The short version
- We don't sell personal information, and we don't use it for advertising.
- Our websites and client portals have no analytics or advertising trackers.
- Photographers own their photos. We never use them to train AI, and we don't send them or anyone's information to AI services.
- Clients' information belongs to the studio they work with. We handle it for that studio, only to run the service.
- Face matching is off unless a studio turns it on for an event and confirms the families agreed. Face data is deleted after 12 months or sooner.
- We delete old sign-in records and clear old IP addresses on a schedule, listed below.
Who we are
HeyShutter is software for photographers, operated by Close Daily LLC ("HeyShutter", "we", "us"). This policy covers heyshutter.com, the photographer app at app.heyshutter.com, client portals we host (at yourstudio.heyshutter.com or on a studio's own domain), the HeyShutter Lightroom Classic plugin, and the emails and texts the service sends.
Studios and their clients
HeyShutter has two kinds of users, and we play a different part for each.
- Photographers and studios. When a photographer signs up and runs a studio on HeyShutter, we are responsible for the account information we collect about them.
- Clients of a studio. When a studio's client views a gallery, books a session or places an order, the studio decides what it collects and how it uses it. We store and process that information for the studio, as its service provider, and only to run the service for that studio. The studio's own privacy policy also applies. If you are a client, contact the studio first with questions or requests about your information. We help studios answer them.
On paid plans a studio's client portal shows only the studio's name, so clients may not see the HeyShutter name. This policy still describes how their information is handled.
What we collect
From photographers and studio staff
- Account details: your name, studio name, email address, mobile number and password. Passwords are stored only in a scrambled, one-way form we can't read.
- Sign-up checks: to stop one person opening many free studios, we record the IP address, browser and device identifier (a cookie) a studio signed up from, and ask our texting provider whether the mobile number is a mobile, landline or internet number. Sign-ups that look like a second account are flagged for a person to review.
- Your studio: the photos, galleries, branding, prices, agreements, settings and everything else you add. This includes payment handles you choose to show clients (such as Venmo or Cash App) and the return address for print orders.
- Billing: when you pay for a plan, our payment processor Stripe collects your card details. We keep your plan, billing dates, payment status and the card brand and last four digits. We never see or store full card numbers.
- Integrations: if you connect the Lightroom Classic plugin, we store a scrambled copy of its access key. The plugin keeps the key in your computer's password store and talks only to HeyShutter.
- Sign-in records: the IP address and browser of each sign-in, so we can spot sign-ins that aren't yours.
From clients of a studio, on the studio's behalf
- Account details: name, email address, phone number and password (stored in a scrambled, one-way form), and notes the studio writes about the client.
- Galleries: which galleries a client can open, the photos they mark as favorites, notes on favorites, and a cookie that remembers a download PIN they entered.
- Orders and payments: what was ordered, prices and totals, and for prints the shipping name, address and phone number. Card payments go through Stripe, so we receive the payment status and method type but never card numbers. Payments made directly to the studio (for example by Venmo or cash) are recorded by the studio.
- Bookings and agreements: the session date, time, location and notes. When a client signs an agreement we keep the typed name, the time, the IP address, a copy of the agreement and a fingerprint of it that shows it wasn't changed afterward.
- Event sign-ups: when a family scans an event's QR code or a number card, the name and email they leave, the contestant number and name, and which gallery the studio links them to.
- Activity: gallery views, downloads, favorites, purchases and sign-ins, with the time and IP address. The studio sees this activity, including when a client is looking at a gallery right now.
From visitors to heyshutter.com
- Our web servers record standard request details (IP address, browser, page and time) to deliver and protect the site.
- Our websites, the app and client portals load fonts from Google Fonts, so Google receives your IP address when a page loads.
- The "Set up with our team" form opens an email in your own email app. We receive only what you send us.
- The blog has comments turned off.
Face matching
HeyShutter can find faces in pageant photos so a studio can sort thousands of photos by person and show families the group and event photos their contestant appears in. Because this involves face data, it works differently from everything else:
- Off unless the studio turns it on. It is available only for pageant events, starts switched off, and runs only after the studio turns it on for that event and confirms that the people in the photos, or a parent or guardian for anyone under 18, agreed to it. Studios are responsible for getting that agreement, for example in their entry form or model release.
- What it creates. For each face in a photo, our servers record where the face is in the photo and a numeric face template used to tell whether two faces are the same person.
- Where it runs. On HeyShutter's own servers. Face data is never sent to another company, never sold, and never used for anything except sorting and matching photos within that one event for that one studio.
- Selfie search. A family member can upload a selfie to find more photos of themselves in an event, after agreeing to it on the page. The selfie is compared and then discarded. We don't store the selfie or a face template made from it, only the list of matching photos.
- How long it's kept. Face data is deleted 12 months after it is created, or sooner when the studio clears it, deletes the photos or deletes the gallery.
If a law where you live gives you rights over face data (for example in Illinois, Texas or Washington), contact the studio or us and we will help.
How we use information
- To run HeyShutter: host and deliver galleries, take orders and bookings, send prints to labs, and show studios their activity and sales.
- To send the emails and texts the service needs, such as sign-up codes, gallery invitations, receipts, booking reminders, password resets and billing notices.
- To bill studios for their plans.
- To keep accounts secure and stop fraud, abuse and duplicate free accounts.
- To answer support requests and fix problems.
- To meet legal obligations and enforce our Terms of Service.
We don't sell personal information or share it for advertising. We don't use photos, clients' information or studios' content to train AI models, and we don't send them to AI services.
Text messages
When you sign up, we text a one-time code to your mobile number to confirm it's yours. The code is sent through our provider Telnyx.
Studios on some plans can text their own clients from the studio's own number, for example when a gallery is ready. A client gets these texts only after ticking "Text me" on their account, and every text names the studio and says how to stop. Reply STOP to any of them to stop, or START to get them again. To register a studio's number, we send the carriers the studio's business details (name, address, contact and, for companies, the EIN, which we don't keep afterward).
Message and data rates may apply. Phone numbers are never used for marketing. Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes.
Google Photos and Dropbox
Clients can save photos straight to Google Photos or Dropbox from a studio's download page. Neither happens unless the client chooses it.
- Google Photos. We ask Google only for permission to add photos to your library. We can't see, change or delete anything already in your Google Photos. Google's access key is used for that one save, held in memory while it runs and never stored. We keep a record of the save (which photos, the album link and whether it finished) so the studio and you can see it worked.
- Dropbox. Dropbox's own button saves the photos to your Dropbox. Dropbox fetches them from us through links that expire after 2 hours. We receive nothing from your Dropbox account.
HeyShutter's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it
| Information | How long |
|---|---|
| A studio's account, photos, galleries, clients and orders | While the studio's account is open. A studio can delete galleries at any time. After a studio closes its account, we delete its content within 90 days, except records we must keep for tax or legal reasons. |
| Sign-in records and password reset links | Deleted 30 days after they expire |
| Sign-ups that were never finished | Deleted 30 days after they expire (each one stays open 24 hours) |
| The IP address, browser and device a studio signed up from | Cleared after 24 months |
| IP addresses in gallery activity | Cleared after 12 months. The activity itself stays with the gallery. |
| Face data | Deleted 12 months after it is created, or sooner (see Face matching) |
| Selfies used for face search | Not stored |
| Server logs | Kept for a limited time for security and troubleshooting |
Security
Every page and file is served over an encrypted connection. Passwords and access keys are stored only in scrambled form. Photo files are private: our servers check who is signed in before sending a photo, and links we give to print labs, Dropbox and similar services are signed and expire. Studios can require a PIN before anything downloads. Only a studio's own staff can see its clients and orders; HeyShutter staff look at a studio's data only to give support, fix a problem or meet a legal obligation. No system is perfectly secure, so if you think your account has been misused, write to us right away.
Children
HeyShutter accounts are for adults, and we don't knowingly collect information directly from children under 13. Studios often photograph children, for example at pageants and family sessions, and upload those photos at a parent's request. A parent or guardian who wants photos or information about their child removed can ask the studio, or write to us and we will work with the studio.
Your choices and rights
- Studios can see and change most of their information in their settings, and can write to us to get a copy of it or to delete their account.
- Clients can change their name, phone and password in the portal. For anything else, including a copy or deletion of your information, contact the studio. You can also write to us and we will pass it on and help.
- Depending on where you live, you may have the right to access, correct, delete or get a copy of your information, and to appeal if we turn a request down. We answer within 30 days, or sooner where the law requires, and we won't treat you differently for asking.
- HeyShutter sends service emails only. If we ever send product news, every message will have an unsubscribe link.
We process information in the United States and in other countries where our providers operate.
Changes to this policy
When we change this policy we update the date at the top. If a change is significant, we email studios before it takes effect.
Contact
Write to [email protected] with any question or request about privacy. HeyShutter is operated by Close Daily LLC.