Privacy Policy
Effective: August 9, 2026
Hey Photo Friend ("we", "us", "our") provides software for photographers to run in-person sales sessions, deliver client galleries, and manage their studio. This Privacy Policy explains what information we collect, how we use it, and who we share it with. By using our services or this website, you agree to the practices described here.
1. Information we collect
- Account information. Email address, name, business name, profile photo, and authentication identifiers when you sign up.
- Photos you upload. Photographs you (or your clients) upload for processing, presentation, or delivery. We store these on encrypted cloud infrastructure on your behalf.
- Client information you enter. Names, email addresses, phone numbers, and session details for the clients you serve. You are the data controller for this information; we process it on your behalf.
- Payment information. When you subscribe or process a client payment, payment card data is handled directly by Stripe or Square. We never see or store full card numbers.
- Usage data. Pages visited, features used, device and browser type, IP address, and approximate location. Used to improve the product and diagnose issues.
- Order approvals. When a client approves an order, we record their typed name, a signature image if drawn, the IP address the approval came from, and a snapshot of the terms shown to them. This is the evidence that an order was authorised.
- Support conversations. Messages you send to our in-app assistant or support team, retained so we can answer follow-ups.
- Waitlist signups. If you join our waitlist, we collect your name and email address.
2. How we use information
- Provide and operate the services you signed up for
- Authenticate your account and protect it from abuse
- Process payments and manage subscriptions
- Send service emails (receipts, security notices, product updates you opted into)
- Improve product features and fix bugs
- Comply with legal obligations
3. Third-party sub-processors
We use trusted third-party services to operate. Each has its own privacy policy.
- Clerk — user authentication and session management. Privacy policy
- Supabase — database hosting and file storage for galleries and session data. Privacy policy
- Cloudflare — CDN, R2 object storage for original photos, and Turnstile for bot/abuse protection on our public forms. Cloudflare Privacy Policy. By using our forms protected by Turnstile, you also agree to the Cloudflare Turnstile Privacy Addendum.
- Stripe and Square — payment processing for subscriptions and client orders. Stripe · Square
- ActiveCampaign — email delivery for waitlist and marketing emails. Privacy policy
- HighLevel (HPF CRM) — CRM integration for photographers who choose to connect it. Privacy policy
- Sentry — error monitoring and performance tracking. PII is scrubbed before transmission where possible. Privacy policy
- Vercel — web hosting and analytics. Privacy policy
- Resend — delivery of transactional email (invoices, order notifications, support replies, account notices). Privacy policy
- Anthropic — powers the in-app Photo Friend assistant. The messages you type to the assistant, and the conversation history in that thread, are sent to Anthropic to generate a reply. Your photographs, client records and order data are never sent. Anthropic does not train models on this content. Privacy policy
- Calendly — scheduling for coaching calls, for photographers who book one. Privacy policy
We will update this list before adding a new sub-processor that handles personal data. If you have a data processing agreement with us, see the DPA for how changes are notified.
4. Cookies and similar technologies
We use cookies and similar local-storage technologies to keep you signed in, remember preferences, measure aggregate usage, and protect against abuse. You can clear or disable cookies in your browser, but some features may stop working.
5. Data retention
- Account data: kept while your account is active. Deleted within 30 days of account closure on request.
- Full-resolution originals: automatically and permanently deleted 90 days after a session is archived. Downsized previews and thumbnails are kept so the session stays viewable.
- Sessions, orders, invoices and album designs: kept indefinitely while your account is active, so your studio history and accounting stay intact. Removed when you erase a client (see below) or close your account.
- Audit and security logs: 365 days, for incident response.
- Backups and disaster-recovery snapshots: up to 30 days. Deleted data can persist in a backup until the backup itself expires.
6. Deleting a client's data
If one of your clients asks you to delete their data, you can do it yourself from the Clients page. Before anything is removed we show you exactly what will go — how many sessions, photographs and files. There are two options:
- Erase personal data. Permanently deletes every photograph and the underlying files, along with notes, favourites, album designs and the client's name, email and phone. Order and payment records are kept, detached from the person.
- Delete everything. Also removes the orders. We block this when the client has paid orders unless you confirm you understand what is being destroyed.
We recommend the first option, and it is the one most laws expect. Records of money that actually changed hands are financial records, and tax and accounting rules generally require keeping them for several years. A deletion request is satisfied by destroying the personal information — the photographs, the contact details, the notes — not by erasing the fact that a sale happened. Deletions are logged so you can evidence that a request was honoured.
Deletion is immediate and irreversible in the live system. Copies may remain in encrypted backups until those expire, up to 30 days.
7. Security
We use industry-standard practices including encryption in transit (TLS), encryption at rest, row-level access controls in our database, multi-factor authentication for administrators, and rate limiting + bot challenges on public endpoints. No system is perfectly secure, but we work hard to protect your information.
8. Your rights
Depending on where you live (GDPR, CCPA, and similar laws), you may have the right to access, correct, delete, or export your personal information, and to object to certain processing. To exercise these rights, email privacy@heyphotofriend.com. We respond within 30 days.
If you are a photographer using Hey Photo Friend, you are the data controller for your clients' information and we are your processor. Our Data Processing Agreement sets out that relationship, and requests from your clients should come to you rather than to us.
9. Children
The service is intended for users 18 and older. We do not knowingly collect personal information from children under 13. Photographers using our platform to deliver galleries containing photos of minors are responsible for obtaining appropriate consent from parents or guardians.
10. International data transfers
Our infrastructure providers may store and process data outside your country of residence, including in the United States. We rely on standard contractual clauses and our providers' compliance frameworks where applicable.
11. Changes
We may update this policy as the product evolves. Material changes will be announced via email or a notice on the service. Continued use after a change constitutes acceptance.
12. Contact
Questions, requests, or concerns: privacy@heyphotofriend.com.
Terms of Service · Data Processing Agreement · Back to waitlist