← Back to home

Privacy Policy

Last updated: June 15, 2025

Digital Memories Platform (“DMP,” “we,” “our,” or “us”) is a software-as-a-service platform for photography and videography studios. This Privacy Policy explains what information we collect when you or your clients use our platform at digitalmemoriesplatform.com (the “Service”), how we use and protect that information, and the choices available to you. By using the Service you agree to this Policy.

1. Introduction

DMP provides photography studios with an integrated workspace covering client relationship management (CRM), bookings and scheduling, invoicing and payments, client-facing galleries, and messaging via email and WhatsApp Business. Studios use DMP to run their own business; their clients typically interact with DMP only when receiving a gallery link, an invoice, a booking confirmation, or a WhatsApp message initiated by their studio.

Protecting the personal information handled through the Service is fundamental to our business. We aim to collect the minimum data required to operate the Service, keep it secure, and give both studios and their end clients meaningful control over the data that concerns them.

2. Information We Collect

We collect information in the following categories:

Account Information

When you register as a user of DMP we collect your name, email address, phone number, password (stored as a one-way hash), preferred language, and, if you enable multi-factor authentication, information used to verify the second factor.

Studio Information

For each studio (organization) using DMP we collect the business name, business address, logo and brand assets, tax identifiers (such as GSTIN where applicable), team member accounts and their assigned roles, and business preferences (currencies, package configurations, working hours).

Client Information

Studios upload information about their own clients (leads, couples, event organizers). This typically includes the client’s name, contact details (email, phone), event details (date, venue), preferences captured during onboarding, and any notes the studio records for its own service delivery.

Booking & CRM Data

Booking records, quotations, contracts, invoices, communication history, task assignments, follow-ups, and pipeline stages that a studio maintains inside DMP.

Uploaded Photos & Videos

Studios upload event deliverables such as photographs, videos, and album previews to share with their clients through DMP galleries. This content is treated as confidential and access is restricted to the owning studio and the recipients the studio grants access to.

Payment Information

When a client pays a studio through DMP, we facilitate the transaction using a licensed payment processor (currently Razorpay for Indian rupee transactions). Full card numbers, UPI credentials, and other sensitive payment credentials are entered directly on the processor’s hosted flow and never touch our servers. We retain a transaction reference, the amount, the payment status, and masked identifiers (for example the last four digits of a card) for reconciliation, receipts, and refund handling.

Device & Browser Information

IP address, user-agent string, device type, operating system, browser version, referring URL, and approximate location derived from the IP address. This information is collected automatically when you interact with the Service and is used primarily for security, abuse prevention, and diagnostics.

Usage Analytics

Aggregated and de-identified information about how the Service is used, such as which features are accessed, session duration, error frequency, and API request rates. We use this information to improve the product. Where user-level analytics are recorded, they are stored under the studio’s organizationId and are subject to the same access controls as the studio’s operational data.

3. How We Use Your Information

We use the information described above to:

  • Create and administer studio and user accounts and authenticate access.
  • Operate CRM, booking, invoicing, and gallery workflows on behalf of studios.
  • Send transactional communications to studios and their clients (email, WhatsApp, in-app notifications) that are directly related to a booking, gallery, invoice, or account event.
  • Process payments through a licensed payment provider and reconcile settlements.
  • Provide customer support, respond to inquiries, and diagnose issues you report.
  • Monitor and improve platform performance, reliability, and feature usability.
  • Detect, prevent, and investigate security incidents, fraud, and abuse.
  • Comply with applicable laws, respond to lawful requests, and enforce our terms.

We do not use client photographs, videos, or private CRM notes to train machine-learning models. Any product intelligence or benchmark features are derived from aggregated, de-identified metrics that cannot reasonably be linked back to an individual studio’s clients.

4. WhatsApp Business Integration

DMP integrates with the Meta WhatsApp Business Platform so that studios can send booking confirmations, reminders, delivery notifications, and gallery links to their clients from their own WhatsApp Business number. Key facts about this integration:

  • Connection is initiated by the studio through Meta’s Embedded Signup (also known as WhatsApp Coexistence) flow. The studio authenticates directly with Meta, selects the WhatsApp Business Account and phone number they want to use, and explicitly authorizes DMP to send messages on their behalf.
  • DMP stores the access token issued by Meta encrypted at rest. The token is used only server-side to deliver messages that the studio (or automated workflows configured by the studio) has originated. The token is never transmitted to any end-client’s browser.
  • DMP does not read the studio’s existing WhatsApp conversations. The integration is scoped to sending messages on behalf of the connected number and receiving delivery, read, and reply status callbacks for messages initiated through DMP.
  • Existing conversations between the studio and its clients remain under the studio’s control on their own device or WhatsApp Business app.
  • The studio may disconnect the integration at any time from Studio Settings → Integrations → WhatsApp. Disconnecting removes the encrypted token from our systems and instructs Meta to unsubscribe DMP from further webhook events for that WhatsApp Business Account.
  • All messaging is subject to the WhatsApp Business Messaging Policy and applicable local regulations. Studios are responsible for obtaining their clients’ consent to receive WhatsApp messages where required by law.

5. Third-Party Services

DMP relies on the following third-party services to deliver the platform. Each provider processes only the data required for its specific function and is bound by its own terms and privacy commitments.

  • Meta WhatsApp Business Platform — delivery of WhatsApp messages initiated by studios and receipt of related delivery status callbacks.
  • Facebook Login for Business (Meta) — the authorization surface studios use to complete WhatsApp Embedded Signup. DMP receives only the connection credentials and business metadata a studio explicitly authorizes.
  • Razorpay — processing of Indian rupee payments and payouts. Sensitive payment credentials are entered on Razorpay’s hosted flow and are not stored by DMP.
  • Amazon Web Services (AWS S3) — storage of uploaded photographs, videos, and other studio deliverables. Storage buckets are configured with private access and TLS in transit.
  • Resend — delivery of transactional email such as password resets, invoices, and gallery invitations.
  • MongoDB (managed database hosting) — primary operational data store.
  • Google OAuth (planned) — a future optional sign-in method for studio users. This integration is not active at the time of the “Last updated” date above; when it launches we will use it only for authentication and will not access unrelated Google services.

We do not claim compliance certifications (such as SOC 2, ISO 27001, HIPAA, or PCI-DSS Level 1) that we have not actually obtained. If we obtain any such certifications in the future, this Policy will be updated to reflect them.

6. Data Security

We apply industry-standard technical and organizational controls to protect the information we handle. Current safeguards include:

  • All traffic between clients and the Service is encrypted in transit using HTTPS/TLS.
  • User passwords are stored as one-way hashes (bcrypt) and are never retrievable in plaintext.
  • Third-party access tokens (for example WhatsApp Business tokens issued through Embedded Signup) are encrypted at rest using AES-256-GCM with keys held only on the server.
  • Authentication uses signed JSON Web Tokens (JWT) with short expiries and server-side revocation for administrative sessions.
  • Access to studio data is governed by role-based permissions (Owner, Manager, Team Member, and other studio-defined roles) enforced at the API layer.
  • Every request is scoped to the authenticated organization; each studio’s data is logically isolated in the database and cross-tenant access is prevented at the query layer.
  • Administrative and privileged actions are recorded in audit logs.
  • Backups are taken regularly and access to production infrastructure is restricted to a limited set of authorized personnel using multi-factor authentication.

No system can be guaranteed to be perfectly secure. We continuously review our controls and encourage users to help us keep the Service safe by using strong, unique passwords, enabling multi-factor authentication when available, and reporting suspected security issues to the address in Section 13.

7. Data Sharing

We do not sell your personal information, and we do not rent or trade it with advertisers.

We share information only in the following limited circumstances:

  • Service providers listed in Section 5, strictly to the extent necessary for them to deliver their service to us. These providers are bound by contractual confidentiality and security obligations.
  • Within a studio’s own organization, so that authorized team members can collaborate on the same clients, bookings, and galleries under the roles the studio assigns.
  • Legal and regulatory obligations, when we are required by law to disclose information in response to a valid legal request, or where disclosure is necessary to protect the rights, safety, or property of DMP, its users, or the public.
  • Business transfers, if DMP is involved in a merger, acquisition, or sale of assets, in which case users will be notified before their information becomes subject to a different privacy policy.

8. Data Retention

We retain information for as long as an account is active or as needed to provide the Service, comply with legal obligations (for example tax and accounting retention requirements), resolve disputes, and enforce our agreements.

When a studio closes its account, the studio’s operational data (leads, bookings, galleries, WhatsApp connection) is scheduled for deletion or anonymization within a reasonable period, subject to any legal hold or ongoing legitimate business need. Backup copies are removed on the applicable backup rotation cycle. Financial records that must be retained under law (for example invoices and tax filings) are kept for the period required by that law.

You may request accelerated deletion of specific records at any time by contacting the address in Section 13; we will honor the request except where retention is legally required.

9. Your Rights

Subject to applicable law and to verification of your identity, you may:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate or incomplete.
  • Delete your account and request removal of associated personal data, subject to Section 8.
  • Export your studio data in a machine-readable format where the feature is supported.
  • Object to or restrict certain processing activities where applicable law provides that right.
  • Withdraw consent for optional processing (such as marketing communications) at any time.
  • Lodge a complaint with a competent data protection authority in your jurisdiction.

End clients of a studio (for example a couple whose photographs are hosted by their photographer through DMP) should first contact the studio, which is the controller of that data. DMP will assist studios in honoring valid requests from their clients.

10. Cookies and Similar Technologies

We use cookies and similar technologies for the following purposes:

  • Essential cookies that are necessary for the Service to function, such as maintaining a user session and remembering that you have accepted the terms.
  • Authentication and session tokens that keep you signed in securely across pages.
  • Preference cookies that remember settings such as language, sidebar collapsed state, and dashboard filters.
  • Analytics cookies that help us understand aggregate usage patterns. Where used, analytics are configured to minimize personal information collection.

You can control cookies through your browser settings. Disabling essential or authentication cookies will cause parts of the Service to stop working.

11. Children\u2019s Privacy

DMP is a business tool intended for use by photography and videography studios and their staff. It is not directed to children, and we do not knowingly collect personal information from individuals under the minimum age required by applicable law in their jurisdiction (16 in most of the European Economic Area, 13 in the United States, and 18 in India for certain purposes). If you believe a child has provided us with personal information, please contact us and we will take reasonable steps to delete it.

12. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal obligations, or the Service. When we make material changes we will update the “Last updated” date at the top of this page and, where appropriate, provide notice through the Service (for example a banner on your studio dashboard or an email). Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

13. Contact

If you have questions about this Policy, want to exercise your rights, or wish to report a privacy or security concern, please contact us:

We aim to respond to privacy requests within a reasonable time frame and, in any event, within the periods required by applicable law.

© 2026 Digital Memories Platform. This Policy is provided for transparency and does not create any contractual right beyond those expressly stated in our Terms of Service.

Privacy Policy — Digital Memories Platform · Digital Memories Platform