Privacy Policy

Last updated March 2026

This Privacy Notice for Studio Lifesaver LLC ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at hello@studiolifesaver.com.

GOOGLE SERVICES INTEGRATION

In Short: We integrate with Google Calendar and Google Places API to help you manage your photography business schedule and locations. Your Google data is never shared with third parties.

Google Calendar Integration

When you connect your Google Calendar to our Services, we access the following information:

  • Calendar Events: We read your calendar events to check for scheduling conflicts and display your availability
  • Event Creation: We create calendar events for confirmed photography sessions, including session details, location, and client information
  • Event Updates: We update calendar events when session details change (time, location, cancellations)
  • Calendar Metadata: We access calendar names, IDs, and timezone settings to ensure accurate scheduling

How We Use Google Calendar Data:

  • Availability Management: Check for conflicts when clients book sessions to prevent double-booking
  • Automatic Scheduling: Create calendar events automatically when sessions are booked
  • Session Reminders: Sync session times to your Google Calendar for notifications and reminders
  • Calendar Sync: Keep your photography schedule synchronized across all your devices

Google Places API

We use Google Places API to help you and your clients specify session locations:

  • Location Search: Search for addresses, landmarks, and venues when setting up sessions
  • Address Autocomplete: Provide address suggestions as you or your clients type location information
  • Place Details: Retrieve complete address information including street, city, state, and zip code
  • Location Display: Show formatted addresses in calendar invites and session confirmations

How We Use Google Places Data:

  • Store session locations with complete address details for calendar invites
  • Display session locations to you and your clients in a readable format
  • Include clickable addresses in calendar events for easy navigation
  • Enable clients to specify their preferred session location during booking

Google API Data Protection

Studio Lifesaver's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We commit to:

  • No Data Sharing: Never sell, share, or transfer your Google data to third parties
  • Limited Use: Only use your Google data for the specific features you've requested (scheduling, location services)
  • Secure Storage: Store all Google API credentials using industry-standard encryption
  • User Control: You can disconnect Google services at any time from your account settings
  • No Profiling: We do not use your Google Calendar or location data for advertising, analytics, or AI training

To disconnect Google Services:

  1. Go to Settings → Integrations in our app
  2. Click "Disconnect" next to Google Calendar
  3. Your Google data will be immediately deleted from our servers
  4. You can also revoke access directly from your Google Account Permissions

SOCIAL MEDIA PLATFORM DATA

In Short: We collect and process data from Facebook and Instagram to enable you to manage and publish content to your connected social media accounts.

Facebook and Instagram Data Collection

When you connect your Facebook Pages and Instagram Business accounts to our Services, we collect and process the following information:

Facebook Data:

  • Facebook Page information (Page ID, Page name, Page profile picture)
  • Page access tokens for content publishing
  • Basic profile information for account verification
  • Facebook Page permissions and roles

Instagram Data:

  • Instagram Business account information (Account ID, username, profile data)
  • Instagram account access tokens for content publishing
  • Instagram Business account profile pictures and basic metadata
  • Connection status between Instagram accounts and Facebook Pages

Authentication Data:

  • OAuth tokens and refresh tokens for maintaining account connections
  • Token expiration dates and renewal information
  • Account connection status and permissions granted

How We Use Facebook and Instagram Data

We use the collected Facebook and Instagram data for the following purposes:

Account Management:

  • Display your connected Facebook Pages and Instagram accounts in our interface
  • Verify account ownership and permissions
  • Maintain secure connections to your social media accounts
  • Enable account selection for content publishing

Content Publishing:

  • Post images and captions to your selected Facebook Pages
  • Publish content to your connected Instagram Business accounts
  • Schedule future posts to your social media accounts
  • Track posting history and success rates

Your Rights Regarding Social Media Data

You have the right to:

  • Access: Request a copy of all Facebook and Instagram data we've collected about you
  • Correction: Update or correct any inaccurate social media account information
  • Deletion: Request deletion of your social media data by disconnecting accounts in the app's Profiles section or contacting us
  • Portability: Request a copy of your social media data in a portable format
  • Objection: Object to certain processing of your Facebook and Instagram data

Account Disconnection and Data Deletion

To disconnect your Facebook or Instagram accounts:

  1. Go to the Profiles section in our app
  2. Click "Disconnect" next to any connected account
  3. Confirm the disconnection in the popup

When you disconnect an account, we will:

  • Immediately revoke access tokens
  • Stop collecting new data from that platform
  • Retain historical posting data for 30 days for service continuity
  • Permanently delete all associated data after 30 days

PHOTO STORAGE AND AI-POWERED IMAGE ANALYSIS

In Short: Your uploaded photos are securely stored on Amazon Web Services (AWS) cloud infrastructure, delivered globally via CloudFront, and analyzed using Amazon Rekognition for automatic tagging.

Photo Storage and Delivery

When you upload photos to our Services, we use AWS S3 (Simple Storage Service) for secure cloud storage and AWS CloudFront for global content delivery:

  • Storage Location: Photos are stored on AWS S3 in secure, encrypted cloud storage in AWS's US-East-1 region
  • Global Distribution: Photos are distributed via AWS CloudFront's global content delivery network for fast, reliable access worldwide
  • Caching: Images may be temporarily cached across AWS's global edge locations to ensure optimal performance
  • Purpose: Storage and delivery are necessary to enable photo management, organization, and social media publishing features
  • File Formats: We support JPG, PNG, and WebP image formats up to 10MB per file
  • Ownership: All uploaded photos remain your property and can be deleted at any time
  • Security: Photos are stored with encryption at rest and in transit through AWS's secure infrastructure

AI-Powered Auto-Tagging with Amazon Rekognition

We use Amazon Rekognition, an AI-powered image analysis service, to automatically detect and tag content in your photos:

  • Analysis Process: Rekognition analyzes images to identify objects, scenes, activities, landmarks, and other relevant content
  • Benefits: Automatic tagging helps organize your photo library, improves content discovery, and suggests relevant tags for social media posts
  • Timing: Image analysis happens automatically upon upload to provide immediate organization benefits
  • Control: All AI-generated tags can be edited, removed, or supplemented with your own tags at any time
  • Accuracy: While Rekognition provides highly accurate results, AI-generated tags are suggestions and can be manually reviewed

Third-Party Service Provider

Amazon Web Services (AWS) acts as our data processor for photo storage, delivery, and AI analysis:

  • Role: AWS processes photo data on our behalf according to our instructions through S3 (storage), CloudFront (global delivery), and Rekognition (AI analysis)
  • Global Network: CloudFront may temporarily cache your images across AWS's global edge locations to provide fast access worldwide
  • Security Standards: AWS maintains SOC 2, ISO 27001, GDPR compliance, and other industry-leading security certifications
  • Privacy Policy: AWS processes data according to their privacy policy available at https://aws.amazon.com/privacy/
  • Data Processing Agreement: We have data processing agreements with AWS ensuring your data protection rights are maintained
  • Data Retention: AWS retains your photos only as long as you maintain them in our Services or as required by law

Your Photo Data Rights

You have complete control over your photo data:

  • Access: View all stored photos, their metadata, and AI-generated tags at any time
  • Download: Download your original photos at any time from the session detail view
  • Delete: Remove individual photos or delete entire sessions with all associated photos
  • Tag Control: Edit, add, or remove any AI-generated tags
  • Export: Request a complete export of all your photo data and metadata

Note: When you delete a photo, it is permanently removed from AWS S3 storage and CloudFront cache, and cannot be recovered. Deleted photos are also removed from any scheduled social media posts.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by using our table of contents below to find the section you are looking for.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.

Do we process any sensitive personal information? We do not process sensitive personal information.

Do we collect any information from third parties? We collect information from Facebook and Instagram when you connect your social media accounts to our Services.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You. The personal information that we collect may include the following:

Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number, and the security code associated with your payment instrument. All payment data is handled and stored by Stripe. You may find their privacy notice at: https://stripe.com/privacy.

THIRD-PARTY BUSINESS SERVICES

In Short: We use trusted third-party services to process payments, send emails, calculate taxes, and sync accounting data. Your data is shared only as necessary to provide these services.

Stripe (Payment Processing)

We use Stripe to process all payments securely:

  • Data Collected: Payment card details, billing address, transaction history, and payment method tokens
  • Purpose: Process subscription payments, client payments, deposits, and refunds
  • Data Handling: Payment card details are sent directly to Stripe and are never stored on our servers
  • Security: Stripe is PCI-DSS Level 1 certified, the highest level of payment security certification
  • Privacy Policy: stripe.com/privacy

SendGrid (Email Delivery)

We use SendGrid (a Twilio company) to send transactional and business emails on your behalf:

  • Data Shared: Recipient email addresses, email content (invoices, contracts, notifications), sender information, and your custom branding
  • Purpose: Deliver account verification emails, password resets, invoices, contracts, booking confirmations, and other business communications
  • Email Tracking: SendGrid may track email opens and clicks to provide delivery statistics
  • Data Retention: SendGrid retains email metadata for delivery reporting; email content is processed but not permanently stored
  • Custom Domains: If you configure a custom sending domain, DNS verification records are managed through SendGrid
  • Privacy Policy: twilio.com/legal/privacy

QuickBooks (Accounting Integration)

When you connect QuickBooks Online to sync your accounting data:

  • Data Synced to QuickBooks: Client information (name, email, address), invoices, payments, deposits, and product/service details
  • Data Retrieved from QuickBooks: Customer records, payment status, and invoice numbers for synchronization
  • Purpose: Automatically sync your photography business finances with your accounting software to reduce manual data entry
  • Authorization: Connection is established through OAuth 2.0; we never see or store your QuickBooks login credentials
  • Disconnection: You can disconnect QuickBooks at any time from Settings → Integrations; future data will no longer sync
  • Privacy Policy: intuit.com/privacy/statement

TaxJar (Sales Tax Calculation)

We use TaxJar to calculate accurate sales tax for your invoices:

  • Data Shared: Transaction amounts, shipping addresses (city, state, zip code), product categories, and your business nexus locations
  • Purpose: Calculate the correct sales tax rate based on the transaction location and applicable tax rules
  • No Personal Client Data: We do not share client names, email addresses, or other personal identifiers with TaxJar
  • Compliance: TaxJar helps ensure your invoices comply with state and local sales tax requirements
  • Privacy Policy: taxjar.com/privacy-policy

Vercel (Client Portal Hosting)

We use Vercel to host client-facing pages such as invoices, proposals, contracts, and booking pages:

  • Data Processed: Public URLs for client-facing documents, subdomain configurations, and custom domain settings
  • Purpose: Host and deliver your client portal pages (invoices, proposals, contracts) with automatic SSL/TLS encryption
  • Custom Domains: If you configure a custom domain for your client portal, Vercel manages DNS verification and SSL certificate provisioning
  • Edge Network: Your client portal pages may be served from Vercel's global edge network for optimal performance
  • No Sensitive Data Storage: Vercel serves pages dynamically; client payment information and sensitive data are not stored on Vercel
  • Privacy Policy: vercel.com/legal/privacy-policy

Render (Application Hosting)

We use Render to host our core application infrastructure:

  • Data Processed: All application data including user accounts, session information, client records, invoices, and business data flows through Render-hosted services
  • Purpose: Host and run the backend API and admin dashboard that powers all application functionality
  • Data Location: Services are hosted in the United States
  • Security: All data is encrypted in transit using TLS; Render maintains SOC 2 Type II compliance
  • Database Connectivity: Render facilitates secure connections to our MongoDB database infrastructure
  • No Direct Data Storage: Render hosts our application code; persistent data is stored in our separate database infrastructure
  • Privacy Policy: render.com/privacy

Your Rights Regarding Third-Party Data Sharing

You have control over how your data is shared:

  • Opt-Out: You can disconnect QuickBooks integration at any time; other services are essential for platform functionality
  • Data Access: Request a copy of all data shared with third-party services by contacting us
  • Data Deletion: When you close your account, we cease sharing new data with these services
  • Questions: Contact us at hello@studiolifesaver.com for any questions about third-party data sharing

Information automatically collected

In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

3. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.

As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions.

Our AI Products are designed for the following functions:

How We Use AI in Our Services:

4. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.

Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us using the contact details provided below.

Account Information

If you would at any time like to review or change the information in your account or terminate your account, you can:

Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.

STATE-SPECIFIC PRIVACY RIGHTS (U.S.)

Depending on your state of residence, you may have additional privacy rights under state law. This section describes rights available to residents of states with comprehensive privacy laws.

🚫 We Do Not Sell Your Personal Information

Studio Lifesaver does NOT sell or share your personal information with third parties for advertising, marketing, or cross-context behavioral advertising purposes. We do not engage in "sales" of personal information as defined under state privacy laws.

California Residents (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request information about the categories and specific pieces of personal information we collect, use, disclose, and sell
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information (we do not sell/share data)
  • Right to Limit Use: Limit the use of sensitive personal information
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights

Global Privacy Control (GPC): We honor GPC signals sent by your browser as a valid opt-out request.

Authorized Agents: California residents may designate an authorized agent to submit requests on their behalf. We may require verification of the agent's authority.

Virginia, Colorado, Connecticut, Utah, and Other State Residents

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, and others) generally have the following rights:

  • Right to Access: Confirm whether we process your personal data and obtain a copy
  • Right to Correct: Correct inaccuracies in your personal data
  • Right to Delete: Delete your personal data
  • Right to Data Portability: Obtain a copy of your personal data in a portable format
  • Right to Opt-Out: Opt out of targeted advertising, sale of personal data, and profiling

Note: Some states require opt-in consent for processing sensitive personal data. We will obtain your consent before collecting or processing sensitive categories of personal information where required by law.

How to Exercise Your Rights

To submit a verifiable consumer request exercising your privacy rights:

We will respond to verifiable requests within 45 days (or the timeframe required by your state law). You may be required to verify your identity before we can fulfill your request.

5. COOKIES AND SIMILAR TECHNOLOGIES

In Short: We use cookies and similar technologies to operate our services and remember your preferences.

We use cookies and similar tracking technologies (like local storage) to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out below:

Types of Technologies We Use

Managing Cookies: You can manage your cookie preferences through our Privacy Settings page or through your browser settings. Note that disabling certain cookies may affect the functionality of our services.

6. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

You have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information.

To request to review, update, or delete your personal information, including Facebook and Instagram data, please:

CONTACT INFORMATION

If you have questions or comments about this notice, you may email us at hello@studiolifesaver.com or contact us by post at:

Studio Lifesaver LLC

10107 Jefferson Cir N
Atlanta, GA 30341
United States

Privacy Inquiries: privacy@studiolifesaver.com