Privacy Policy
Last updated 28 August 2026
Who we are
Aperture is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For photographers’ own account data we are the controller. For the buyer data a photographer collects through their storefront, the photographer is the controller and we are their processor. Contact for privacy matters: hello@aperture.pictures.
What we collect from photographers
Name, email address and password hash for your studio account; organisation name and subdomain; your Stripe customer and Connect account identifiers (we never see full card numbers); subscription status; the photographs, subject lists, sections, packs and prices you upload; and server logs of your use of the studio.
What we collect from buyers
Buyers can browse with only an access code, in which case we store a signed, short-lived session token in their browser and nothing about them on our servers until they buy. At checkout Stripe collects the email address and payment details; we receive the email address, the order contents and the Stripe payment reference. Buyers who choose to create an account give us an email address (verified by one-time code) so they can see their order history. Storefront request logs record IP addresses for security purposes only; rate limiting stores a one-way hash of the address, not the address itself.
Why we use it
To run the studio and storefronts; to process orders and deliver downloads; to send transactional email (sign-in codes, order confirmations, abandoned-cart reminders where the photographer has enabled them); to bill subscriptions; to prevent abuse; and to meet legal obligations. We do not sell personal data and we do not use buyer data for advertising.
Who else sees it
Stripe (payments, subscriptions, tax), our hosting and database providers, our image storage and delivery provider, our transactional email provider, our background-job provider, and our error-monitoring provider — each under a data-processing agreement and only to the extent needed to provide their service. The photographer whose storefront you bought from sees your order and email address so they can fulfil it.
How long we keep it
Order records are kept for as long as tax and accounting law requires (typically 7–10 years). Photographs and galleries are kept while the photographer’s account is active and deleted within 90 days of closure. Buyer session tokens expire within 24 hours; order-download links expire after 90 days. Rate-limit counters are discarded within the hour. Logs are retained for up to 30 days.
Your rights
Depending on where you live you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to complain to a supervisory authority ([SUPERVISORY AUTHORITY]). Buyers should first contact the photographer they bought from, since they control that data; we will assist them in responding. Photographers can contact us at the address above.
International transfers
Our providers may process data outside your country. Where data leaves the EEA or UK we rely on adequacy decisions or standard contractual clauses with the provider.
Cookies and local storage
We use strictly necessary cookies for studio and buyer sign-in, and browser local storage for the buyer’s gallery session and cart. We do not use advertising or cross-site tracking cookies.
Changes
We will post changes here and update the date above. Material changes affecting photographers will also be announced in the studio.