Skip to content

Legal

Privacy Policy

StudioOS is built for photographers who trust us with their business and their clients' families. This policy explains, in plain language, what we collect, why, how long we keep it, and how you can take it back.

Effective September 21, 2026

1What StudioOS is

StudioOS is studio management software for professional photographers. Photographers use StudioOS to publish a booking page, schedule and manage sessions, keep client records, send contracts and questionnaires, issue invoices and collect payments, deliver image galleries, and organize the day-to-day work of running a photography studio.

Throughout this policy, “you” means the photographer or studio that holds a StudioOS account. “Your clients” means the people your studio photographs and works with. Your clients do not hold StudioOS accounts; their information reaches us because you, as their photographer, put it into your studio's workspace or they submit it through your booking page, contract, questionnaire, or gallery. For that information, your studio is the controller of the data and StudioOS acts as your service provider.

2Information we collect

Account and profile information. Your name, email address, password credentials (stored only as a secure hash, never as readable text), and any profile details you add. If you sign in with Google, we receive your name, email address, and profile picture from Google to identify your account — nothing more.

Studio and business information. Your studio name, logo, brand colors and typography, session types, collections and pricing, availability, business contact details, booking page content and photographs, workflow and automation settings, and the documents you create such as contracts, questionnaires, and proposals.

Client information you enter or receive. Client names, email addresses, phone numbers, mailing addresses, household and family details you record, session dates and locations, notes and preferences, communication history, questionnaire answers, signed agreements, and the photographs you upload for delivery.

Payment-related information. StudioOS does not collect, process, or store full payment card numbers. Payments run through Stripe or Square using the account you connect, and card details are entered directly with that processor. StudioOS stores only the records it needs to run your business: invoice and payment amounts, currency, processing fees and surcharges, status, timestamps, the processor's transaction identifiers, and where the processor provides them, the last four digits and card brand.

Calendar information. If you connect Google Calendar, we access calendar data as described in the next section.

Technical and usage information. Log data such as IP address, browser and device type, pages requested, timestamps, and error diagnostics. We also record security-relevant events such as sign-ins, sessions and devices, and administrative actions inside your workspace.

Messages you send us. Support requests and product feedback, including anything you choose to include in them.

3Google Calendar and Google API data

StudioOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Connecting Google Calendar is entirely optional. Nothing in StudioOS requires it, and the rest of the product works without it. You grant access through Google's own consent screen, and you can withdraw it at any time.

What we request, and why. When you connect Google Calendar, StudioOS requests permission to view your calendars and to create and manage events on them. We use that access for four purposes only:

  • Displaying your calendar events inside StudioOS, so your photography schedule and the rest of your life appear in one place.
  • Creating and updating photography sessions on your connected Google Calendar when you book, reschedule, or cancel them in StudioOS.
  • Keeping StudioOS and Google Calendar synchronized, so a change made in one is reflected in the other.
  • Checking your free/busy times to prevent double-booking before a session is confirmed.

What we do not access. StudioOS does not request or receive your Gmail messages, Google Drive files, Google Contacts, Google Photos, or any other Google service. The only Google data we access is your basic profile and email address (to identify the connected account) and your Google Calendar.

What we store. We store the identity of the connected Google account and the calendar you selected, and — for the sessions StudioOS itself manages — the calendar event identifiers and the session details needed to keep those events accurate. Calendar events that StudioOS did not create are read to display your schedule and to check availability; we do not build a copy of your personal calendar for any other purpose. Your authorization credentials are held encrypted, and StudioOS never exposes them in the browser or in logs.

Limited Use. Google user data is used only to provide and improve the calendar features described above. We do not use it for advertising, we do not sell it, we do not transfer it to others except as necessary to provide those features or as required by law, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.

How to disconnect. In StudioOS, open Settings → Connected Apps → Google Calendar and choose Disconnect. That revokes the connection and deletes the stored credentials for that account. You can also remove StudioOS from your Google Account permissions page. After disconnecting, StudioOS stops reading and writing your calendar; events already created on your Google Calendar remain yours and stay where they are unless you delete them.

4How we use information

  • To provide the product: your booking page, sessions, clients, contracts, questionnaires, invoices, galleries, and calendar.
  • To authenticate you, secure your account, and detect or investigate suspicious activity.
  • To send transactional messages you or your clients expect — booking confirmations, agreements, invoices, gallery deliveries, and account notices.
  • To provide support when you ask for it.
  • To keep the service reliable: diagnostics, error monitoring, and aggregated usage measurement.
  • To meet legal, tax, and accounting obligations.

We do not sell your information or your clients' information. We do not use your content or your clients' content to train machine-learning models. Where StudioOS uses AI features (for example, Evie's summaries of your own studio data), the request is made only to operate that feature for you.

5Service providers and sharing

StudioOS runs on infrastructure and services operated by other companies. They process information only to perform work for us, under contract, and may not use it for their own purposes. The categories are:

  • Cloud hosting, database, authentication, and file storage.
  • Payment processing — Stripe and Square, for the account you connect.
  • Transactional email delivery.
  • Google, when you choose to connect Google Calendar or sign in with Google.
  • Error monitoring and product analytics.

We also share information when you direct us to (for example, sending a gallery to a client), when required by law or valid legal process, to protect the rights and safety of StudioOS, our users, or the public, and in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your information becomes subject to a different policy.

6How long we keep information

We keep your studio's information for as long as your account is active, because that information is your business records. When you close your account or ask us to delete your data, we delete or irreversibly anonymize it within 30 days, except where we must keep specific records longer to meet legal, tax, or accounting obligations, or to resolve a dispute. Routine backups are retained on a rolling basis and are overwritten within 90 days.

Google Calendar credentials are deleted as soon as you disconnect the integration. Security and audit logs are retained for a limited period so we can investigate incidents.

7Your choices, access, and deletion

  • Access and correction — most of your information can be viewed and edited directly in StudioOS at any time.
  • Export — ask us and we will provide your studio's records in a portable format.
  • Deletion — email us and we will delete your account and its data within 30 days, subject to the exceptions above.
  • Disconnect integrations — Google Calendar, payment processors, and gallery storage can each be disconnected independently in Settings.
  • Marketing email — every non-transactional email includes an unsubscribe link. Transactional messages about your account and your bookings cannot be turned off while your account is active.

Depending on where you live, you may have additional rights over your personal information, including the right to object to or restrict certain processing and the right to complain to a supervisory authority. Write to us and we will honor them. To make any of these requests, email support@studioossuite.com from the address on your account.

If you are a client of a studio that uses StudioOS and you want your information corrected or deleted, contact your photographer — the studio controls its own records. If you cannot reach them, write to us and we will help.

8Security

Information is encrypted in transit with TLS and at rest by our hosting and storage providers. Access to studio data is enforced at the database level so that one studio cannot reach another's records. Passwords are stored only as secure hashes. Integration credentials — including Google Calendar authorization — are stored encrypted and are never sent to the browser or written to logs. StudioOS supports two-factor authentication and passkeys, keeps an audit trail of sensitive actions, and lets you review and revoke active sessions and devices.

No system is perfectly secure. If a breach affects your information, we will notify you promptly and tell you plainly what happened and what to do.

9Cookies and analytics

StudioOS uses cookies and similar browser storage that are necessary to run the service — principally to keep you signed in, remember your workspace and interface preferences, and protect against fraudulent requests. We use limited, privacy-respecting analytics to understand which features are used and where the product fails. We do not run advertising networks, we do not use third-party advertising cookies, and we do not track you across other websites.

10Children's privacy

StudioOS is a business tool and is not directed to children. We do not knowingly create accounts for anyone under 18. Photographers do photograph children, and a studio may record a child's name, birthday, or session details as part of a family's record — that information is entered and controlled by the studio, and StudioOS processes it only to provide the service. If you believe a child's information reached us in error, contact us and we will remove it.

11Changes to this policy

We may update this policy as StudioOS grows. When we make a material change, we will update the effective date at the top of this page and notify account holders by email or inside the product before the change takes effect. Continuing to use StudioOS after a change means you accept the updated policy.

12Contact us

Questions about this policy, or about the information StudioOS holds, go to support@studioossuite.com. A real person reads it. These Terms and any dispute arising from or relating to StudioOS will be governed by the laws of the Commonwealth of Kentucky, without regard to its conflict-of-law principles.

See also our Terms of Service.