Privacy Policy
Last updated: September 19, 2026 • Effective date: September 19, 2026
Our Core Privacy Principles
You and your clients retain full copyright and ownership of all uploaded photographs. We never claim IP rights.
We never monetize, broker, or sell personal contact details, images, or client lists to third-party advertisers.
All contracts, client invoices, private proofing links, and hi-res image deliveries are protected with end-to-end TLS and AES-256 encryption.
1. Overview & Scope
Welcome to StudioMitra ("we," "our," or "us"). StudioMitra provides a photography studio management platform, client proofing galleries, invoicing, and contract workflow tools. This Privacy Policy explains how information is collected, used, and disclosed when you use our websites, applications, and related services (collectively, the "Services").
This policy applies to studio owners, photographers, studio team members, and the clients or guests who access photography galleries and invoices managed through StudioMitra.
2. Information We Collect
Depending on your interaction with StudioMitra, we may collect the following categories of information:
- Account & Studio Profile Data: Name, email address, studio name, phone number, brand assets (logos, custom domain configurations), and profile credentials.
- Client & Booking Records: Client names, email addresses, event dates, photoshoot locations, questionnaires, and signed contracts submitted through your studio workspace.
- Photographs & Media Metadata: Images, RAW/JPEG assets, gallery collections, album favorites, EXIF metadata (camera model, capture timestamp, resolution), and proofing selections.
- Billing & Payment Information: Payment transactions processed through certified third-party payment gateways (e.g., Stripe or Razorpay). We do not store complete credit card or CVV information on our servers.
- Usage & Technical Logs: IP address, device specifications, browser type, operating system, referrers, and diagnostic session analytics.
3. Photo Rights & Ownership
StudioMitra makes zero ownership claims over your content. All photographs, watermark overlays, client portfolios, and intellectual property uploaded to your account remain solely the property of you or your clients.
You grant StudioMitra only the limited license necessary to host, thumbnail, convert, and transmit your images to your designated clients upon your request.
We never use your private galleries to train public AI models or license your photographs to stock libraries.
4. How We Use Information
We process your data strictly to operate, maintain, and enhance the StudioMitra platform, including to:
- Create and host private, responsive client delivery galleries.
- Facilitate client proofing, photo favorites selection, and hi-res image downloads.
- Process client invoices, retainers, and automated payment receipts.
- Send transactional notifications, booking updates, and contract signature confirmations.
- Prevent fraudulent activity, spam, and unauthorized gallery access.
- Provide dedicated customer support and troubleshooting assistance.
5. Client Gallery Privacy & Access Controls
As a studio owner, you have granular control over how galleries are presented to clients:
Restrict gallery access or download rights with custom client PINs.
Protect proofs with customizable studio watermark overlays prior to purchase.
Toggle high-resolution vs. web-resolution downloads per collection.
Set automatic gallery expiration to limit viewing windows.
6. Payments & Billing Security
All financial transactions, subscription fees, and client payments are routed through PCI-DSS Level 1 compliant processors such as Stripe or Razorpay.
StudioMitra does not capture or store raw credit card numbers, bank account passwords, or CVV security codes. Payment processors handle all sensitive billing data in compliance with financial security regulations.
7. Terms & Conditions
View Full 30-Clause PolicyBy accessing or subscribing to StudioMitra, you agree to comply with our Terms of Service. Studio accounts are licensed on a SaaS subscription basis for photography professionals, studios, and authorized team members.
- Users are responsible for safeguarding account login credentials and two-factor authentication tokens.
- Content uploaded must not infringe upon third-party copyrights, trademarks, or contain unlawful material.
- StudioMitra reserves the right to suspend accounts engaged in abusive automated scraping, spam distribution, or fraudulent chargeback activity.
- Service Level Agreements target 99.9% platform availability, excluding scheduled maintenance windows announced in advance.
8. Refund & Cancellations Policy
View Full 24-Clause PolicyWe believe in total billing transparency for all StudioMitra subscription plans and add-on storage tiers:
- 14-Day Money-Back Guarantee: New annual studio subscriptions are eligible for a full refund within 14 calendar days of the initial purchase date if you are not completely satisfied.
- Subscription Cancellations: You may cancel recurring billing at any time from your Studio Dashboard. Your subscription will remain active until the end of the current paid billing cycle with zero penalty fees.
- Client Invoices & Shoot Retainers: Financial transactions between photographers and their end-clients (e.g. wedding shoot deposits or print store orders) are governed by the photographer's individual studio contract. StudioMitra acts as the technology facilitator.
- Refund Processing Time: Approved subscription refunds are processed back to the original payment method within 5 to 7 business days.
9. Chargeback, Dispute & Unauthorized Transaction Policy
View Full 50-Clause PolicyStudioMitra maintains robust dispute mitigation workflows in collaboration with acquiring banks, card networks (Visa, Mastercard, RuPay, Amex), and licensed payment aggregators:
- Direct Dispute Resolution: Cardholders are encouraged to contact our support team at support@studiomitra.com prior to filing a bank chargeback to resolve billing questions amicably.
- Delivery Evidence & Proofing Logs: For client invoice disputes, StudioMitra maintains cryptographically timestamped delivery logs, download records, IP access logs, and digital contract signatures to assist photographers in chargeback defense.
- Unauthorized Transaction Reporting: If you identify an unrecognized transaction, notify us immediately within 24 hours. Our fraud operations team will immediately freeze the compromised token, initiate gateway investigations, and assist with reversal procedures.
10. Cyber Crime & Cyber Fraud Management Policy
View Security ControlsIn compliance with the Information Technology Act 2000, CERT-In directions, and global anti-fraud protocols, StudioMitra enforces proactive cyber security measures:
- Automated Threat Detection: Real-time heuristic monitoring for credential stuffing, bot-driven brute force attacks, distributed denial of service (DDoS), and anomalous download velocities.
- Identity & Phishing Prevention: Studio custom domains and client notification emails are protected with strict SPF, DKIM, and DMARC authentication records to prevent spoofing.
- Law Enforcement Cooperation: Confirmed instances of identity theft, money laundering, ransomware, or unauthorized system penetration will be reported to competent statutory authorities and cyber crime cells.
11. Information Security & Cyber Security Policy
View Full 57-Clause PolicyOur infrastructure architecture follows defense-in-depth principles aligned with ISO/IEC 27001 standards:
- Network Security: Cloud infrastructure isolated across multi-tier Virtual Private Clouds (VPCs) with strict ingress/egress firewalls and web application firewall (WAF) filtering.
- Data Encryption Standards: All data in transit is encrypted using TLS 1.3. Gallery vaults and database volumes are encrypted at rest using AES-256 with rotating KMS key management.
- Vulnerability Management: Periodic independent third-party penetration testing, static application security testing (SAST), and dependency vulnerability auditing.
12. Data Protection & Data Processing Policy
View Full 48-Clause PolicyStudioMitra operates as a Data Processor under India's Digital Personal Data Protection (DPDP) Act 2023 and GDPR:
- Purpose Limitation: We only process client personal data and media files as instructed by the photographer for delivering gallery, booking, and invoicing services.
- Data Minimization: We only collect necessary parameters required to complete operational studio deliverables.
- No Commercial Exploitation: Client photographs, booking questionnaires, and email addresses are never sold, rented, or repurposed for targeted advertising.
13. Data Backup & Recovery Policy
View Continuity PolicyTo prevent accidental loss of precious client photo collections and studio accounting history:
- Multi-Region Redundancy: Client image archives are replicated across geo-separated storage facilities with 99.999999999% (11 9s) durability.
- Continuous Point-in-Time Recovery: Database state is captured through continuous write-ahead transaction logs and automated daily snapshots.
- Disaster Recovery SLA: Recovery Point Objective (RPO) of < 1 hour and Recovery Time Objective (RTO) of < 4 hours under certified business continuity scenarios.
15. Your Rights & Choices
Depending on your location (including rights under DPDP Act 2023, GDPR, CCPA, and applicable local privacy legislation), you may exercise the following rights:
- Right to Access: Request a copy of the personal information we hold about you.
- Right to Rectification: Update or correct inaccurate account or studio details.
- Right to Erasure: Request the permanent deletion of your studio account and client records.
- Right to Portability: Receive your data in a structured, machine-readable format.
16. Contact Our Privacy & Compliance Team
If you have questions regarding this Privacy Policy, wish to exercise your data rights, or have security concerns, please contact our Data Protection Officer:
StudioMitra Privacy & Security Office
Email: privacy@studiomitra.com
Support: support@studiomitra.com
We typically respond to privacy inquiries within 2 business days.