Privacy Policy
This policy explains what information Photo Booth CRM collects, why we collect it, the legal grounds we rely on, and the rights you have over it. The short version hasn't changed: we collect what's needed to run the service, we don't sell your data, and your business data stays yours.
Who we are
Photo Booth CRM is operated by Photo Booth CRM, an Ohio business in the United States ("we", "us", "PBC").
For data protection purposes:
- For account holders (photo booth business owners — "you"), we are the controller of your account data.
- For your clients' information submitted through your booking forms and client portal, you are the controller and we are your processor, acting on your instructions under our Data Processing Agreement (see Section 3).
Privacy contact: support@photoboothcrm.app — or submit a support ticket from inside the app.
1. Information we collect
From account holders (we are the controller):
- Account information: your name, email address, phone number, and password (stored securely hashed — we never see your password).
- Business information: business name, business address, tax/VAT number where you provide one, packages, pricing, templates, calendar events, branding, and settings.
- Billing information: payment and payout details are collected and held by our payment processor, Stripe. We receive only limited billing metadata (plan, subscription status, renewal date) — we never see or store your full card number or bank details.
- Security activity: sign-ins, sign-outs, and security setting changes, including the IP address and browser they came from. This log is visible to you on your Security page.
- Support and feature requests: messages you send us through the in-app forms.
- Usage information: how you use the product, to keep it reliable and improve it.
From your clients (you are the controller; we process on your behalf):
Submitted through your public booking form or client portal: name, email, phone number, event date and venue address, event details, free-text notes, optional uploaded files or photos, e-signature records (name, IP address, and timestamp on signed contracts), payment status, and consent records (such as SMS opt-in). Card payments are entered on Stripe's hosted checkout and settle directly to your Stripe account — this data never touches our servers.
From website visitors:
- First-party traffic measurement: on our public marketing homepage we count visits, pages viewed, referring site, and device type. This is cookieless: to estimate unique visitors we derive a short-lived code from your IP address and browser that rotates daily. We do not store your raw IP address.
- Advertising and analytics tools (consent-based): on our public marketing and signup pages we use Google Analytics and the Meta Pixel to understand traffic and measure our ads. In the UK and EU, these tools do not load unless you consent via our cookie banner, and you can decline as easily as accept or withdraw consent at any time via Cookie Settings. Where they run, they set their own cookies and receive device and usage data; if you submit an email on our signup form with consent given, it is hashed in your browser and shared with Meta for ad measurement (advanced matching). These tools never run inside your account dashboard or on your clients' booking forms.
- Region detection: we determine your approximate country from your connection via a third-party IP lookup (geojs.io) to show the correct regional experience. Your IP address is not stored for this purpose.
2. Why we process it, and our legal bases
Where UK GDPR or EU GDPR applies, we rely on the following legal bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Operating the service: storing and displaying your data, generating your public pages, sending booking notifications | Account + business data | Contract (Art. 6(1)(b)) |
| Essential account emails (confirmation, password reset, login codes) | Email address | Contract |
| Subscription billing and records | Billing metadata | Contract; retention of invoices under legal obligation (Art. 6(1)(c)) |
| Security logging and account protection | Sign-in activity, IP, browser | Legitimate interests (Art. 6(1)(f)) — keeping accounts secure |
| First-party, cookieless traffic measurement | Derived daily-rotating identifier | Legitimate interests — understanding aggregate site usage |
| Product and lifecycle emails to account owners (welcome, tips, trial reminders, feature updates) | Name, email, account status | Legitimate interests for existing customers; every email includes unsubscribe |
| Google Analytics and Meta Pixel on marketing/signup pages | Cookies, device and usage data | Consent (Art. 6(1)(a)), collected via the cookie banner; withdrawable at any time |
| Responding to support requests | Ticket contents | Legitimate interests |
| Processing your clients' booking data | See Section 1 | Performed on your documented instructions as your processor; you are responsible for your own lawful basis toward your clients |
We do not use your data for automated decision-making that produces legal or similarly significant effects.
3. Your clients' information
Information your clients submit through your booking form and portal belongs to your business. We process it solely to provide the service to you, under our Data Processing Agreement, which forms part of your contract with us and covers our security measures, confidentiality, subprocessors, breach notification, and deletion obligations. You are the controller of this data: you are responsible for your own privacy notice to your clients, your lawful basis for collecting their information, and how you use it outside the platform.
If you are an event client of a business that uses Photo Booth CRM and want to exercise privacy rights over your booking data, contact that business directly — they control your data. We will assist them in fulfilling your request.
4. Who we share data with (subprocessors and recipients)
We do not sell personal data. We share it only with the service providers listed below, each bound by a data processing agreement. We will give account holders advance notice, in the app, before adding a new subprocessor.
| Provider | Purpose | Location / transfer safeguard |
|---|---|---|
| Supabase | Database, authentication, file storage | United States; Standard Contractual Clauses |
| Stripe | Subscription billing and client payments (Stripe Connect) | United States and local entities; DPF / SCCs |
| Vercel | Hosting, CDN, serverless compute | Global edge, US HQ; DPF / SCCs |
| Postmark | Transactional email (account, login, notifications) | United States; SCCs |
| SendGrid (Twilio) | Marketing email | United States; DPF / SCCs |
| Loops | Product and lifecycle email to account owners | United States; SCCs |
| Telnyx | SMS delivery | United States; SCCs |
| Cloudflare R2 | Encrypted backups | United States; SCCs |
| Google (Analytics) | Consent-based analytics on marketing/signup pages | United States; EU-US / UK Data Privacy Framework |
| Meta (Pixel) | Consent-based ad measurement on marketing/signup pages | United States; EU-US / UK Data Privacy Framework |
Law enforcement and legal requests. We may also disclose information if required by law, or to protect the rights, safety, or security of the service, our users, or others. We disclose personal data to authorities only when we are legally required to and the request is valid and properly scoped. For U.S. legal process we look to the Stored Communications Act framework: a subpoena for basic account information, a court order for non-content records, and a search warrant for content. We do not hold full card or bank details — those requests should go to Stripe. Where permitted, we notify the affected account holder before disclosing their information, unless a valid non-disclosure order or an emergency involving a risk of death or serious injury applies. On a valid preservation request we will preserve specified data for up to 90 days while legal process is obtained. Send legal requests to support@photoboothcrm.app with "Legal Request" in the subject line; we review each one and will object to requests that are invalid, unclear, or overbroad.
5. International transfers
We are based in the United States, and most of our infrastructure is US-based. Where we transfer personal data of UK or EU individuals outside the UK/EEA, we rely on an approved safeguard: the EU-US and UK Extension to the Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses (with the UK International Data Transfer Addendum) otherwise, as reflected in each provider's data processing agreement. You can request more information about the safeguard applied to a specific transfer via our privacy contact.
6. Cookies and similar technologies
- Inside your account: essential browser storage only — keeping you signed in and remembering preferences like dark mode and filters. No advertising trackers.
- Marketing and signup pages: non-essential cookies (Google Analytics, Meta Pixel) load only with your consent in the UK and EU, managed through our cookie banner and changeable any time via Cookie Settings. Our homepage traffic count is cookieless and first-party.
- Each cookie and its purpose is described in this section; you can accept, decline, or withdraw consent at any time.
- Do Not Track and Global Privacy Control: because there is no common industry standard for "Do Not Track" browser signals, we do not respond to them; however, we honour the Global Privacy Control (GPC) signal as an opt-out of sharing personal information for targeted advertising.
7. Retention and deletion
- Account and business data: kept while your account is active. Within 30 days of account deletion or subscription termination, your profile, bookings, public pages, uploads, and related records are deleted.
- Billing records: retained for 7 years to meet tax and accounting obligations.
- Security logs: retained for 12 months.
- Backups: encrypted backups are retained for 30 days on a rolling basis; deleted data ages out of backups within that window, and backups are never used to restore deleted records except for disaster recovery.
- Your clients' data: retained according to your instructions and deleted when you delete it, when you delete your account, or at contract end per the DPA.
You can request deletion at any time via a support ticket or our privacy contact — deletion is free and honoured within one month.
8. Your rights
If you are in the UK or EU (and in many other places), you have the right to:
- Access the personal data we hold about you, and receive a copy;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten");
- Port your data — receive it in a structured, machine-readable format;
- Object to processing based on legitimate interests, including direct marketing (which we will always stop on request);
- Restrict processing in certain circumstances;
- Withdraw consent at any time where processing is based on consent (e.g. cookies), without affecting prior processing.
To exercise any right, email support@photoboothcrm.app or submit a support ticket. We will respond within one month and will not charge you. We may need to verify your identity first.
You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your local data protection authority. We'd appreciate the chance to resolve your concern first, but you're not required to contact us before complaining.
California residents: we do not sell personal data for money. Because consent-based advertising tools may involve "sharing" for cross-context behavioral advertising under the CCPA, you can opt out via our cookie banner, your browser's Global Privacy Control signal (which we honour), or by contacting us. We do not knowingly share the personal information of anyone under 16.
Other U.S. state privacy rights: If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or another U.S. state with a comprehensive privacy law, you have similar rights to access, correct, delete, and receive a copy of your personal information, and to opt out of targeted advertising and any "sale" of your data (which you can do through our cookie banner or the Global Privacy Control). You may appeal a decision on your request by contacting us; if we deny your appeal, you may contact your state attorney general. To exercise these rights, email support@photoboothcrm.app. You may use an authorized agent to submit a request on your behalf, with proof of authorization.
9. Text messaging (SMS)
When a business using Photo Booth CRM offers text updates, its clients can opt in on that business's booking form by checking the SMS consent box and providing a mobile number. Opt-in is explicit and optional — you can submit a booking without it. Messages are transactional: booking confirmations, updates, reminders, and replies about your event, sent by that specific business through Photo Booth CRM. Message frequency varies; message and data rates may apply. Reply STOP to opt out at any time, or HELP for help; opting out never affects your booking.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers collected for SMS and SMS opt-in consent data are never sold, rented, or shared for marketing, and are used only to send the transactional messages you agreed to receive.
10. Security
Access to your data requires your login; two-factor authentication is available and recommended. Data is encrypted in transit and at rest, isolation between accounts is enforced at the database level, sensitive operations require fresh verification, and we keep encrypted backups. If a personal data breach occurs that is likely to result in a risk to you, we will notify you and, where required, the relevant supervisory authority without undue delay — and where we act as your processor, we will notify you promptly so you can meet your own obligations to your clients.
11. Children
Photo Booth CRM is a business tool for adults and is not directed to children. We don't knowingly collect personal information from anyone under 18 as an account holder, or under 16 through booking forms. If you believe a child has submitted information, contact us and we'll delete it.
12. Changes to this policy
If this policy changes meaningfully, we'll notify you in the app (and by email for significant changes) before the changes take effect. Earlier versions are available on request.
13. Contact
Photo Booth CRM
support@photoboothcrm.app
Or submit a support ticket from inside the app (account menu → Support). No account? Use our contact form.