Privacy policy
Last updated 10 October 2026
This policy explains what personal data Photomitra (“Photomitra”, “we”) handles, why, where it is kept, for how long, and the rights you have under India's Digital Personal Data Protection Act, 2023. Questions: privacy@photomitra.com.
1. Who this policy is for
- Website visitors on photomitra.com, including anyone who books a demo.
- Studios: photographers and their teams who use Photomitra. For their own account data, we decide how it is used.
- Guests and clients of a studio: people who open a studio's photo page, album or link. The studio decides to collect this data for its event; we process it on the studio's behalf and only as described here.
2. What we collect
From website visitors
- What you type in the demo form: your name, studio name, WhatsApp number, city (optional) and the page you sent it from.
- Basic technical data our servers record for security, such as your IP address, browser and the time of a request.
From studios
- Account details: names, email addresses and phone numbers of the studio's users.
- Content the studio adds: events, photos, albums, portfolio stories, quotations, bookings, payment records and client details.
- Billing records for the Photomitra plan.
From guests and clients of a studio
- The name a guest gives before the photo search, and contact details only if they choose to share them with the studio.
- A selfie, used once to find the guest's photos. The selfie image is not saved. We keep a numeric face template (not a photo) to show new photos of the guest while the event is online.
- What a guest does with photos (views, downloads), so the studio sees how its delivery is used.
- Selections, notes and messages a couple or client leaves on albums and quotations.
3. Why we use it
- To provide Photomitra: deliver photos, run albums, websites and studio tools.
- To find a guest's photos from their selfie, with their consent.
- To answer demo requests and support questions, and to bill studios.
- To keep the service secure, prevent abuse and meet legal obligations.
We do not sell personal data, and we do not use guests' photos or face data to train AI models or for advertising.
4. Consent and children
Guests see a consent screen before their selfie is used, and can continue without the photo search if the studio allows the full gallery. For a child, a parent or guardian gives the consent. Anyone can withdraw consent at any time (section 8).
5. Where data is kept
- Our servers, the database and the archive vault run on Amazon Web Services in Mumbai, India.
- Event photos and small previews are stored and delivered through Cloudflare's global network (R2), which may serve them from outside India.
- Emails to our addresses pass through Cloudflare Email Routing.
These providers process data for us under their own security commitments and may not use it for their own purposes.
6. How long we keep it
- Event photos for guests: 24 hours after the event by default, up to 30 days if the studio chooses.
- Face templates: deleted together with the event's photos.
- Guest contact details shared with a studio: up to one year after consent, unless withdrawn earlier.
- Studio accounts: while the account is active. After non-payment, the account turns read-only and its data is deleted on day 45.
- Demo requests: until we no longer need them to follow up, or you ask us to delete them.
- Database backups are kept for a short period for recovery, then replaced.
7. How we protect it
Encrypted connections (HTTPS) for every page and download (cameras send photos over FTP, which most cameras can't encrypt), encrypted storage at our providers, private links that expire, optional PINs on client links with limits on wrong guesses, separation between studios, and a log of every administrator action. See Security & privacy.
8. Your rights
Under the DPDP Act you can ask to access, correct or erase your personal data, withdraw consent, and nominate someone to act for you.
- Guests can delete their own data from the studio's photo page (“Delete my data”) or ask the studio.
- Anyone can write to privacy@photomitra.com. We reply within 30 days, usually much sooner. Requests about a studio's guests are handled together with that studio.
9. Cookies
We use only the cookies needed for the service to work: staying signed in, remembering a guest's session and PIN access, and your theme choice. No advertising or tracking cookies.
10. Changes and contact
If we change this policy, we update the date above and tell studios by email before important changes take effect. Grievances and questions: privacy@photomitra.com.