← Back to PhotoCRM

Privacy Policy

Last Updated: March 2026

PhotoCRM ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our photography business management platform at photocrm.io (the "Service"). By using PhotoCRM, you agree to the collection and use of information in accordance with this policy.

Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address
  • Full name
  • Password (encrypted via Clerk authentication)
  • Organization/business name
  • Profile information you choose to provide

1.2 Client Data

When you use PhotoCRM to manage your photography business, we store:

  • Client names, email addresses, phone numbers, and physical addresses
  • Project details, status, and notes
  • Communication history between you and your clients
  • Client portal access information

1.3 Financial Information

For optional storage upgrades and invoice management:

  • Payment information processed securely through Stripe (we do not store credit card numbers)
  • Billing address and tax information
  • Invoice data including amounts, payment status, and transaction history
  • Account details and storage usage

1.4 Media Files

We store the media files you upload to PhotoCRM:

  • Photographs and images in various formats
  • Video files
  • Documents and other project-related files
  • Metadata associated with uploaded files (filename, size, upload date)
  • Generated thumbnails and optimized versions

Files are stored securely in Cloudflare R2 storage with encryption at rest and in transit.

1.5 Cloud Integration Data

When you connect third-party cloud storage services:

  • OAuth access tokens for Google Drive and Microsoft OneDrive
  • Folder and file metadata from connected services
  • Sync status and storage usage information

We only access the specific folders and files you authorize. You can revoke access at any time through your account settings.

1.6 Usage and Analytics Data

We automatically collect information about how you use PhotoCRM:

  • Log data (IP address, browser type, device information)
  • Pages visited and features used
  • Performance metrics and error reports
  • Storage usage statistics
  • Google Analytics data (you can opt out via browser settings)

1.7 Team Member Data

For multi-user accounts (teams):

  • Team member names and email addresses
  • Role assignments (Owner, Admin, Member, View-Only)
  • Permission settings and access levels
  • Activity logs for audit purposes

How We Use Your Information

We use the collected information for the following purposes:

Service Delivery

To provide, maintain, and improve PhotoCRM's features including client management, project tracking, file storage, invoicing, and client portals.

Account Management

To create and manage your account, process optional storage upgrades, and provide customer support.

Communication

To send transactional emails (invoice notifications, project updates, password resets) and optional marketing communications (you can unsubscribe anytime).

Security and Fraud Prevention

To detect and prevent fraud, unauthorized access, and other security threats.

Analytics and Improvement

To understand how users interact with PhotoCRM and improve our features, performance, and user experience.

Legal Compliance

To comply with legal obligations, respond to lawful requests, and enforce our Terms of Service.

Data Sharing and Disclosure

3.1 We Do NOT Sell Your Data

PhotoCRM does not sell, rent, or trade your personal information or client data to third parties for their marketing purposes.

3.2 Service Providers

We share data with trusted third-party service providers who help us operate PhotoCRM:

  • Clerk - Authentication and user management
  • Stripe - Payment processing and subscription billing
  • Cloudflare R2 - Secure file storage
  • MongoDB Atlas - Database hosting
  • Vercel - Application hosting and deployment
  • Resend - Transactional email delivery
  • Google Analytics - Usage analytics (anonymized data)

These providers are contractually obligated to protect your data and only use it for the specific services they provide to us.

3.3 Client Portal Access

When you share project files with your clients through client portals, your clients can access the specific project information and files you authorize. This is an intended feature of the Service.

3.4 Legal Requirements

We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

3.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email and/or prominent notice on our website before your information becomes subject to a different privacy policy.

Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: All data is encrypted in transit using TLS/SSL and at rest in our storage systems
  • Authentication: Secure authentication via Clerk with support for multi-factor authentication (MFA)
  • Access Controls: Role-based access controls (RBAC) with 25+ granular permissions to limit data access
  • Tenant Isolation: Complete data separation between organizations in our multi-tenant architecture
  • Regular Backups: Automated daily backups of all data with disaster recovery procedures
  • Infrastructure Security: Hosting on secure, SOC 2 compliant infrastructure (Vercel, Cloudflare, MongoDB Atlas)
  • Monitoring: Continuous security monitoring and logging of access attempts

Important: While we implement robust security measures, no system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and should use strong, unique passwords.

Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:

  • Active Accounts: Your data is retained while your account is active
  • Account Deletion: When you delete your account, we permanently delete your data within 30 days
  • Legal Requirements: We may retain certain information as required by law (e.g., tax records for 7 years)
  • Backup Systems: Data in backup systems may persist for up to 90 days after deletion
  • Anonymous Analytics: Aggregated, anonymized analytics data may be retained indefinitely

Your Rights and Choices

You have the following rights regarding your personal information:

Access and Portability

You can access, download, and export your data at any time through your account settings. Contact us at support@photocrm.io for a complete data export.

Correction

You can update or correct your account information and client data directly through the PhotoCRM interface.

Deletion

You can delete your account and all associated data from your account settings. This action is permanent and cannot be undone.

Marketing Opt-Out

You can unsubscribe from marketing emails by clicking the "unsubscribe" link in any marketing email. You will still receive transactional emails necessary for the Service.

Cookie Management

You can manage cookies through your browser settings. Note that disabling certain cookies may limit your ability to use some features of PhotoCRM.

Third-Party Integrations

You can disconnect Google Drive or OneDrive integrations at any time from your settings. This will revoke PhotoCRM's access to your cloud storage.

International Data Transfers

PhotoCRM operates globally and your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your country. By using PhotoCRM, you consent to the transfer of your information to these countries. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

Children's Privacy

PhotoCRM is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us at support@photocrm.io and we will take steps to delete such information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on this page with a new "Last Updated" date
  • Sending an email notification to the address associated with your account
  • Displaying a prominent notice within PhotoCRM

Your continued use of PhotoCRM after the effective date of the updated Privacy Policy constitutes your acceptance of the changes.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

PhotoCRM Privacy Team

Email:

Website: https://photocrm.io

We will respond to your inquiry within 30 days.

Acknowledgment

By using PhotoCRM, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by its terms. If you do not agree with this Privacy Policy, please do not use PhotoCRM.

Privacy Policy - PhotoCRM