LEGAL · PRIVACY

Privacy Policy

Clients, Visitors & Photographers

Last Updated: September 2, 2026

This Privacy Policy explains how YesMoment.co (“YesMoment,” “we,” “us,” or “our”) collects, uses, stores, shares, transfers and protects personal data when you visit YesMoment.co, create an account, create or view a photographer profile, submit or respond to a photography request, use a Request Room, send or receive an offer, make or receive a booking, make a payment, communicate through the Platform, contact support or otherwise interact with our services.

This Policy applies to website visitors, prospective clients, clients, photographers, photography businesses, account holders and other individuals whose personal data is processed through the YesMoment marketplace (collectively, the “Platform”).

By using the Platform, you acknowledge that this Privacy Policy has been made available to you. Where applicable law requires separate consent for a particular processing activity, we will request that consent separately.

1. Who We Are

Data Controller: YesMoment.co
Location: Istanbul, Türkiye
General Contact: info@yesmoment.co
Privacy Requests: info@yesmoment.co

YesMoment operates an online photography marketplace connecting individuals seeking photography services (“Clients”) with independent photographers and photography businesses (“Photographers”) in destinations around the world.

For personal data for which YesMoment determines the purposes and means of processing, YesMoment acts as the data controller.

Photographers using the Platform are independent service providers. Once a Photographer independently receives and processes personal data for the performance of their own photography services, legal obligations, business records, photograph delivery or direct communications, that Photographer may act as a separate independent data controller for those processing activities.

2. European Users and GDPR

YesMoment serves Clients and Photographers located in Europe and other jurisdictions. Where the European Union General Data Protection Regulation (“GDPR”) applies to our processing activities, we process personal data in accordance with the applicable requirements of the GDPR.

This may apply even where YesMoment operates from outside the European Economic Area (“EEA”), including where our services are offered to individuals located in the European Union.

Where applicable law requires YesMoment to designate a representative within the European Union, the applicable representative's identity and contact information will be made available through this Policy or another legally appropriate notice.

3. Personal Data We May Collect

The information we process depends on how you use YesMoment. We may collect information directly from you, automatically from your interaction with the Platform, from another Platform user involved in a request or booking, and from service providers supporting the transaction.

3.1 Identity and Contact Information

We may process:

  • full name;
  • display name;
  • email address;
  • telephone number;
  • WhatsApp or other communication details;
  • country or general location;
  • account information;
  • other contact information voluntarily provided.

3.2 Client Request Information

When a Client submits a photography request, we may process information such as:

  • destination or photography location;
  • requested or approximate session date;
  • type of photography session;
  • proposal, engagement, couple, wedding, family or other session details;
  • photography preferences;
  • budget information where requested;
  • special requests;
  • messages submitted to a Photographer;
  • additional information voluntarily provided in free-text fields.

3.3 Photographer Account and Profile Information

If you use YesMoment as a Photographer, we may process:

  • name and business name;
  • email address and telephone number;
  • city, country and service locations;
  • profile photograph;
  • biography;
  • languages;
  • portfolio links;
  • website and social-media links;
  • starting prices;
  • services offered;
  • response and account information;
  • verification information where applicable;
  • Photographer offers and package descriptions;
  • booking history;
  • commercial or commission information associated with the Photographer account;
  • account status and Platform activity.

3.4 Marketplace Activity

We may process information relating to:

  • Photographer profiles viewed or selected;
  • requests submitted or received;
  • offers submitted or received;
  • offer prices;
  • package descriptions;
  • request status;
  • booking status;
  • booking history;
  • session date;
  • session destination;
  • Request Room interactions;
  • support activity;
  • other actions necessary to operate the marketplace.

3.5 Communications

We may process and retain communications connected with the Platform, including:

  • Client messages to Photographers;
  • Photographer messages relating to Clients;
  • support requests;
  • booking communications;
  • email correspondence;
  • complaints;
  • cancellation requests;
  • rescheduling requests;
  • payment disputes;
  • other marketplace communications.

Communications may be retained or reviewed where reasonably necessary to operate the Platform, facilitate bookings, provide support, investigate suspected fraud, enforce our agreements, protect Users, establish what was agreed between a Client and Photographer, resolve disputes, respond to chargebacks, or protect YesMoment's legal rights.

4. Booking and Payment Information

Where a booking payment is made through YesMoment, payment processing may be performed by an independent payment-service provider.

Full payment-card numbers, card security codes and similar sensitive card credentials are generally entered into the payment provider's payment environment and are not intended to be stored by YesMoment.

We may nevertheless receive, generate and retain transaction-related information including:

  • total session price;
  • booking payment amount;
  • remaining balance;
  • currency;
  • payment status;
  • payment identifier;
  • transaction identifier;
  • payment token or technical reference;
  • booking reference;
  • transaction timestamps;
  • payment completion information;
  • payment failure information;
  • refund information;
  • chargeback information;
  • fraud or verification results supplied by payment providers.

We may use these records to confirm bookings, maintain transaction history, prevent fraud and duplicate payments, investigate payment issues, respond to chargebacks, reconcile transactions, provide support, enforce our agreements and comply with legal, accounting or regulatory obligations.

5. Request Rooms and Private Booking Links

YesMoment may provide private Request Rooms, booking pages or similar interfaces connected to an individual request or booking.

Information displayed or processed may include:

  • Client information;
  • Photographer information;
  • session information;
  • messages;
  • offers;
  • package information;
  • total session price;
  • booking payment;
  • remaining balance;
  • payment status;
  • booking status;
  • booking confirmation;
  • support communications.

Request Rooms may use unique tokens, URLs or technical identifiers. Users are responsible for not intentionally sharing private booking links, access tokens or account credentials with unauthorized persons.

We may retain technical records associated with these interfaces for security, fraud prevention, transaction integrity, dispute resolution and protection of our legal interests.

6. Technical, Device and Security Data

Certain information may be generated automatically when you interact with YesMoment.

This may include:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • referring page or campaign;
  • pages or features accessed;
  • session identifiers;
  • timestamps;
  • request identifiers;
  • booking identifiers;
  • authentication records;
  • error and diagnostic information;
  • security logs;
  • interaction and navigation information;
  • information reasonably necessary to detect suspicious activity.

We may use such information to secure the Platform, investigate unauthorized activity, prevent fraud, diagnose technical problems, protect transaction integrity, understand Platform performance and establish evidence relevant to requests, bookings, payments or disputes.

Where technical information can reasonably be linked to an identifiable person, we treat it as personal data where required by applicable law.

7. Portfolio and Photography Content

Photographers may upload, link to or provide photographs, videos, portfolio material, profile images and other creative content for display through YesMoment.

Such content may itself contain personal data, including images of identifiable individuals.

Photographers are responsible for ensuring that they have an appropriate legal basis, permission, license, model release or other authority required to provide and use such content through the Platform.

YesMoment may process portfolio content for the operation of Photographer profiles, marketplace functionality, technical formatting, promotion of Photographer listings, Platform marketing and other uses permitted by the Photographer's applicable marketplace agreement.

We may remove or restrict content where we receive a legitimate privacy, copyright, image-right or other legal complaint.

8. Why We Process Personal Data

We may process personal data for purposes including:

  • operating the YesMoment marketplace;
  • creating and maintaining accounts;
  • displaying Photographer profiles;
  • receiving photography requests;
  • routing requests to relevant Photographers;
  • allowing Photographers to respond;
  • delivering and updating offers;
  • facilitating bookings;
  • processing and verifying booking payments;
  • confirming reservations;
  • facilitating Client–Photographer communications;
  • providing customer and Photographer support;
  • sending transactional communications;
  • administering cancellations and rescheduling;
  • resolving complaints and disputes;
  • preventing fraud, spam and abuse;
  • detecting unauthorized activity;
  • protecting Platform security;
  • preventing manipulation or circumvention of Platform systems;
  • maintaining booking and transaction records;
  • enforcing our Terms and marketplace agreements;
  • establishing, exercising and defending legal claims;
  • complying with lawful authority requests;
  • meeting accounting, tax and regulatory obligations;
  • improving the reliability and usability of the Platform;
  • measuring marketplace and business performance.

9. GDPR Legal Bases

Where GDPR applies, the legal basis we rely on depends on the particular processing activity.

9.1 Contract and Pre-Contractual Steps

We may process information where necessary to perform a contract or take steps requested by you before entering into a contract, including to:

  • create and operate an account;
  • submit or receive photography requests;
  • provide Photographer profiles;
  • submit or receive offers;
  • facilitate bookings;
  • operate Request Rooms;
  • provide transaction-related functionality;
  • provide requested support.

9.2 Legitimate Interests

Where permitted, we may rely on our legitimate interests or those of another party for activities including:

  • preventing fraud and abuse;
  • protecting Clients and Photographers;
  • securing the Platform;
  • maintaining transaction records;
  • investigating complaints;
  • preventing Platform manipulation or fee circumvention;
  • improving marketplace operations;
  • protecting our business and legal rights;
  • establishing, exercising or defending legal claims.

Where required, we balance those interests against the privacy rights and freedoms of the affected individual.

9.3 Legal Obligations

We may process or retain information where necessary to comply with laws or legally binding requirements relating to matters such as taxation, accounting, payment services, consumer protection, regulatory compliance, court orders, data protection or lawful authority requests.

9.4 Consent

We may rely on consent where applicable law requires it, including for certain non-essential cookies, certain marketing activities or another processing activity for which consent is the appropriate legal basis.

Where processing is based on consent, consent may be withdrawn at any time in accordance with applicable law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

10. Sensitive and Special Category Information

YesMoment does not ordinarily request special categories of personal data as part of its standard marketplace or booking process.

Users should avoid submitting unnecessary information concerning health, racial or ethnic origin, religious or philosophical beliefs, political opinions, biometric information, sexual life, sexual orientation or other legally protected sensitive categories in free-text messages.

If such information is incidentally submitted, we may delete, restrict, minimize or otherwise process it only where a valid legal basis exists and to the extent reasonably necessary under applicable law.

11. Who We Share Information With

11.1 Clients and Photographers

The core purpose of YesMoment requires information to be shared between Clients and Photographers.

When a Client submits a request to, communicates with, receives an offer from or books a Photographer, we may provide the Photographer with information reasonably necessary to respond to and perform the requested service.

This may include:

  • Client name;
  • session destination;
  • session date;
  • request details;
  • Client messages;
  • booking information;
  • contact details where appropriate for the relevant stage of the booking.

Likewise, Clients may receive Photographer information necessary to evaluate, communicate with and receive the photography service.

11.2 Payment Providers

Information may be shared with payment processors, acquiring institutions, banks, card networks, fraud prevention providers and associated financial-service providers where necessary to process, authenticate, verify, refund, investigate or defend a transaction.

11.3 Technology and Infrastructure Providers

We may use third-party technology companies to provide infrastructure necessary to operate YesMoment.

Providers currently or potentially used may include services providing:

  • website hosting;
  • application hosting;
  • databases;
  • workflow automation;
  • email services;
  • cloud storage;
  • analytics;
  • communications;
  • payment processing;
  • fraud prevention;
  • security and monitoring.

Such providers may include platforms such as Webflow, Bubble, Make, Google Workspace and payment providers used by YesMoment from time to time.

Our service-provider relationships and technical infrastructure may change as the Platform develops.

11.4 Professional Advisers

We may share information with lawyers, accountants, auditors, insurers, cybersecurity professionals, payment-dispute advisers and other professional advisers where reasonably necessary.

11.5 Authorities

We may disclose personal data to courts, law enforcement, regulators, tax authorities, data-protection authorities or other government bodies where required or permitted by applicable law.

We may also make disclosures where reasonably necessary to investigate fraud, protect Users, enforce legal rights, respond to legal proceedings or defend YesMoment against a claim.

12. International Data Transfers

YesMoment is an international marketplace.

Personal data may therefore be transferred to, accessed from or processed in countries other than the country in which the individual is located.

This may include Türkiye, countries within the European Economic Area, the United States, and countries where Photographers, payment providers or infrastructure providers operate.

For example, a Client located in one European country may request a Photographer located in another country, while technical infrastructure used by YesMoment may operate from additional jurisdictions.

Where GDPR or another applicable law requires safeguards for an international transfer, we will use or rely on an available lawful transfer mechanism as appropriate.

Depending on the circumstances, such mechanisms may include:

  • an applicable adequacy decision;
  • European Commission Standard Contractual Clauses;
  • contractual data-protection safeguards;
  • another transfer mechanism permitted by applicable law;
  • a legally available derogation for a specific transfer where appropriate.

We may also assess or implement supplementary safeguards where legally appropriate to the relevant transfer.

13. Fraud, Chargebacks, Complaints and Legal Claims

Where a request, booking, payment, refund, chargeback, complaint, suspected fraud event or other dispute arises, we may preserve and use information reasonably relevant to investigating, resolving or defending that matter.

Relevant records may include:

  • the original photography request;
  • Photographer offer;
  • accepted package information;
  • booking confirmation;
  • payment records;
  • transaction identifiers;
  • communications;
  • Request Room activity;
  • timestamps;
  • security records;
  • IP information where available;
  • delivery or service evidence;
  • correspondence with Clients or Photographers.

Where permitted by law and reasonably necessary, such information may be provided to banks, payment providers, card networks, insurers, professional advisers, courts, regulatory bodies, law enforcement or other parties involved in investigating or resolving the matter.

14. Data Retention

We retain personal data for no longer than reasonably necessary for the purpose for which it was collected, taking into account contractual, legal, accounting, taxation, security, fraud-prevention and dispute-resolution requirements.

The applicable retention period may depend on the category of information and circumstances surrounding a request or booking.

Data Category General Retention Approach
Unbooked requests Normally retained for up to 24 months after the last relevant activity unless a longer period is reasonably required.
Photographer accounts and profiles Retained while the account is active and for a reasonable period following closure where required for marketplace, security, dispute or legal purposes.
Confirmed bookings Retained for the duration necessary for contractual, accounting, tax, dispute, consumer-protection and legal-record requirements.
Payment and transaction records May be retained for extended legal or financial record-keeping periods, including after the session has been completed.
Communications Retained for a reasonable period after the request or booking and longer where relevant to a complaint, dispute, fraud investigation or legal claim.
Fraud, chargeback and dispute evidence Retained until the matter and any applicable legal claim or limitation period has reasonably concluded.
Technical and security logs Retained according to security needs and the operational requirements of the relevant systems.

When information is no longer reasonably required, it may be deleted, anonymized or securely isolated in accordance with our data-management practices.

A request for deletion does not necessarily require YesMoment to delete information that we are legally required or lawfully entitled to retain, including information necessary for taxation, accounting, fraud prevention, security, legal claims, contractual evidence or regulatory compliance.

15. Security

We use reasonable technical and organizational measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, disclosure or unauthorized access.

Measures may include, where appropriate:

  • encrypted network transmission;
  • authentication;
  • access controls;
  • restricted administrative access;
  • transaction logging;
  • service-provider security controls;
  • security monitoring;
  • technical and organizational reviews.

No internet service, website, database, electronic communication, cloud platform or storage system can be guaranteed to be completely secure.

Users are responsible for maintaining the confidentiality of their own account credentials, Request Room links and private access information.

If a personal-data breach occurs, we will assess the incident and make notifications to affected individuals and/or competent authorities where and when required by applicable law.

16. Cookies and Similar Technologies

YesMoment may use cookies, local storage, session identifiers, pixels and similar technologies to operate, secure, analyze and improve the Platform.

16.1 Essential Technologies

These may be used for:

  • Platform functionality;
  • authentication;
  • security;
  • Request Room continuity;
  • booking flows;
  • fraud prevention;
  • maintaining necessary application state.

16.2 Analytics

Analytics tools may help us understand traffic sources, Platform usage, conversion funnels, technical performance, errors and interaction patterns.

16.3 Advertising and Marketing Technologies

Where YesMoment uses advertising, conversion measurement, analytics, remarketing or comparable non-essential technologies, these technologies will be operated subject to applicable cookie and privacy requirements.

Where legally required, non-essential cookies and similar technologies will not be activated until the necessary consent has been obtained.

17. Marketing Communications

YesMoment may send communications required to operate a request, Photographer account or confirmed booking.

These may include request notifications, Photographer offers, booking confirmations, payment information, security notices, support replies and service-related reminders.

Such service and transactional communications are different from optional promotional marketing.

Where applicable law requires consent for promotional marketing, we will request the appropriate consent.

Users may unsubscribe from optional promotional emails using the unsubscribe method included in the message or by contacting us.

Opting out of marketing does not prevent YesMoment from sending communications reasonably necessary to operate an account, request, transaction or booking.

18. Your GDPR and Privacy Rights

Depending on your location, the nature of the processing and applicable law, you may have rights including:

  • the right to be informed about processing;
  • the right to request access to your personal data;
  • the right to request correction of inaccurate data;
  • the right to request erasure in applicable circumstances;
  • the right to request restriction of processing;
  • the right to object to certain processing;
  • the right to data portability where applicable;
  • the right to withdraw consent where processing relies on consent;
  • the right to object to certain direct marketing;
  • rights relating to certain automated decision-making where applicable;
  • the right to lodge a complaint with a competent supervisory authority.

Privacy rights are subject to applicable legal conditions, exceptions and identity-verification requirements.

For example, a request for deletion does not override a legal obligation or lawful basis requiring or permitting YesMoment to maintain payment, accounting, fraud, contractual or litigation-related records.

Requests may be submitted to:

info@yesmoment.co
Subject: Privacy Request

We may request reasonable information to verify the identity of the person making a request before providing, modifying or deleting personal data.

19. European Supervisory Authorities

Where GDPR applies, individuals may have the right to lodge a complaint with a competent data-protection supervisory authority, including an authority in the EU Member State of their habitual residence, workplace or where an alleged GDPR infringement occurred, where applicable.

We encourage Users to contact YesMoment first so that we have an opportunity to investigate and respond to the concern, although doing so does not remove a person's right to contact a competent supervisory authority.

20. Automated Processing and Matching

YesMoment may use software, rules, filters, search tools, sorting systems or other automated processes to operate and organize marketplace information, such as filtering Photographers by destination, availability, profile information or other relevant criteria.

Unless separately disclosed, YesMoment does not intend to make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect that individual within the meaning of applicable GDPR requirements.

21. Children's Privacy

YesMoment accounts and independent bookings are intended for adults aged 18 or older.

Photography sessions may naturally include children, including family photography sessions.

Where an adult Client provides information relating to a child for the legitimate purpose of arranging a photography session, the Client represents that they have appropriate authority to provide information reasonably necessary for that purpose.

Users should not provide unnecessary sensitive information concerning children.

If you believe a minor has independently provided personal data to YesMoment inappropriately, please contact us.

22. Third-Party Websites and Independent Services

YesMoment may contain or provide links to Photographer websites, Photographer portfolios, Instagram or other social-media profiles, payment services, map services and other independent third-party websites or platforms.

Those third parties may operate under their own privacy policies and independently determine how information provided directly to them is processed.

YesMoment does not control the independent privacy practices of third-party services outside our control.

23. Business Transfers and Corporate Transactions

If YesMoment, its business or relevant assets are involved in a merger, acquisition, restructuring, financing, sale, insolvency process, investment transaction, transfer of assets or similar corporate event, personal data may be reviewed, disclosed or transferred as part of that transaction to the extent permitted by applicable law.

Any recipient of personal data will remain subject to applicable data-protection obligations.

24. Protection of YesMoment, Clients and Photographers

Where permitted by applicable law, YesMoment may process, preserve and use information where reasonably necessary to:

  • protect the Platform;
  • protect Clients;
  • protect Photographers;
  • enforce YesMoment agreements;
  • prevent fraudulent requests;
  • prevent fraudulent bookings;
  • investigate payment abuse;
  • prevent unauthorized access;
  • detect misuse of Platform systems;
  • investigate deliberate marketplace circumvention;
  • respond to complaints;
  • respond to chargebacks;
  • establish evidence of requests, offers and bookings;
  • establish, exercise or defend legal rights.

The fact that a User requests deletion or closes an account does not necessarily prevent YesMoment from retaining information reasonably necessary for an unresolved payment, fraud investigation, contractual dispute, legal claim or applicable regulatory obligation.

25. Changes to This Privacy Policy

YesMoment may update this Privacy Policy from time to time as the Platform, marketplace architecture, payment systems, legal requirements, service providers or processing activities change.

The “Last Updated” date at the top of this Policy identifies the current version.

Where required by applicable law, material changes will be communicated by an appropriate method.

We may maintain technical records identifying the version of the Privacy Policy or privacy notice that was presented to a User at a particular time.

26. Records of Notice, Consent and Acceptance

YesMoment may maintain compliance records reasonably necessary to demonstrate the operation of its privacy, consent and contractual processes.

Such records may include, where available:

  • applicable Privacy Policy version;
  • Terms or agreement version;
  • date and time a notice was presented;
  • date and time consent was given or withdrawn;
  • account or request identifier;
  • booking identifier;
  • technical transaction records;
  • IP or security information where legally appropriate;
  • other information reasonably necessary to demonstrate compliance.

Acknowledgement that a Privacy Policy has been presented is not treated as consent where applicable law requires a separate, freely given consent for a particular processing activity.

27. Applicable Data Protection Laws

Depending on the relevant processing activity, location of the individual and applicable law, YesMoment's processing may be subject to privacy and data-protection legislation including:

  • Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), where applicable;
  • Türkiye's Law No. 6698 on the Protection of Personal Data (“KVKK”), where applicable;
  • other mandatory data-protection or privacy laws that apply to a particular processing activity.

Nothing in this Privacy Policy is intended to waive, exclude or restrict a privacy right that cannot lawfully be waived under applicable law.

28. Contact

YesMoment.co Istanbul, Türkiye Privacy & Data Protection info@yesmoment.co Subject: Privacy Request

Acknowledgement

By submitting information to YesMoment or using Platform functionality after this Privacy Policy has been made available, you acknowledge that you have been informed of the personal-data processing described in this Policy.

Where applicable law requires separate consent for a particular processing activity, your acknowledgement of this Privacy Policy does not replace that consent.

YesMoment may retain reasonable technical and compliance evidence demonstrating when a particular notice, agreement or consent mechanism was presented or completed.

© YesMoment.co
Privacy Policy Version 2026-09-02