Privacy Policy
Effective: 14 August 2026 · Last updated: 24 August 2026
If you are a parent who got an email about your child's photos from an event, the section you want is Section 6. It says exactly what is stored, for how long, and how to have it destroyed.
1. Who we are, and the two kinds of people in this policy
Phramed is a software platform operated by Handled Agency LLC, a South Carolina limited liability company. Photographers use it to deliver client galleries, take bookings, accept payments, and, at qualifying events, offer face matching so families can find their own photos.
There are two very different relationships here and this policy treats them differently:
- Photographers are our customers. They create an account, they log in, and they have a contract with us.
- Clients and event participants never create a Phramed account. They arrive through a link a Photographer sent them. For their data we act on the Photographer's behalf, as their service provider, not as our own customer relationship.
If you are a Client and have a question about your data, contact the Photographer first: they control the gallery, the booking, and the relationship with you. If you cannot reach them, contact us at privacy@phramed.co.
2. What we collect from Photographers
- Account: email address, a hashed password (we never store it in readable form), name and studio name.
- Payment setup: if you connect Stripe, your Stripe account identifier and its connection status. We never receive or store your clients' card numbers.
- Calendar (optional): if you connect Google Calendar, the OAuth tokens Google issues and the connected account's email. If you connect an Apple or iCloud calendar, the iCloud email and app-specific password you provide. See the security note in Section 8.
- Content: photos, galleries, shot lists, contracts, and your branding settings.
- Usage: IP address and basic request metadata, used for rate limiting and abuse prevention, plus account activity such as sign-in times. Session tokens are stored hashed.
3. What we collect from a Photographer's clients
| If they… | We collect |
|---|---|
| View a gallery | An anonymous device identifier used to remember favorited photos and whether a password-protected gallery was unlocked. If the Photographer set a client name or email on the gallery, that too. |
| Book a session | Name, email, optional phone, any notes, and the date and time booked. |
| Buy photos | Name and email as given to Stripe at checkout, the amount, and which package. Card details are handled entirely by Stripe. |
| Send an inquiry | Name, email, optional phone, and their message. |
| Sign up for event photo matching | Name, email, optional phone, state of residence, date of birth, and the two reference photos described in section 5. The date of birth is used for one thing: to determine whether the person is under 18 and therefore whether a parent or guardian has to give permission before any faceprint is created. It is not shown to the Photographer's other clients, is not used for advertising, and is deleted with the rest of the sign-up. |
4. How we use it
- To provide the service: render a gallery, hold and confirm a booking, take a payment, send a confirmation email, sync a calendar.
- To notify a Photographer when something happens on their account.
- To prevent abuse, such as rate limiting sign-in attempts.
- To improve the product.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use data collected on a Photographer's behalf for our own marketing.
5. Payments
Photographers connect their own Stripe account and are paid directly by their clients. Phramed is not the merchant of record for gallery or package sales. For event photography with face matching, Phramed collects a percentage as a Stripe application fee at the time of the transaction; the underlying charge still belongs to the Photographer. We never receive, transmit or store full card numbers.
6. Biometric data and event face matching
At some events, a Photographer may offer face matching so a family can find their own photos by submitting two reference photos: one taken with the camera at sign-up, and one uploaded headshot. This processes biometric data as defined under Illinois BIPA, Texas CUBI and Washington's biometric privacy law, and we handle it deliberately.
Consent
An adult participant consents for themselves at sign-up. For a minor, nothing happens until a parent or guardian follows an emailed link and signs. Until that moment no faceprint is created for that child and no search runs. This is enforced in the software, not by policy: a face search only ever runs for a participant whose consent is recorded as granted.
The Photographer running the event is also required to confirm to us that they obtained proper consent from each participant or guardian.
What is actually stored
A mathematical representation of facial geometry (a "face vector"), generated by Amazon Rekognition, plus the reference photos themselves so a photographer can correct a wrong match. They are not used to identify anyone outside that one event's photos, and it is never sold, shared or used to train anything.
How long we keep it
Face vectors and reference photos are destroyed no later than 90 days after the event date, or immediately on a withdrawal of consent, whichever comes first.
This runs automatically on a daily schedule, and deletion at Amazon is confirmed before we mark anything as destroyed, so we can never report a deletion that did not actually happen. We keep a record that the destruction occurred and when, because being able to prove the date is the point of having a retention schedule.
The photographs themselves are not biometric data and are not deleted by this schedule. They belong to the Photographer and are governed by their own arrangement with you.
Illinois
Phramed does not offer face matching to Illinois residents at all. State of residence is a required question at sign-up and an Illinois answer is refused. This is written into the software unconditionally rather than left as a setting, so no photographer and no configuration can switch it on.
Deleting it sooner
Any participant, or their parent or guardian, can have this data destroyed at any time and for any reason. Reply to the consent email, or simply tell the photographer. They can destroy one person's faceprint immediately from their own account, and that is the fastest route. If you would rather not go through the photographer, contact privacy@phramed.co and we will action it. You do not have to give a reason, and it does not affect the photographs the photographer took.
Declining counts as a withdrawal. If a guardian answers "no" on the consent page, the reference photo uploaded at sign-up is deleted straight away rather than waiting for the retention window to run out.
7. Cookies and advertising
- A session cookie for logged-in Photographers. HttpOnly, unreadable by JavaScript, expiring after 30 days of inactivity.
- A gallery-unlock cookie for a client who entered a correct access word.
- An anonymous visitor identifier used only to remember favorited photos on that gallery.
Advertising measurement, on our marketing pages only
We advertise Phramed to photographers. To find out whether those ads work, our marketing pages load the Meta (Facebook) advertising pixel. Those pages are our home page, our landing pages for particular kinds of photography, our sign-in and sign-up page, and these legal pages. On them, the pixel tells Meta that a visit happened and, if you create an account, that a sign-up happened. Meta may connect that to a Facebook or Instagram account, which is how they report whether an ad led to a sign-up.
It is not on the pages your clients see, and that is enforced in code rather than promised. If you are here because a photographer sent you a link to your gallery, your photos, or a consent request, no advertising tracker runs on that page. That covers every gallery link, every short link, the family photo pages, the guardian consent and withdrawal pages, the enrollment pages, booking pages, and shared run-of-day pages. Those pages are served with a security policy that does not permit an advertising script to load at all, so it cannot start happening by mistake if somebody changes the site later.
The signed-in Photographer app at /studio and /planner is not tracked
either. We do not report what you do inside the product to an advertising network.
You can limit this. Most browsers let you block third-party cookies and scripts, and any content blocker will stop the pixel outright, which does not affect your ability to use Phramed. Meta also offers ad preference and off-Facebook activity controls in your Facebook or Instagram account settings.
Two other third parties that are not advertising
Cloudflare Turnstile runs on our sign-in page, our sign-up page and the event enrollment form. It is an anti-abuse check that replaces a CAPTCHA, and on the enrollment form it is what stops an automated script from running up face-matching costs. It may set a short-lived Cloudflare cookie to remember that the check passed. It is not an advertising product, it does not profile you, and Cloudflare does not use it to build an advertising audience.
Google Fonts supplies the typefaces on every page of this site, including client galleries and the family photo pages. Loading a font means your browser requests a file from Google, which necessarily discloses your IP address and the fact of the request to Google. No cookie is set and it is not used for advertising, but we would rather name it than let "no third-party tracker on your gallery" be read as "no third-party request at all". Those are different claims and only the first one is true.
We use no other third-party advertising or tracking cookies. Our own traffic counting uses Cloudflare Web Analytics, which does not use cookies and does not fingerprint visitors.
8. Security
Passwords are hashed and never stored in readable form. Session tokens are hashed. Data is encrypted in transit. Face vectors are held in a per-event collection scoped so that it cannot reach any other event's data.
Third-party credentials a Photographer entrusts to us are encrypted at rest with AES-256-GCM under a key held separately from the database, so the database on its own is not enough to read them. That covers Google Calendar OAuth tokens and Apple or iCloud app-specific passwords. A credential that cannot be encrypted is refused rather than stored in the clear.
An earlier version of this page said otherwise, and we are leaving a note rather than quietly editing it. Until 24 August 2026, iCloud app-specific passwords were stored with our database provider's standard protections and were not separately encrypted by us. That was disclosed here at the time and it has now been fixed. If you connected an Apple calendar before that date, disconnect and reconnect it from studio settings and the stored password is replaced with an encrypted one.
No system is perfectly secure and we cannot guarantee absolute security of anything transmitted to us.
9. Who else touches your data
We use a small number of companies to run Phramed. Each one gets only what it needs to do its job, and none of them is permitted to use it for their own purposes. This is the whole list.
| Who | What they do | What reaches them |
|---|---|---|
| Cloudflare | Hosting, the database, photo storage, anti-abuse checks | Everything on this page, since the product runs on their network. Photos are stored in their object storage and are not public. |
| Stripe | Payments and Photographer subscriptions | Buyer name, email and amount. Card numbers go to Stripe directly and never reach us. |
| Resend | Sending email | The recipient's email address and the contents of the message. That includes gallery delivery emails, booking confirmations, receipts, password resets, and the guardian consent request and its reminders. |
| Amazon Web Services | Face matching only (Rekognition) | The two reference photos and the resulting face vector, for participants who have consented. Nothing else about you, and nothing at all if a Photographer does not run face matching. |
| Calendar sync, and fonts on every page | Calendar sync only if a Photographer connects it, and only that Photographer's own booking data. Fonts disclose your IP address to Google on any page you load. See Section 7. | |
| Meta | Advertising measurement, marketing pages only | That a visit or a sign-up happened. Never on a page a Photographer's client sees. See Section 7. |
Data is stored in the United States. Our hosting runs on a global network, so a request may be served from an edge location near you, but stored data (the database, photos, and face vectors) is held in US regions.
10. Your rights
- Photographers can update or delete account information by contacting privacy@phramed.co, and can disconnect a calendar at any time from studio settings, which removes the stored credentials immediately.
- Clients can request access to or deletion of their information from the Photographer directly, or from us if the Photographer is unreachable.
- Event participants and guardians have the additional rights in Section 6, which apply regardless of where you live.
California residents have the right to know what personal information we collect and why, to request deletion or correction, to opt out of sale or sharing, and not to be discriminated against for exercising any of those rights. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of, but the right to ask stands. Write to privacy@phramed.co.
11. How long we keep other data
- Photographer account data is kept while the account is active and for 30 days after closure, unless the law requires longer.
- Client data such as bookings, purchases and inquiries is kept while the associated Photographer account is active, and is controlled by that Photographer, who can delete a gallery or booking at any time.
- Biometric data has its own, shorter schedule in Section 6, which overrides everything in this section.
12. Children
Phramed accounts are for photographers and are not directed at children. Galleries and event photography often contain images of minors, uploaded and controlled by the photographer who took them, which is ordinary professional photo delivery rather than data collection from a child. The one place a minor's data is actively collected is event face matching, described in Section 6, which requires a guardian to sign before anything is processed.
13. Changes to this policy
We will post changes here and update the date at the top. For material changes we will email active Photographers.
14. Contact
Handled Agency LLCGreenville, South Carolina
privacy@phramed.co