Privacy Policy

Last updated: July 23, 2026

This policy explains what information Photo Booth CRM collects, why we collect it, the legal grounds we rely on, and the rights you have over it. The short version hasn't changed: we collect what's needed to run the service, we don't sell your data, and your business data stays yours.

Who we are

Photo Booth CRM is operated by Photo Booth CRM, an Ohio business in the United States ("we", "us", "PBC").

For data protection purposes:

Privacy contact: support@photoboothcrm.app — or submit a support ticket from inside the app.

1. Information we collect

From account holders (we are the controller):

From your clients (you are the controller; we process on your behalf):

Submitted through your public booking form or client portal: name, email, phone number, event date and venue address, event details, free-text notes, optional uploaded files or photos, e-signature records (name, IP address, and timestamp on signed contracts), payment status, and consent records (such as SMS opt-in). Card payments are entered on Stripe's hosted checkout and settle directly to your Stripe account — this data never touches our servers.

From website visitors:

2. Why we process it, and our legal bases

Where UK GDPR or EU GDPR applies, we rely on the following legal bases:

PurposeDataLegal basis
Operating the service: storing and displaying your data, generating your public pages, sending booking notificationsAccount + business dataContract (Art. 6(1)(b))
Essential account emails (confirmation, password reset, login codes)Email addressContract
Subscription billing and recordsBilling metadataContract; retention of invoices under legal obligation (Art. 6(1)(c))
Security logging and account protectionSign-in activity, IP, browserLegitimate interests (Art. 6(1)(f)) — keeping accounts secure
First-party, cookieless traffic measurementDerived daily-rotating identifierLegitimate interests — understanding aggregate site usage
Product and lifecycle emails to account owners (welcome, tips, trial reminders, feature updates)Name, email, account statusLegitimate interests for existing customers; every email includes unsubscribe
Google Analytics and Meta Pixel on marketing/signup pagesCookies, device and usage dataConsent (Art. 6(1)(a)), collected via the cookie banner; withdrawable at any time
Responding to support requestsTicket contentsLegitimate interests
Processing your clients' booking dataSee Section 1Performed on your documented instructions as your processor; you are responsible for your own lawful basis toward your clients

We do not use your data for automated decision-making that produces legal or similarly significant effects.

3. Your clients' information

Information your clients submit through your booking form and portal belongs to your business. We process it solely to provide the service to you, under our Data Processing Agreement, which forms part of your contract with us and covers our security measures, confidentiality, subprocessors, breach notification, and deletion obligations. You are the controller of this data: you are responsible for your own privacy notice to your clients, your lawful basis for collecting their information, and how you use it outside the platform.

If you are an event client of a business that uses Photo Booth CRM and want to exercise privacy rights over your booking data, contact that business directly — they control your data. We will assist them in fulfilling your request.

4. Who we share data with (subprocessors and recipients)

We do not sell personal data. We share it only with the service providers listed below, each bound by a data processing agreement. We will give account holders advance notice, in the app, before adding a new subprocessor.

ProviderPurposeLocation / transfer safeguard
SupabaseDatabase, authentication, file storageUnited States; Standard Contractual Clauses
StripeSubscription billing and client payments (Stripe Connect)United States and local entities; DPF / SCCs
VercelHosting, CDN, serverless computeGlobal edge, US HQ; DPF / SCCs
PostmarkTransactional email (account, login, notifications)United States; SCCs
SendGrid (Twilio)Marketing emailUnited States; DPF / SCCs
LoopsProduct and lifecycle email to account ownersUnited States; SCCs
TelnyxSMS deliveryUnited States; SCCs
Cloudflare R2Encrypted backupsUnited States; SCCs
Google (Analytics)Consent-based analytics on marketing/signup pagesUnited States; EU-US / UK Data Privacy Framework
Meta (Pixel)Consent-based ad measurement on marketing/signup pagesUnited States; EU-US / UK Data Privacy Framework

5. International transfers

We are based in the United States, and most of our infrastructure is US-based. Where we transfer personal data of UK or EU individuals outside the UK/EEA, we rely on an approved safeguard: the EU-US and UK Extension to the Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses (with the UK International Data Transfer Addendum) otherwise, as reflected in each provider's data processing agreement. You can request more information about the safeguard applied to a specific transfer via our privacy contact.

6. Cookies and similar technologies

7. Retention and deletion

You can request deletion at any time via a support ticket or our privacy contact — deletion is free and honoured within one month.

8. Your rights

If you are in the UK or EU (and in many other places), you have the right to:

To exercise any right, email support@photoboothcrm.app or submit a support ticket. We will respond within one month and will not charge you. We may need to verify your identity first.

You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your local data protection authority. We'd appreciate the chance to resolve your concern first, but you're not required to contact us before complaining.

California residents: we do not sell personal data for money. Because consent-based advertising tools may involve "sharing" for cross-context behavioral advertising under the CCPA, you can opt out via our cookie banner, your browser's Global Privacy Control signal (which we honour), or by contacting us. We do not knowingly share the personal information of anyone under 16.

Other U.S. state privacy rights: If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or another U.S. state with a comprehensive privacy law, you have similar rights to access, correct, delete, and receive a copy of your personal information, and to opt out of targeted advertising and any "sale" of your data (which you can do through our cookie banner or the Global Privacy Control). You may appeal a decision on your request by contacting us; if we deny your appeal, you may contact your state attorney general. To exercise these rights, email support@photoboothcrm.app. You may use an authorized agent to submit a request on your behalf, with proof of authorization.

9. Text messaging (SMS)

When a business using Photo Booth CRM offers text updates, its clients can opt in on that business's booking form by checking the SMS consent box and providing a mobile number. Opt-in is explicit and optional — you can submit a booking without it. Messages are transactional: booking confirmations, updates, reminders, and replies about your event, sent by that specific business through Photo Booth CRM. Message frequency varies; message and data rates may apply. Reply STOP to opt out at any time, or HELP for help; opting out never affects your booking.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers collected for SMS and SMS opt-in consent data are never sold, rented, or shared for marketing, and are used only to send the transactional messages you agreed to receive.

10. Security

Access to your data requires your login; two-factor authentication is available and recommended. Data is encrypted in transit and at rest, isolation between accounts is enforced at the database level, sensitive operations require fresh verification, and we keep encrypted backups. If a personal data breach occurs that is likely to result in a risk to you, we will notify you and, where required, the relevant supervisory authority without undue delay — and where we act as your processor, we will notify you promptly so you can meet your own obligations to your clients.

11. Children

Photo Booth CRM is a business tool for adults and is not directed to children. We don't knowingly collect personal information from anyone under 18 as an account holder, or under 16 through booking forms. If you believe a child has submitted information, contact us and we'll delete it.

12. Changes to this policy

If this policy changes meaningfully, we'll notify you in the app (and by email for significant changes) before the changes take effect. Earlier versions are available on request.

13. Contact

Photo Booth CRM
support@photoboothcrm.app

Or submit a support ticket from inside the app (account menu → Support). No account? Use our contact form.