Privacy Policy
Last updated: 28 July 2026
Who we are
Blink Origin - www.helium22.com ("we", "us") operates BlinkOrigin, a stock photo platform. This policy explains what personal data we collect and why, in line with UK GDPR and the Data Protection Act 2018.
Information we collect
- Account data — your name, username (email), optional contact email, password (stored only as a strong one-way hash), your authenticator enrolment and a hashed recovery key. We never store your password or recovery key in readable form.
- Content — photos you upload and the criteria, tags, titles and prices you attach to them.
- Transactions — your credit ledger, purchases and (for authors) sales and payout records. We never hold card numbers or bank details: payments run on Stripe's own systems, and payouts go to your own Stripe account.
- Security logs — sign-in attempts, the IP address and device fingerprint of sign-ins (to alert you to unfamiliar devices), an audit trail of account actions, and contact-form submissions including the sending IP.
How we use it
To run your account and the marketplace; to email you the notifications you'd expect (registration, password changes, receipts, payout confirmations, unfamiliar-device alerts); to prevent abuse (rate limiting, IP blocking); and to meet legal and accounting obligations for sales records. We do not sell personal data and we run no advertising.
Cookies
BlinkOrigin uses only essential and preference cookies: a session cookie that keeps you signed in and holds your basket, small preference cookies remembering your chosen thumbnail size and display currency, and a cookie recording that you have acknowledged this notice. There are no analytics or advertising cookies, and nothing is shared with third parties.
Third parties
Stripe processes payments and payouts under its own privacy policy. Our email notifications are delivered through Microsoft 365. Photos and account data are stored on our own infrastructure and are not shared with data brokers.
How long we keep data
Account data lasts while your account exists; transaction records are retained as long as tax law requires; security logs are pruned on a rolling basis (sign-in attempts after 30 days).
You may close your account at any time from your account page, provided no payout is outstanding. On closure your photos are withdrawn from the library immediately, and closure remains reversible for 60 days so you can change your mind. After 60 days, photos that were never purchased are permanently deleted along with their files, and your personal data is erased: accounts with no sales or purchases are deleted outright, while accounts with transaction history are anonymised so the sale and licence records other users and the law depend on remain intact. Photos that buyers have licensed always stay in the library — their permanent photo IDs and the licences purchased must remain valid.
Your rights
Under UK GDPR you can request access to, correction of, or deletion of your personal data, and you can object to or restrict processing. Contact us via the contact page or at support@helium22.com. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
Changes
We'll update this page when our practices change; the date above always reflects the current version.