Privacy Policy

Last updated: September 10, 2026

How ShootGlow collects, uses, retains, and protects personal information.

Privacy Policy

ShootGlow (“ShootGlow,” “we,” “us,” or “our”) provides studio management software for photographers and their teams. This Privacy Policy explains how we collect, use, share, retain, and delete personal information when you use ShootGlow websites, apps, and related services (the “Service”).

If you have questions, contact us using the details in §15.

1. Roles and Scope

Who this policy covers

  • Studio owners and team members who create or use a ShootGlow account.
  • Clients and other individuals whose information studios process through the Service (for example, bookings, contracts, galleries, invoices, and messages).
  • Visitors to ShootGlow-operated marketing and product web properties.

Controller vs processor

  • ShootGlow as controller (or “business”): We decide how to process account, billing, support, security, product-analytics (where permitted), and website visitor data needed to operate ShootGlow as a SaaS product.
  • ShootGlow as processor (or “service provider”): When a studio stores or processes its clients’ personal information in ShootGlow, the studio is typically the controller/business, and we process that data on the studio’s instructions to provide the Service.

Studios are responsible for providing their own notices to clients where required and for having a lawful basis to upload client information.

2. Personal Information We Collect

We collect information in three ways: you provide it, it is generated by use of the Service, or it is received from service providers and integrations you enable.

Account and studio data

  • Name, email address, authentication identifiers, and profile details.
  • Studio profile information, business contact details, branding assets, and settings.
  • Role, membership, and permission data for multi-tenant access control.
  • Support communications and feedback you send us.

Client and booking data (studio-controlled)

  • Client names, email addresses, phone numbers, addresses, event/session details, notes, tags, questionnaires, and communication history.
  • Contract, invoice, order, and payment-status metadata associated with studio workflows.

Photo and media data

  • Uploaded images and derivatives (for example, delivery-resolution or watermarked versions).
  • File and processing metadata needed for storage, transformation, and delivery.
  • Product configuration may strip certain metadata (such as EXIF) from delivery variants.

Payments and billing data

  • ShootGlow subscription billing identifiers, plan entitlements, invoices, and payment event metadata from Stripe.
  • Studio client payment event metadata when Stripe Connect (or another configured processor) is used.
  • We do not store full payment card numbers in ShootGlow systems; card data is handled by the payment processor.

Device, usage, diagnostics, and security data

  • Log data, request metadata, IP address, approximate location derived from IP, browser/device details, and feature interaction events.
  • Error, performance, and reliability telemetry.
  • Bot-protection signals (for example, Cloudflare Turnstile) on protected forms.

Cookies and similar technologies

We use essential cookies and local storage required for authentication, security, and preferences. Non-essential analytics cookies/tools (such as PostHog) are used only where permitted by your cookie preference choice. You can change preferences via the Cookie preferences control on our sites.

3. How We Use Personal Information

We use personal information to:

  • Provide, operate, secure, and support the Service.
  • Authenticate users and enforce tenant isolation and role-based access.
  • Process bookings, contracts, messaging, media delivery, and payments workflows.
  • Bill for ShootGlow subscriptions and manage entitlements, trials, and plan changes.
  • Detect, investigate, and prevent fraud, abuse, spam, and security incidents.
  • Analyze product usage and improve reliability and usability (subject to cookie consent where required).
  • Communicate service, transactional, and (where permitted) marketing messages.
  • Comply with law, enforce our Terms, and protect rights, safety, and property.

We do not use studio client photo libraries to train public generative AI models.

4. How We Share Information

We share personal information only as needed to operate the Service:

  • Service providers / sub-processors that host or process data on our behalf (see §6).
  • Payment processors (Stripe) for subscription billing and, where used by a studio, client payments via Connect.
  • Studios and authorized team members within a tenant, according to roles the studio configures.
  • Clients and recipients the studio chooses to message or grant gallery / portal access to.
  • Legal and safety disclosures when required by law, legal process, or to protect ShootGlow, users, or the public from harm, fraud, or security risk.
  • Business transfers as part of a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising in product workflows.

5. Legal Bases (GDPR / UK GDPR)

Where European data-protection law applies, we rely on one or more of:

  • Contract — to provide the Service you request.
  • Legitimate interests — for example platform security, abuse prevention, service improvement, and essential operations, balanced against your rights.
  • Legal obligation — tax, accounting, and compliance requirements.
  • Consent — where required (for example certain cookies or marketing).

You may withdraw consent where processing is consent-based without affecting the lawfulness of prior processing.

6. Sub-processors and Service Providers

We use infrastructure and service providers that process data to deliver the Service, including:

  • Supabase (database and authentication infrastructure)
  • Cloudflare (hosting, CDN, storage/R2, edge security, Turnstile)
  • Stripe (payments and billing)
  • Resend (email delivery)
  • Telnyx (SMS delivery)
  • PostHog (product analytics and feature flags, subject to cookie preferences)
  • Trigger.dev (background job processing)
  • GlitchTip (application error tracking)

We use contractual and technical controls intended to limit processing to authorized purposes. A current list may also be provided on request to privacy@shootglow.com.

7. SMS and Messaging

Where SMS is enabled for a studio workflow (for example one-time passcodes or transactional notifications):

  • Message frequency varies by the studio’s configuration and your interactions.
  • Message and data rates may apply.
  • Reply STOP to opt out of SMS from that program (where supported by the carrier pathway); reply HELP for help.
  • Opting out of SMS does not opt you out of essential email account or billing notices related to an existing relationship.

Studios remain responsible for obtaining any required consent before messaging their clients. Full program details (purpose, opt-in, HELP/STOP, and rates) are published on the public SMS Terms page linked from the marketing footer.

8. Data Retention

We retain personal information only as long as needed for the purposes described in this policy, including:

  • Active account data — while the studio account remains active and for a reasonable period afterward for reactivation, disputes, and backups.
  • Client and operational records — according to studio settings, product retention controls, and legal obligations.
  • Logs and telemetry — for security, debugging, and reliability windows.
  • Billing and financial records — for tax, accounting, and legal retention periods.

When retention ends, we delete or de-identify information, subject to legal holds, security backups, and fraud-prevention needs.

9. Your Rights and Choices

Depending on where you live, you may have rights to:

  • Access the personal information we hold about you.
  • Correct inaccurate personal information.
  • Delete personal information.
  • Restrict or object to certain processing.
  • Portability of certain data.
  • Opt out of marketing emails (unsubscribe links are included where required).
  • Manage cookie preferences for non-essential analytics.

Studio clients: If your information was uploaded by a photography studio, start with that studio — they are usually the controller. We will assist studios with verified requests as required.

ShootGlow account holders / visitors: Email privacy@shootglow.com. We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising privacy rights.

10. California Privacy Notice (CCPA/CPRA)

For California residents, the categories of personal information we collect are described in §2 (identifiers; commercial information; internet/electronic activity; audio/visual information such as session photos where provided; professional or employment-related information for studio users when provided).

We collect these categories for the business purposes in §3. We disclose them to service providers as in §4 and §6.

  • We do not sell personal information.
  • We do not share personal information for cross-context behavioral advertising in product workflows.
  • We do not use or disclose sensitive personal information to infer characteristics for advertising.
  • You may request know/access, deletion, and correction rights subject to legal exceptions. Contact privacy@shootglow.com or use in-product deletion tools available to studio admins for client records they control.

Authorized agents may submit requests with proof of authorization. We may deny requests that we cannot verify.

11. International Transfers

ShootGlow is operated from the United States. Personal information may be processed in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer safeguards (such as standard contractual clauses or equivalent mechanisms).

12. Security

We apply administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, tenant isolation boundaries, and monitoring for abuse.

No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and for configuring appropriate team access within your studio.

13. Children

The Service is directed to businesses and professionals. It is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. If you believe a child has provided us personal information, contact privacy@shootglow.com and we will take appropriate steps.

Studios that photograph minors are responsible for obtaining any required parental/guardian consent for their own client relationships.

14. Changes to this Policy

We may update this Privacy Policy from time to time. We will revise the “Last updated” date on the policy page and, for material changes, provide additional notice as appropriate (for example in-product or by email to account holders).

15. Contact

For privacy requests or questions:

  • Email: privacy@shootglow.com
  • Postal address: ShootGlow Privacy Team, 2000 Oakley Park Rd #200, Commerce, MI 48390, United States