DRAFT - must be reviewed by legal counsel before launch.

Privacy Policy

Last updated: June 17, 2026

How ShootGlow collects, uses, retains, and protects personal information.

Privacy Policy

ShootGlow provides studio management software for photographers and their teams. This policy explains how we collect, use, share, retain, and delete personal information.

1. Scope

This policy applies to:

  • Photographer studios and team members who use ShootGlow.
  • Clients of those studios whose information is processed through ShootGlow workflows.
  • Visitors to ShootGlow-operated web properties.

2. Data We Collect

We collect the following categories of data:

Account and studio data

  • Name, email address, and login identifiers for studio users.
  • Studio profile details, business contact information, and billing profile data.
  • Role and access information needed for multi-tenant permissions.

Client and booking data

  • Client names, email addresses, phone numbers, event/session details, notes, and communication history.
  • Contract metadata and invoice/payment status metadata.

Photo and image data

  • Uploaded image files and derivatives (for example, delivery-resolution or watermarked versions).
  • File metadata needed for processing, storage, and delivery.
  • We may remove metadata (such as EXIF) from delivery variants based on product configuration.

Payments data

  • Payment event metadata and status updates from Stripe (for example, successful payment, failed payment, refund).
  • We do not store full payment card numbers in ShootGlow systems.

Device, usage, and diagnostics data

  • Log data, request metadata, IP address, browser/device details, and feature interaction analytics.
  • Error and performance telemetry used for reliability, abuse prevention, and debugging.

3. How We Use Data

We use data to:

  • Provide core product functionality (bookings, galleries, contracts, messaging, payments workflows).
  • Authenticate users and enforce tenant isolation and role-based access.
  • Process and deliver media assets.
  • Detect fraud, abuse, and service misuse.
  • Support customers and resolve incidents.
  • Improve product performance, usability, and reliability.
  • Meet legal, accounting, tax, and regulatory obligations.

4. Legal Bases (GDPR)

Where GDPR applies, we rely on one or more of the following legal bases:

  • Performance of a contract.
  • Legitimate interests (for example, platform security, product improvement, and abuse prevention).
  • Compliance with legal obligations.
  • Consent, where required for specific processing.

5. CCPA/CPRA Notice

For California residents:

  • We process personal information for business purposes described in this policy.
  • We do not sell personal information in exchange for monetary consideration.
  • We do not share personal information for cross-context behavioral advertising in product workflows.
  • You may request access, deletion, and correction rights subject to legal exceptions.

6. Sub-processors and Service Providers

ShootGlow uses infrastructure and service providers that process data on our behalf, including:

  • Supabase (database/auth infrastructure)
  • Cloudflare (hosting, CDN, storage, edge services)
  • Stripe (payments)
  • Resend (email delivery)
  • Telnyx (SMS delivery)
  • PostHog (product analytics and feature flags)

We use contractual and technical controls to limit processing to authorized purposes.

7. Data Retention

We retain data only as long as necessary for product operation and legal obligations.

Typical retention approach:

  • Active account data: retained while the studio account is active.
  • Client and operational records: retained according to studio settings and legal obligations.
  • Logs and telemetry: retained for operational security and incident response windows.
  • Billing and financial records: retained for tax/accounting compliance periods.

8. Deletion and Data Subject Rights

Depending on applicable law, data subjects may request:

  • Access to personal data.
  • Correction of inaccurate data.
  • Deletion of personal data.
  • Restriction or objection to certain processing.
  • Data portability (where applicable).

Studios can request deletion workflows for client records and associated data, subject to legal retention exceptions.

9. International Transfers

Data may be processed in jurisdictions other than your own. Where required, we use appropriate safeguards for cross-border transfers.

10. Security

We apply administrative, technical, and organizational safeguards designed to protect personal information, including access controls, tenant isolation boundaries, and transport security.

No system is completely risk-free. You are responsible for maintaining your account credentials securely.

11. Children

ShootGlow is not directed to children under 13, and we do not knowingly collect data directly from children in that age group.

12. Changes to this Policy

We may update this policy from time to time. Material updates will be reflected by an updated date and, where appropriate, additional notice.

13. Contact

For privacy requests or questions: