.
We may process information where necessary to perform a contract or take steps requested by you before entering into a contract, including to:
Where permitted, we may rely on our legitimate interests or those of another party for activities including:
Where required, we balance those interests against the privacy rights and freedoms of the affected individual.
We may process or retain information where necessary to comply with laws or legally binding requirements relating to matters such as taxation, accounting, payment services, consumer protection, regulatory compliance, court orders, data protection or lawful authority requests.
We may rely on consent where applicable law requires it, including for certain non-essential cookies, certain marketing activities or another processing activity for which consent is the appropriate legal basis.
Where processing is based on consent, consent may be withdrawn at any time in accordance with applicable law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
YesMoment does not ordinarily request special categories of personal data as part of its standard marketplace or booking process.
Users should avoid submitting unnecessary information concerning health, racial or ethnic origin, religious or philosophical beliefs, political opinions, biometric information, sexual life, sexual orientation or other legally protected sensitive categories in free-text messages.
If such information is incidentally submitted, we may delete, restrict, minimize or otherwise process it only where a valid legal basis exists and to the extent reasonably necessary under applicable law.
The core purpose of YesMoment requires information to be shared between Clients and Photographers.
When a Client submits a request to, communicates with, receives an offer from or books a Photographer, we may provide the Photographer with information reasonably necessary to respond to and perform the requested service.
This may include:
Likewise, Clients may receive Photographer information necessary to evaluate, communicate with and receive the photography service.
Information may be shared with payment processors, acquiring institutions, banks, card networks, fraud prevention providers and associated financial-service providers where necessary to process, authenticate, verify, refund, investigate or defend a transaction.
We may use third-party technology companies to provide infrastructure necessary to operate YesMoment.
Providers currently or potentially used may include services providing:
Such providers may include platforms such as Webflow, Bubble, Make, Google Workspace and payment providers used by YesMoment from time to time.
Our service-provider relationships and technical infrastructure may change as the Platform develops.
We may share information with lawyers, accountants, auditors, insurers, cybersecurity professionals, payment-dispute advisers and other professional advisers where reasonably necessary.
We may disclose personal data to courts, law enforcement, regulators, tax authorities, data-protection authorities or other government bodies where required or permitted by applicable law.
We may also make disclosures where reasonably necessary to investigate fraud, protect Users, enforce legal rights, respond to legal proceedings or defend YesMoment against a claim.
YesMoment is an international marketplace.
Personal data may therefore be transferred to, accessed from or processed in countries other than the country in which the individual is located.
This may include Türkiye, countries within the European Economic Area, the United States, and countries where Photographers, payment providers or infrastructure providers operate.
For example, a Client located in one European country may request a Photographer located in another country, while technical infrastructure used by YesMoment may operate from additional jurisdictions.
Where GDPR or another applicable law requires safeguards for an international transfer, we will use or rely on an available lawful transfer mechanism as appropriate.
Depending on the circumstances, such mechanisms may include:
We may also assess or implement supplementary safeguards where legally appropriate to the relevant transfer.
Where a request, booking, payment, refund, chargeback, complaint, suspected fraud event or other dispute arises, we may preserve and use information reasonably relevant to investigating, resolving or defending that matter.
Relevant records may include:
Where permitted by law and reasonably necessary, such information may be provided to banks, payment providers, card networks, insurers, professional advisers, courts, regulatory bodies, law enforcement or other parties involved in investigating or resolving the matter.
We retain personal data for no longer than reasonably necessary for the purpose for which it was collected, taking into account contractual, legal, accounting, taxation, security, fraud-prevention and dispute-resolution requirements.
The applicable retention period may depend on the category of information and circumstances surrounding a request or booking.
| Data Category | General Retention Approach |
|---|---|
| Unbooked requests | Normally retained for up to 24 months after the last relevant activity unless a longer period is reasonably required. |
| Photographer accounts and profiles | Retained while the account is active and for a reasonable period following closure where required for marketplace, security, dispute or legal purposes. |
| Confirmed bookings | Retained for the duration necessary for contractual, accounting, tax, dispute, consumer-protection and legal-record requirements. |
| Payment and transaction records | May be retained for extended legal or financial record-keeping periods, including after the session has been completed. |
| Communications | Retained for a reasonable period after the request or booking and longer where relevant to a complaint, dispute, fraud investigation or legal claim. |
| Fraud, chargeback and dispute evidence | Retained until the matter and any applicable legal claim or limitation period has reasonably concluded. |
| Technical and security logs | Retained according to security needs and the operational requirements of the relevant systems. |
When information is no longer reasonably required, it may be deleted, anonymized or securely isolated in accordance with our data-management practices.
A request for deletion does not necessarily require YesMoment to delete information that we are legally required or lawfully entitled to retain, including information necessary for taxation, accounting, fraud prevention, security, legal claims, contractual evidence or regulatory compliance.
We use reasonable technical and organizational measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, disclosure or unauthorized access.
Measures may include, where appropriate:
No internet service, website, database, electronic communication, cloud platform or storage system can be guaranteed to be completely secure.
Users are responsible for maintaining the confidentiality of their own account credentials, Request Room links and private access information.
If a personal-data breach occurs, we will assess the incident and make notifications to affected individuals and/or competent authorities where and when required by applicable law.
YesMoment may use cookies, local storage, session identifiers, pixels and similar technologies to operate, secure, analyze and improve the Platform.
These may be used for:
Analytics tools may help us understand traffic sources, Platform usage, conversion funnels, technical performance, errors and interaction patterns.
Where YesMoment uses advertising, conversion measurement, analytics, remarketing or comparable non-essential technologies, these technologies will be operated subject to applicable cookie and privacy requirements.
Where legally required, non-essential cookies and similar technologies will not be activated until the necessary consent has been obtained.
YesMoment may send communications required to operate a request, Photographer account or confirmed booking.
These may include request notifications, Photographer offers, booking confirmations, payment information, security notices, support replies and service-related reminders.
Such service and transactional communications are different from optional promotional marketing.
Where applicable law requires consent for promotional marketing, we will request the appropriate consent.
Users may unsubscribe from optional promotional emails using the unsubscribe method included in the message or by contacting us.
Opting out of marketing does not prevent YesMoment from sending communications reasonably necessary to operate an account, request, transaction or booking.
Depending on your location, the nature of the processing and applicable law, you may have rights including:
Privacy rights are subject to applicable legal conditions, exceptions and identity-verification requirements.
For example, a request for deletion does not override a legal obligation or lawful basis requiring or permitting YesMoment to maintain payment, accounting, fraud, contractual or litigation-related records.
Requests may be submitted to:
info@yesmoment.co
Subject: Privacy Request
We may request reasonable information to verify the identity of the person making a request before providing, modifying or deleting personal data.
Where GDPR applies, individuals may have the right to lodge a complaint with a competent data-protection supervisory authority, including an authority in the EU Member State of their habitual residence, workplace or where an alleged GDPR infringement occurred, where applicable.
We encourage Users to contact YesMoment first so that we have an opportunity to investigate and respond to the concern, although doing so does not remove a person's right to contact a competent supervisory authority.
YesMoment may use software, rules, filters, search tools, sorting systems or other automated processes to operate and organize marketplace information, such as filtering Photographers by destination, availability, profile information or other relevant criteria.
Unless separately disclosed, YesMoment does not intend to make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect that individual within the meaning of applicable GDPR requirements.
YesMoment accounts and independent bookings are intended for adults aged 18 or older.
Photography sessions may naturally include children, including family photography sessions.
Where an adult Client provides information relating to a child for the legitimate purpose of arranging a photography session, the Client represents that they have appropriate authority to provide information reasonably necessary for that purpose.
Users should not provide unnecessary sensitive information concerning children.
If you believe a minor has independently provided personal data to YesMoment inappropriately, please contact us.
YesMoment may contain or provide links to Photographer websites, Photographer portfolios, Instagram or other social-media profiles, payment services, map services and other independent third-party websites or platforms.
Those third parties may operate under their own privacy policies and independently determine how information provided directly to them is processed.
YesMoment does not control the independent privacy practices of third-party services outside our control.
If YesMoment, its business or relevant assets are involved in a merger, acquisition, restructuring, financing, sale, insolvency process, investment transaction, transfer of assets or similar corporate event, personal data may be reviewed, disclosed or transferred as part of that transaction to the extent permitted by applicable law.
Any recipient of personal data will remain subject to applicable data-protection obligations.
Where permitted by applicable law, YesMoment may process, preserve and use information where reasonably necessary to:
The fact that a User requests deletion or closes an account does not necessarily prevent YesMoment from retaining information reasonably necessary for an unresolved payment, fraud investigation, contractual dispute, legal claim or applicable regulatory obligation.
YesMoment may update this Privacy Policy from time to time as the Platform, marketplace architecture, payment systems, legal requirements, service providers or processing activities change.
The “Last Updated” date at the top of this Policy identifies the current version.
Where required by applicable law, material changes will be communicated by an appropriate method.
We may maintain technical records identifying the version of the Privacy Policy or privacy notice that was presented to a User at a particular time.
YesMoment may maintain compliance records reasonably necessary to demonstrate the operation of its privacy, consent and contractual processes.
Such records may include, where available:
Acknowledgement that a Privacy Policy has been presented is not treated as consent where applicable law requires a separate, freely given consent for a particular processing activity.
Depending on the relevant processing activity, location of the individual and applicable law, YesMoment's processing may be subject to privacy and data-protection legislation including:
Nothing in this Privacy Policy is intended to waive, exclude or restrict a privacy right that cannot lawfully be waived under applicable law.
By submitting information to YesMoment or using Platform functionality after this Privacy Policy has been made available, you acknowledge that you have been informed of the personal-data processing described in this Policy.
Where applicable law requires separate consent for a particular processing activity, your acknowledgement of this Privacy Policy does not replace that consent.
YesMoment may retain reasonable technical and compliance evidence demonstrating when a particular notice, agreement or consent mechanism was presented or completed.