Privacy policy

Last updated September 30, 2026

Draft: business details (entity, state, email) are still being added.

Shuttrflow makes software that photographers use to run their studios. This policy explains what personal information we handle, why, and the choices you have.

Who this covers

  • Photographers and their teams who use Shuttrflow (“studios”).
  • People who visit shuttrflow.com or join our waitlist.
  • Clients of a studio, whose details the studio keeps in Shuttrflow (see “If you're a studio's client” below).

If you're a studio's client

When you book, sign a contract, pay an invoice or view a gallery, you're dealing with the studio. The studio decides what it collects about you and why; Shuttrflow stores and processes it on the studio's behalf, under our data processing agreement with them. For requests about your information (a copy, a correction, deletion) please contact the studio first. We'll help them respond, and if you can't reach them, contact us.

What we collect

  • Account details: your name, email, studio name and address, and your password, which we never see or store in readable form (it's kept only as a one-way hash, and checked against known breaches when you set it).
  • Billing details: your plan, modules and payment history. Card and bank details are handled by Stripe; we only keep things like the card brand and last four digits.
  • What you put into Shuttrflow: photos, galleries, contracts, invoices, bookings, client records, your website and emails you send through it.
  • Technical information: IP address, browser type and activity logs, used to run and protect the service. Counts of sign-in attempts are kept as one-way hashes for up to a day.
  • Page-speed measurements: how quickly pages load for visitors (Vercel Speed Insights). They're anonymous, use no cookies, and aren't used to track anyone.
  • Waitlist sign-ups: your email and anything you tell us about your studio.
  • Messages you send us.

How we use it

To provide Shuttrflow, bill for it, keep accounts secure (including spotting and blocking fraud and abuse), send service emails, answer support requests, improve the product using aggregate information, and meet our legal obligations.

We don't sell personal information, don't share it for advertising, and don't use advertising or tracking tools. The only measuring we do is anonymous page speed.

Who we share it with

Only service providers that help us run Shuttrflow, under contracts that require them to protect it and use it only for us:

ProviderWhat they doWhere
VercelHosts the website and app, and measures page speed (Speed Insights: anonymous, no cookies)United States
SupabaseDatabase and sign-in (logins, studio records)United States (Oregon)
Cloudflare (R2)Stores photos, logos and exportsUnited States / global
StripeCard and bank payments, Shuttrflow subscriptions, studio payoutsUnited States
ResendSends account and client emailsUnited States
Have I Been PwnedChecks new passwords against known breaches (only the first 5 characters of a one-way hash are sent)Global

Studio payments from clients go through each studio's own Stripe account, under Stripe's terms and privacy policy. We may also disclose information when the law requires it, to protect people's safety or our rights, or as part of a sale or merger of our business (the buyer would be bound by this policy).

How long we keep it

We keep a studio's information while its account is open. When a studio is deleted, it goes offline right away and everything (photos, records and logins that belong to no other studio) is erased after 30 days, unless it's restored first. Records we must keep for tax or legal reasons (for example, payment records) are kept for as long as the law requires. Waitlist details are kept until you ask us to remove them.

How we protect it

  • Encrypted connections (HTTPS) everywhere, with strict transport security.
  • Each studio's data is kept separate from every other studio's at the database level.
  • Passwords must be strong, are checked against known breaches, and are stored only as one-way hashes. Repeated failed sign-ins are slowed down and blocked.
  • Gallery PINs are encrypted, and private photos are served through short-lived links.
  • Card and bank numbers never touch our servers.

No system is perfectly secure. If a breach affects your information, we'll tell you (and, for a studio's clients, the studio) as the law requires.

Your rights

You can ask for a copy of your information, a correction, deletion, or a full export of a studio's data. To make a request, contact us (details to be added). We'll need to confirm it's you. Depending on where you live (for example California, the EU or the UK) you may have additional rights, including to object to or restrict some uses, and to complain to your local data protection authority. We don't discriminate against anyone for using these rights.

Children

Shuttrflow is for businesses and isn't directed at children under 13. Studios often photograph children; in that case the studio is responsible for getting a parent's or guardian's permission.

Where your information is stored

Shuttrflow is run from the United States and our providers store data mainly in the United States. By using Shuttrflow from elsewhere, you understand your information will be processed there.

Changes

If we change this policy we'll update it here, and tell studios by email before significant changes take effect.

Contact

Questions about privacy? Contact us (details to be added).