Privacy Policy
Last updated 9 August 2026
PhotoPortal is software photographers use to run their studios. This page explains exactly what the app collects, why it needs it, who processes it on our behalf, and how to get it removed. It describes what the software actually does — not a generic template.
Who we are
“PhotoPortal”, “we” and “us” means the developer of the PhotoPortal mobile and web applications. PhotoPortal is a technology provider: photographers use it to run their own businesses. We are not a marketplace, and we are not the merchant of record for sessions you book.
This matters for your data. When you book a session, the photographer you booked with is the business you are dealing with, and they control the client relationship. We provide the software that holds it.
What we collect
Depending on whether you use PhotoPortal as a photographer or as a client:
Account and profile
- Email address and password (the password is stored hashed by Firebase Authentication — we never see it).
- Display name, full name, and studio name.
- Profile and cover photographs, if you upload them.
- Phone number, if you provide one.
Business and session data
- Bookings: session type, date, time, location, notes, and price.
- Contracts, including your signature and the date you signed.
- Invoices, payment records, and refund or dispute records.
- Messages you send to the other party through the app.
- Addresses and shoot locations, including their geocoded coordinates.
Photographs
- Images you upload — portfolio work, delivered galleries, feed posts, moodboards — and their dimensions.
Device and technical
- Push notification tokens, so the app can tell you a gallery is ready.
- Approximate device location, only while a weather forecast for a shoot is being looked up. It is used for that lookup and not stored.
- Analytics, crash reports, and performance data, including device identifiers.
Why we collect it
| What | Why |
|---|---|
| Email, password | To create and secure your account, and to contact you about your bookings. |
| Name, studio name, profile photos | To identify you to the people you work with, and to build a photographer’s public storefront. |
| Bookings, contracts, invoices | To operate the service you are using, and to keep the financial records the law requires. |
| Photographs | To store and deliver the work — the core purpose of the product. |
| Locations and geocoding | To show where a shoot is and give directions. |
| Device location | Only to fetch a weather forecast for a scheduled shoot. |
| Push tokens | To notify you about bookings, payments and gallery deliveries. |
| Analytics and crash data | To find and fix faults, and to understand which parts of the app are used. |
Photographs, and who can see them
Photographs are the most sensitive thing this app holds, so it is worth being precise about visibility:
- Delivered galleries are private to the photographer who delivered them and the client they belong to. Access is enforced by our database rules, not by an unlisted link alone.
- Portfolio images, storefront content, packages and feed posts are public. A photographer publishes these deliberately, and anyone with the link can see them without signing in.
- Photographers control their clients’ galleries. If you are a client, the photographer you booked with can see, replace and remove the images in your gallery.
Payments
Payments run through Stripe. Photographers connect their own Stripe account and are paid directly into it; we take a platform fee on each transaction. Card data is collected by Stripe in their own payment form and is never sent to or stored on our servers.
Stripe processes your payment information under Stripe’s privacy policy. For identity and bank details supplied during photographer payout onboarding, Stripe is the controller of that verification data.
Who else sees your data
We do not sell your personal information, and we do not share it for advertising. We use the following service providers to run the product:
| Provider | What they handle |
|---|---|
| Google Firebase | Authentication, database, file storage, server functions, analytics, crash reporting, push messaging |
| Stripe | Payments, payouts, and photographer identity verification |
| Google Maps Platform | Turning shoot addresses into map coordinates and directions |
| Expo | Delivering push notifications to mobile devices |
We may also disclose information where we are legally required to, or to protect the safety of a person.
How long we keep it
- Account and profile data is kept while your account is open, and deleted when you delete your account.
- Photographs are kept while your account is open. When a photographer’s account is deleted, their clients are notified to download delivered galleries, which are then kept for 30 days before permanent removal.
- Booking, invoice and payment records are retained in anonymised form after account deletion, because financial and tax record-keeping requires it. Your personal details are stripped from them.
- Backups. Deleted data can persist in secure backups for up to about 14 days before being overwritten.
Your choices and rights
You can, at any time:
- See and correct your profile information in the app or on this site.
- Delete your account and data — in the app under Account, or via our data deletion page if you can no longer sign in.
- Turn off notifications in your notification preferences, or in your device settings.
- Turn off location access in your device settings. Only the weather feature uses it.
- Ask for a copy of the personal data we hold about you, by emailing us.
Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including rights to object to or restrict processing. Email us and we will honour them.
Children
PhotoPortal accounts are for adults. You must be 18 or older to create one, and we do not knowingly collect personal information from children as account holders.
Photographs of children may appear in galleries — family and newborn sessions are ordinary photography work. Those images are uploaded and controlled by the photographer, who is responsible for having the consent of a parent or guardian. If you believe an image of your child is held here without your consent, email us and we will remove it.
Security
Data is encrypted in transit and at rest by our infrastructure providers. Access to each record is enforced by server-side database and storage rules, so one photographer cannot read another’s bookings and one client cannot read another’s gallery. Financial records are writable only by our servers, never by an app.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
Changes to this policy
If we change how we handle your data, we will update this page and change the date at the top. Material changes will also be surfaced in the app.
Contact us
Privacy questions, data requests, and complaints: privacy@photoportal.app.