Legal

Privacy Policy

What Still Bureau collects, why, who it is shared with, how long it is kept, and the choices you have — including where a photographer, not Still Bureau, is responsible for your information.

Effective
Last updated

01Scope and our two roles

This policy explains how Backlot Development, LLC handles personal information in the Still Bureau marketing site, the photographer dashboard, published photographer sites, client galleries, any features we later enable, and our mobile and native clients.

Still Bureau handles personal information in two distinct roles, and which one applies changes your rights and who to contact:

  • We are the controller for information about photographers and prospective customers — the account you create, any billing relationship with us, your use of the dashboard, and visits to our own marketing pages. This policy governs that information. We also determine the restricted transaction archive's accounting, reconciliation, and dispute purposes and its retention schedule described below.
  • We are a processor for information a photographer puts into their workspace — photographs and the people in them, contacts, projects, bookings, contracts, invoices, gallery visitors, and, where commerce is enabled, buyers. The photographer decides what is collected and why; we handle it on their instructions. Their own privacy notice governs that information, and privacy requests about it should go to them. We will route a misdirected request to the right photographer where we can identify them.

A photographer's instruction to fulfill an existing purchased download can continue after studio closure. For that limited delivery, we process the purchased files and minimum access records on the photographer's instruction. We operate the retained delivery service and handle requests about access or privacy at hello@stillbureau.com. The photographer remains responsible for the original collection, sale, and content license.

This release is dated September 5, 2026. Existing accounts receive notice before the general legal release takes effect on October 6, 2026; new accounts and explicit earlier acceptance use this release immediately. If you request closure earlier, we show the applicable retained-delivery and transaction-retention notice before closure. The optional delivery instruction is separate from general Terms acceptance. The restricted transaction archive serves the accounting purpose described here and does not depend on marketing consent or that optional instruction.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

02Information we collect

Information you give us

Scroll horizontally to view all columns.

CategoryExamplesWhy
AccountName, email address, authentication credential state (Still Bureau does not store plaintext passwords), email-verification state, profile and studio details.Create and secure your account, authenticate you, and contact you about the Service.
BillingWhere payment features are enabled: plan or add-on selections, subscription status, renewal dates, invoices, and the last four digits and brand of a card as reported by Stripe.Process a payment you authorize, apply plan limits, and keep required tax and accounting records. Still Bureau does not receive or store full card numbers.
ContentPhotographs, video, RAW files, captions, alt text, page and blog copy, logos, fonts, and site settings.Host, process, and publish the site and galleries you configure.
Studio recordsContacts, inquiries, projects, bookings, contracts, invoices, messages, and notes you enter about your clients.Operate the studio features you enabled. You are the controller of these records.
SupportMessages you send us and the context you include.Answer your question and improve the Service.

Information created by using the Service

  • Media metadata. Uploaded files may carry embedded metadata such as capture time, camera and lens, exposure settings, and — if your camera recorded it — GPS coordinates. We read capture time and dimensions to order and render galleries, and we store the file's metadata with it. Published web renditions are re-encoded, which removes most embedded metadata from the public copy; original files retain whatever metadata you uploaded.
  • Sign-in sessions. Active dashboard sessions record a device label, browser user agent, IP address, and last-seen time so you can review and revoke them in security settings.
  • Security audit records. Owner-visible records of sensitive account actions, including the actor's email address and IP address.
  • Legal acceptance records. The Terms and Privacy version and content hashes you accepted, when you accepted them, and a bounded browser user-agent string. We keep this evidence to administer our agreement and resolve disputes.
  • Gallery and site activity. Gallery sessions (a visitor's display name and, where they provided it, email address), favorites, comments, download events, and daily view and download counts per gallery. These are shown to the photographer, not to other visitors.
  • Order records. Where commerce is enabled, order line items, amounts, fulfillment and shipping details, refunds, and the buyer email address needed to deliver a purchase.
  • Surviving purchase records. Private purchased files, limited delivery details, purchase-access hashes, original license and download limits, download counts, refund state, and the policy version and time of the limited delivery instruction. The separate restricted transaction archive keeps only the accounting fields listed under retention below.
  • Message and campaign records. Campaign subject and body remain in the photographer's workspace with the campaign record. Delivery, bounce, complaint, unsubscribe, and suppression records are retained separately as needed to send and protect deliverability. SMS delivery data would be collected only if SMS is later enabled.
  • Operational logs. Server and proxy logs containing IP address, timestamp, request path, status, user agent, and bandwidth totals. These are used for security, abuse prevention, capacity, and debugging, and are configured to exclude request bodies, credentials, access tokens, message content, and private file URLs.
  • Push notification registrations. If push notifications are later enabled and you opt in, the browser or device endpoint, its encryption keys, and the user agent.

Information from third parties

Our email provider tells us delivery, bounce, and complaint events. Stripe payment features and Google Calendar synchronization are available where enabled and connected for the account. SMS, browser push, and automatic print fulfillment require their provider setup and acceptance to be complete before use. The applicable providers and data categories are listed on the Subprocessors page before customer data is sent.

03How we use information

  • Provide, host, and operate the Service and the features you turn on.
  • Authenticate you, protect accounts, detect abuse and fraud, and enforce limits.
  • Where payment features are enabled, process payments you authorize, apply plan entitlements, issue receipts and invoices, deliver purchases, and reconcile refunds.
  • Continue authorized purchased-file delivery after studio closure and maintain the separate restricted transaction archive for accounting, reconciliation, disputes, and applicable record obligations.
  • Send service messages you cannot opt out of while you have an account: verification, password resets, receipts, security and legal notices, and material changes to this policy or the Terms.
  • Provide support and respond to what you ask us.
  • Measure and improve the Service in aggregate — reliability, performance, and which features are used.
  • Send optional product news to photographers, where permitted and always with a one-click unsubscribe.
  • Comply with law, tax and accounting duties, and valid legal process.

05Local photo analysis and editing

Some features analyze uploaded media inside your own workspace. They are optional, run only when you enable them, and their output is visible only to you and the collaborators you have invited.

  • Quality and duplicate review. Local scoring of sharpness, exposure, and focus, plus grouping of near-duplicate and burst frames, to help you cull a shoot.
  • Local edit assistance. Consistent batch adjustments, personal styles, and bounded clone-heal processing run inside the Service. They create reviewable versions and do not overwrite the original.

None of these features make a decision that produces a legal or similarly significant effect on a person. Deleting the associated photo or gallery removes its analysis and edit records from the active database; stored media versions follow the media-deletion and retention process described below.

06Cookies, browser storage, and analytics

We use a small number of strictly necessary cookies to sign you in, keep gallery and password-protected pages unlocked, and protect forms. These do not require consent because the Service cannot work without them.

On our own public marketing pages we offer optional Google Analytics 4. It loads only after you accept, advertising storage and personalization are disabled, IP addresses are truncated, and the tag never loads in accounts, dashboards, client galleries, checkout, or other customer-specific areas. You can change or withdraw the choice at any time from the privacy button on those pages.

Photographers on eligible plans may connect their own analytics or advertising tags to their site. Those tags belong to the photographer, load only after the visitor accepts the consent banner on that site, and are governed by the photographer's privacy notice and the tag vendor's terms.

The Cookie Policy lists the first-party cookies and browser-storage keys set by the current application, with their purpose and lifetime or browser-controlled retention.

07When we share information

We share personal information only in these situations:

  • With the photographer whose site you used. If you are a gallery visitor or buyer, the photographer sees the information their gallery, form, or order required — for example your name, email address, favorites, and order details — so they can deliver your photographs and support your purchase.
  • With service providers. Vendors that host, store, send, and monitor the Service, and payment providers only if a payment feature is enabled and used, under contracts that limit them to our instructions. They are listed on the Subprocessors page.
  • With integrations you connect. Only the data that integration needs, and only while it is connected.
  • For legal reasons. To comply with law or valid legal process, to enforce our Terms, or to protect the rights, safety, and property of our customers, the public, or us. Where we are permitted to, we notify the affected customer first.
  • In a corporate transaction. If we are involved in a merger, acquisition, or sale of assets, information may transfer to the successor under this policy. We will give notice before your information becomes subject to a materially different policy.
  • With your direction. Anything else you ask us to share.

We never sell personal information, and we do not disclose it for cross-context behavioral advertising or targeted advertising, including information about people under 16.

08International transfers

The Service is hosted in the United States, and our providers may process information in other countries. Where we transfer personal information out of the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with technical measures including encryption in transit and at rest. Contact us for a copy of the relevant safeguards.

09How long we keep information

Scroll horizontally to view all columns.

DataRetention
Account and ordinary studio workspaceKept to operate the account. Closure removes ordinary active workspace records after outstanding payments, fulfillment, and other obligations are safely resolved. The limited delivery and transaction exceptions below do not preserve the workspace.
Purchased files and delivery grantsRetained privately for as long as the buyer's original download right remains valid, including after studio closure. Original licenses, expiry, allowance, used downloads, and refund or revocation state remain unchanged. A non-expiring right does not gain an expiry because the studio closes. Once no valid grant requires a file, it enters deletion, subject to a documented hold or unresolved obligation concerning that file.
Other media objectsClosure requests deletion of media not needed for surviving purchases or unresolved obligations. Inaccessible residual objects, versions, and recovery copies follow the separate rules below.
Buyer contacts and studio activityBuyer email, shipping details, contacts, projects, messages, marketing data, and proofing activity are not retained merely to keep purchase links working. Only the separately specified invoice identity and financial fields may remain in the restricted transaction archive.
Legal acceptance and limited delivery instructionOrdinary account acceptance records are deleted with the account. A surviving delivery keeps the applicable policy version, content hashes, instruction time, and opaque purchase binding needed to document that limited instruction. This does not record acceptance of new general Terms where only the delivery instruction was given.
Purchase access and delivery securityPurpose-specific purchase cookies expire within 30 days. Their expiry does not expire an otherwise valid purchase link. Capability hashes, grant state, and brief read leases remain only as needed for authorized delivery; security logs have a separate limited retention process.
Gallery access sessions and related proofing activityThe browser access token expires after no more than 30 days. The database session and attached favorites, comments, or downloads remain while the related gallery or account remains.
Expired unfinished uploadsRemoved by the upload cleanup process; timing can vary.
Message delivery, bounce, and suppression recordsKept while needed to protect deliverability and to honor unsubscribe and STOP requests.
Restricted transaction archiveSeven years after the end of the calendar year of each record's last financial event: issue, payment, or refund, measured in UTC. Closing the account, accessing or copying a record, and retrying a job do not restart the clock. At the deadline records become eligible for scheduled deletion, unless a documented record-specific legal hold or unresolved obligation still requires them.
Operational and security logsKept for a limited period for security and debugging, then deleted or aggregated.
Database recovery copiesProduction point-in-time recovery uses a rolling seven-day retention window.
Versioned media copiesDeleted or replaced object versions can remain in restricted storage for up to 90 days.

What the restricted transaction archive contains

The archive contains opaque merchant and source identifiers; invoice and order numbers and dates; line items, installment and payment records; currency and subtotal, discount, tax, tip, charged, refunded, payout, and fee amounts; tax jurisdiction; payment, refund, gift-card ledger, and closed dispute status; and exact payment-provider references needed for reconciliation. Issued invoices may retain the seller's display name and bill-to name and email as part of the invoice identity. Payment-link payer contact data, unrelated CRM notes, marketing data, reusable payment credentials, full card details, and complete provider payloads are excluded.

Access is restricted to authorized personnel handling accounting, reconciliation, security, verified record requests, or legal process. The archive is not a customer database for marketing, a public record, or a recoverable studio workspace. We record the applicable policy, source financial dates, and retention deadline. A legal hold or unresolved obligation must identify the affected record, reason, and review date; it does not restart the ordinary retention clock when released.

For example, a record whose last financial event occurs in 2026 is retained through December 31, 2033 and becomes deletion-eligible on January 1, 2034 UTC, absent a documented hold or unresolved obligation. If reliable financial dates are missing, we restrict the record for a documented review with a review date within 90 days instead of treating the closure or copy date as a new financial event. This seven-year schedule is our business policy, not a universal statutory requirement. Sellers must keep their own records for the duties that apply in their jurisdiction. Stripe separately applies its own retention rules.

Closing an account removes sign-in access, cancels any linked platform subscription, and starts the deletion process above. You do not have to accept new general Terms to leave. Purchased delivery and restricted transaction records have different purposes and lifetimes. Retained photographs and their embedded metadata can still be personal information even when delivery records contain no buyer email; we do not silently strip metadata from a purchased original. Export the records and files you need before closing, because the deleted workspace cannot be restored from these limited records.

10How we protect information

  • HTTPS everywhere, with HSTS and automatic certificate renewal.
  • Encryption in transit and at rest for the database and media storage.
  • Still Bureau does not store plaintext account passwords. Locally managed credentials are stored as salted hashes, and we cannot display or retrieve an original password.
  • Media buckets block public object-store access. The application serves web and thumbnail renditions only when the site and gallery access rules permit it. Uploaded originals require dashboard access or a gallery download route the photographer enabled. A purchased file requires the corresponding valid purchase access, including when delivered from the private retained service after studio closure.
  • Least-privilege access for the small number of people who operate the platform, plus audit records for sensitive account actions.
  • Optional account controls you can enable: session review and revocation, IP allow-lists, concurrent-session limits, and idle-session expiry.
  • Automated backups with restore testing, and monitored alerting.

No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as required by law and without undue delay. To report a vulnerability, see the Security page.

11Your rights and choices

Everyone

  • Access, correct, or delete your account information from account settings.
  • Delete your account from account settings; active records and stored media then follow the deletion and retention process described above.
  • Unsubscribe from optional marketing email with the link in every message.
  • Accept or refuse optional analytics, and change that choice later.
  • If push notifications are later enabled, turn them off in your browser or device settings.

EEA, UK, and Switzerland

You have the right to access, rectification, erasure, restriction, portability, and objection, including objection to processing based on legitimate interests, and the right to withdraw consent. You may also lodge a complaint with your supervisory authority — we would appreciate the chance to address it first.

California and other US states

You have the right to know the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients; to correct inaccurate information; to delete it; to obtain a portable copy; and to be free from discrimination for exercising these rights. Because we neither sell personal information nor share it for cross-context behavioral advertising, there is nothing to opt out of. On Still Bureau's own marketing pages, we honor Global Privacy Control signals as a request to refuse optional analytics. Photographer-operated site banners currently rely on the visitor's explicit choice.

Making a request

Email hello@stillbureau.com. We verify identity and authority using information relevant to the request and respond within the period the applicable law requires — generally 30 days, or 45 days in California, with an extension where permitted. An authorized agent may act for you with written permission we can verify.

If your request concerns information a photographer holds about you — a gallery you were invited to, a booking, or an original sale — contact that photographer directly. For retained delivery after studio closure or our restricted transaction archive, contact us at the address above. We handle requests within our responsibilities and coordinate with the photographer where appropriate; we do not require a closed studio to answer an access request before you can contact us.

12Children

The Service is a professional tool for adults. We do not knowingly collect personal information from children under 16 for our own purposes, and children may not create accounts. Photographers regularly photograph children in the ordinary course of their work; when they do, they are the controller of that content and are responsible for the consent of a parent or guardian.

If you believe a child has given us personal information for which we are the controller, contact hello@stillbureau.com and we will delete it.

13Changes to this policy

We update this policy when the Service or the law changes. The “last updated” date at the top always reflects the current version. For material changes we give notice by email or in the dashboard before they take effect, and where the law requires it we ask for your consent.

14Contact us

Backlot Development, LLC is the controller for the information described in this policy. Reach our privacy contact at hello@stillbureau.com or by post at 5331 Golden Apple Dr, Winter Garden, FL 34787.

For a data processing agreement, standard contractual clauses, our subprocessor list, or a security questionnaire, use the same address.