Back to Home

Privacy Policy

Last updated: September 19, 2026 • Effective date: September 19, 2026

Our Core Privacy Principles

100% Photo Ownership

You and your clients retain full copyright and ownership of all uploaded photographs. We never claim IP rights.

Zero Selling of Data

We never monetize, broker, or sell personal contact details, images, or client lists to third-party advertisers.

Bank-Grade Encryption

All contracts, client invoices, private proofing links, and hi-res image deliveries are protected with end-to-end TLS and AES-256 encryption.

1. Overview & Scope

Welcome to StudioMitra ("we," "our," or "us"). StudioMitra provides a photography studio management platform, client proofing galleries, invoicing, and contract workflow tools. This Privacy Policy explains how information is collected, used, and disclosed when you use our websites, applications, and related services (collectively, the "Services").

This policy applies to studio owners, photographers, studio team members, and the clients or guests who access photography galleries and invoices managed through StudioMitra.

2. Information We Collect

Depending on your interaction with StudioMitra, we may collect the following categories of information:

  • Account & Studio Profile Data: Name, email address, studio name, phone number, brand assets (logos, custom domain configurations), and profile credentials.
  • Client & Booking Records: Client names, email addresses, event dates, photoshoot locations, questionnaires, and signed contracts submitted through your studio workspace.
  • Photographs & Media Metadata: Images, RAW/JPEG assets, gallery collections, album favorites, EXIF metadata (camera model, capture timestamp, resolution), and proofing selections.
  • Billing & Payment Information: Payment transactions processed through certified third-party payment gateways (e.g., Stripe or Razorpay). We do not store complete credit card or CVV information on our servers.
  • Usage & Technical Logs: IP address, device specifications, browser type, operating system, referrers, and diagnostic session analytics.

3. Photo Rights & Ownership

StudioMitra makes zero ownership claims over your content. All photographs, watermark overlays, client portfolios, and intellectual property uploaded to your account remain solely the property of you or your clients.

You grant StudioMitra only the limited license necessary to host, thumbnail, convert, and transmit your images to your designated clients upon your request.

We never use your private galleries to train public AI models or license your photographs to stock libraries.

4. How We Use Information

We process your data strictly to operate, maintain, and enhance the StudioMitra platform, including to:

  • Create and host private, responsive client delivery galleries.
  • Facilitate client proofing, photo favorites selection, and hi-res image downloads.
  • Process client invoices, retainers, and automated payment receipts.
  • Send transactional notifications, booking updates, and contract signature confirmations.
  • Prevent fraudulent activity, spam, and unauthorized gallery access.
  • Provide dedicated customer support and troubleshooting assistance.

6. Payments & Billing Security

All financial transactions, subscription fees, and client payments are routed through PCI-DSS Level 1 compliant processors such as Stripe or Razorpay.

StudioMitra does not capture or store raw credit card numbers, bank account passwords, or CVV security codes. Payment processors handle all sensitive billing data in compliance with financial security regulations.

7. Terms & Conditions

View Full 30-Clause Policy

By accessing or subscribing to StudioMitra, you agree to comply with our Terms of Service. Studio accounts are licensed on a SaaS subscription basis for photography professionals, studios, and authorized team members.

  • Users are responsible for safeguarding account login credentials and two-factor authentication tokens.
  • Content uploaded must not infringe upon third-party copyrights, trademarks, or contain unlawful material.
  • StudioMitra reserves the right to suspend accounts engaged in abusive automated scraping, spam distribution, or fraudulent chargeback activity.
  • Service Level Agreements target 99.9% platform availability, excluding scheduled maintenance windows announced in advance.
Need full details on user rights, billing, cancellations, intellectual property, or grievance redressal?Read Terms & Conditions →

8. Refund & Cancellations Policy

View Full 24-Clause Policy

We believe in total billing transparency for all StudioMitra subscription plans and add-on storage tiers:

  • 14-Day Money-Back Guarantee: New annual studio subscriptions are eligible for a full refund within 14 calendar days of the initial purchase date if you are not completely satisfied.
  • Subscription Cancellations: You may cancel recurring billing at any time from your Studio Dashboard. Your subscription will remain active until the end of the current paid billing cycle with zero penalty fees.
  • Client Invoices & Shoot Retainers: Financial transactions between photographers and their end-clients (e.g. wedding shoot deposits or print store orders) are governed by the photographer's individual studio contract. StudioMitra acts as the technology facilitator.
  • Refund Processing Time: Approved subscription refunds are processed back to the original payment method within 5 to 7 business days.
Need full details on AutoPay mandates, duplicate debits, failed charges, or refund timelines?Read Refund Policy →

9. Chargeback, Dispute & Unauthorized Transaction Policy

View Full 50-Clause Policy

StudioMitra maintains robust dispute mitigation workflows in collaboration with acquiring banks, card networks (Visa, Mastercard, RuPay, Amex), and licensed payment aggregators:

  • Direct Dispute Resolution: Cardholders are encouraged to contact our support team at support@studiomitra.com prior to filing a bank chargeback to resolve billing questions amicably.
  • Delivery Evidence & Proofing Logs: For client invoice disputes, StudioMitra maintains cryptographically timestamped delivery logs, download records, IP access logs, and digital contract signatures to assist photographers in chargeback defense.
  • Unauthorized Transaction Reporting: If you identify an unrecognized transaction, notify us immediately within 24 hours. Our fraud operations team will immediately freeze the compromised token, initiate gateway investigations, and assist with reversal procedures.
Need full details on chargeback representment, cyber incident severity, or evidence preservation?Read Dispute Policy →

10. Cyber Crime & Cyber Fraud Management Policy

View Security Controls

In compliance with the Information Technology Act 2000, CERT-In directions, and global anti-fraud protocols, StudioMitra enforces proactive cyber security measures:

  • Automated Threat Detection: Real-time heuristic monitoring for credential stuffing, bot-driven brute force attacks, distributed denial of service (DDoS), and anomalous download velocities.
  • Identity & Phishing Prevention: Studio custom domains and client notification emails are protected with strict SPF, DKIM, and DMARC authentication records to prevent spoofing.
  • Law Enforcement Cooperation: Confirmed instances of identity theft, money laundering, ransomware, or unauthorized system penetration will be reported to competent statutory authorities and cyber crime cells.
Suspecting an unauthorized login, session hijacking, phishing attempt, or ransomware incident?Report Cyber Incident →

11. Information Security & Cyber Security Policy

View Full 57-Clause Policy

Our infrastructure architecture follows defense-in-depth principles aligned with ISO/IEC 27001 standards:

  • Network Security: Cloud infrastructure isolated across multi-tier Virtual Private Clouds (VPCs) with strict ingress/egress firewalls and web application firewall (WAF) filtering.
  • Data Encryption Standards: All data in transit is encrypted using TLS 1.3. Gallery vaults and database volumes are encrypted at rest using AES-256 with rotating KMS key management.
  • Vulnerability Management: Periodic independent third-party penetration testing, static application security testing (SAST), and dependency vulnerability auditing.
Need full details on access controls, SSDLC, vulnerability triage, or endpoint encryption standards?Read Cyber Security Policy →

12. Data Protection & Data Processing Policy

View Full 48-Clause Policy

StudioMitra operates as a Data Processor under India's Digital Personal Data Protection (DPDP) Act 2023 and GDPR:

  • Purpose Limitation: We only process client personal data and media files as instructed by the photographer for delivering gallery, booking, and invoicing services.
  • Data Minimization: We only collect necessary parameters required to complete operational studio deliverables.
  • No Commercial Exploitation: Client photographs, booking questionnaires, and email addresses are never sold, rented, or repurposed for targeted advertising.
Need full details on shared responsibility, model rights, or user independent backup obligations?Read Data Protection Policy →

13. Data Backup & Recovery Policy

View Continuity Policy

To prevent accidental loss of precious client photo collections and studio accounting history:

  • Multi-Region Redundancy: Client image archives are replicated across geo-separated storage facilities with 99.999999999% (11 9s) durability.
  • Continuous Point-in-Time Recovery: Database state is captured through continuous write-ahead transaction logs and automated daily snapshots.
  • Disaster Recovery SLA: Recovery Point Objective (RPO) of < 1 hour and Recovery Time Objective (RTO) of < 4 hours under certified business continuity scenarios.
Review our 3-2-1 independent photography backup guideline and operational recovery SLAs:Read Backup Guidelines →

14. Cookies & Marketing Consent Policy

View Full 41-Clause Policy

StudioMitra, a brand operated by SAFALPAY INDIA PRIVATE LIMITED, maintains a comprehensive Cookie Policy, Marketing & Communication Consent Policy (Version 1.0, Effective 19 September 2026). Acceptance of necessary cookies alone does not constitute consent for marketing communications.

  • Strictly Essential Cookies: Required for studio authentication, session tokens, CSRF protection, and shopping cart persistence for print orders.
  • Functional & Preference Cookies: Remembers your dashboard language, currency view, and client gallery grid sorting preferences.
  • Analytics & Performance Cookies: Aggregated metrics to assess page load velocities, Core Web Vitals, and gallery responsiveness.
  • Marketing & Telecom Consent: Commercial SMS, voice calls, and WhatsApp communications follow strict opt-in, TRAI/TCCCPR frameworks, and DND preferences.
Need full details on cookie categories, third-party trackers, TRAI DLT guidelines, or consent withdrawal?Read Cookie Policy →

15. Your Rights & Choices

Depending on your location (including rights under DPDP Act 2023, GDPR, CCPA, and applicable local privacy legislation), you may exercise the following rights:

  • Right to Access: Request a copy of the personal information we hold about you.
  • Right to Rectification: Update or correct inaccurate account or studio details.
  • Right to Erasure: Request the permanent deletion of your studio account and client records.
  • Right to Portability: Receive your data in a structured, machine-readable format.

16. Contact Our Privacy & Compliance Team

If you have questions regarding this Privacy Policy, wish to exercise your data rights, or have security concerns, please contact our Data Protection Officer:

StudioMitra Privacy & Security Office

Email: privacy@studiomitra.com

Support: support@studiomitra.com

We typically respond to privacy inquiries within 2 business days.