Legal

Privacy Policy

Last updated: August 26, 2026

This Privacy Policy explains how Client Flow Photo (“we,” “us,” or “our”) collects, uses, and shares information when you use our service at clientflow.photo and related services (the “Service”).

1. Information we collect

We may collect:

  • Account information from photographers (name, email, password, billing-related identifiers).
  • Event and form data you configure (event names, custom questions, settings).
  • Guest check-in data submitted through an event form, which may include name, email, phone, company, job title, notes, answers to custom questions, and a selfie image.
  • Payment information processed by Stripe. We do not store full card numbers on our servers.
  • Technical data such as IP address, browser type, and basic usage logs needed to operate and secure the Service.

2. How we use information

  • Provide and operate the Service (accounts, events, check-in, matching boards).
  • Process payments and prevent fraud.
  • Communicate about the Service, security, and support.
  • Improve reliability, accessibility, and product features.
  • Comply with law and enforce our Terms of Service.

3. How photographers use guest data

When guests check in to a photographer’s event, that photographer (the account owner) can access the submission, including the selfie and form answers, to match and deliver headshots. Photographers are responsible for how they use guest data and for providing any notices required for their own shoots or clients.

4. Sharing

We share information with:

  • Service providers that help us run the Service (for example Supabase for database/auth/storage and Stripe for payments).
  • The photographer who owns the event a guest checks into.
  • Authorities when required by law or to protect rights, safety, and security.

We do not sell personal information.

5. Retention

We retain account, event, and submission data while an account is active and as needed to provide the Service, resolve disputes, and meet legal obligations. Photographers may delete events or request account deletion; some backups or logs may persist for a limited period.

6. Security

We use industry-standard measures (encryption in transit, access controls, private selfie storage) to protect information. No method of transmission or storage is 100% secure.

7. Your choices

  • Photographers can update account details in Settings.
  • Guests should contact the photographer who collected their check-in for corrections or deletion related to that event.
  • You may contact us to request access, correction, or deletion of account data where applicable.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

9. International users

The Service may be hosted in the United States. If you access it from elsewhere, you consent to processing in the U.S. and other locations where our providers operate.

10. Changes

We may update this policy. We will post the revised version on this page and update the “Last updated” date.

11. Contact

Questions about privacy: lenstate333@gmail.com