Privacy Policy
This version takes effect on 14 October 2026. Until that day the previous version still governs accounts that existed before 29 September 2026, and we emailed every account holder to say so. Accounts created from 29 September 2026 are on this version already.
This explains what we do with personal data, why we are allowed to do it, and what you can make us do about it. It covers photographers who hold an Xposure account and the clients and guests who open their galleries.
The company behind Xposure, and the one you would write to or complain about, is named in the legal notice, with its address. For data questions the address is privacy@xposureapp.net. We are small enough that Belgian law does not require us to appoint a data protection officer, so we have not; that email reaches the person who makes these decisions.
1. Who is responsible for what
Which of us answers for a piece of data depends on whose data it is.
- Your account is ours to answer for. When you sign up, we decide what happens to your name, your email address, your billing records, and how you use the product. We are the controller for that, and this policy is how we tell you about it.
- Your clients are yours to answer for. The photographs you upload, the people in them, your bookings, your orders, your signed contracts, and the answers your clients give to any questionnaire you send them belong to your side of the fence. You are the controller, we are your processor, and we act on your instructions. The terms of service contain the data processing agreement that governs this, written so that you can hand it to a client who asks you for one.
Because you are the controller, your clients need a privacy notice from you rather than from us. Every gallery carries a Privacy link for exactly that. If you have your own policy, put its address in Studio under Business details and the link goes there. If you have not, the link goes to a notice we publish in your name, built from those same business details, so your clients always have something to read and you are not left without one.
2. What we collect, and why we are allowed to
Under the GDPR every use of personal data needs a legal basis. Ours are below, next to what they cover, because a list of data with no reasons attached is not much use to anyone.
If you are a photographer with an account
- Account data. Your name and email address, your password as a hash, and two factor settings if you turn them on. We need these to give you the account you asked for, so the basis is performance of our contract with you. If you sign up or sign in with Google, Google sends us your name, your email address, whether Google has verified it, your profile photo and your Google account ID. We keep the ID to recognise you, and copy the photo into a new account when you sign up.
- Billing data. Your subscription status, invoices, and payment history. Stripe collects and holds the card number; we never see it and never store it. Basis: performance of the contract, and legal obligation for the parts our accounts have to keep.
- Payout and sales data. If you sell through the platform, the transaction records and payout status needed to route money to you, plus the business details you type in for invoices and contracts, such as your business name and VAT number. Basis: performance of the contract, and legal obligation for tax records.
- Usage and security data. Sign in times, IP addresses, and logs of what happened when something went wrong. Basis: our legitimate interest in keeping accounts from being broken into and in being able to debug our own software.
- Support conversations. Whatever you send us and what we said back. Basis: performance of the contract.
- Studio teams. If you join a studio on Xposure, its owner and admins see your name, email address, role, when you joined and when you were last active, and a log of what you change in their studio. While you work in a studio you see its galleries, bookings and client details on the studio's behalf; for that data the studio is the controller, as it is for its clients. Basis: performance of our contract with the studio, and the legitimate interest of the studio and of us in knowing who has access and who changed what.
One thing we do to the photographs themselves. An automated scanner checks thumbnails for nudity so that we can find content that breaks the rules in the terms of service, mainly anything illegal and anything explicit that has reached a public page or been put up for sale. The scanner flags; it does not act. When something is flagged, one of us looks at that thumbnail, which means a person at Xposure can end up seeing a photograph from a private gallery. We look at what was flagged and nothing else, it is logged, and since nudity in private galleries is allowed, the usual outcome is that we close it and nothing happens. Basis: our legitimate interest in keeping illegal material off the platform and keeping our payment processing alive, and legal obligation where the content has to be reported.
If you wrote to a photographer, opened a gallery, booked a session, or bought a photograph
Here the photographer decides and we carry it out. We are describing it so you can see what happens, not because we chose it.
- If you write to a photographer through their contact form. Your name, email address, your message, and the package you asked about if you picked one. The photographer can add their own notes and track the conversation from first message to booking. If you contacted them another way, they can add the enquiry by hand, with your phone number or your Instagram or WhatsApp handle if you gave one. We keep it for them and use it for nothing of our own.
- Booking and purchase data. Your name, email address, phone number if you gave one, what you booked or bought, and the payment, which Stripe handles. When the photographer adds VAT to a photo sale, Stripe also asks for your billing country and postal code to work out the right rate, and for a VAT number if you buy as a business. You can get back to your bookings through a sign in link sent to your email, with no password.
- Print orders. If you order prints or an album from a photographer's gallery: your name, email address, shipping address and phone number, the items you chose with the crop you set, and the payment, which Stripe handles. The photographer sees all of it, to check the order before it is printed. We send your name, shipping address, phone number and email address, together with the print files, to the print lab that makes and ships the order, and the lab hands the parcel to a carrier. Your order page opens from the link in your confirmation email, without a password. It shows the items, your shipping address, the status and the tracking, and it is where you report a problem. Anyone with that link can open the page, so treat it like your gallery link. If you report a problem, the description and photos you send go to the photographer, and, when the lab is at fault, to us and to the lab.
- Contract signatures. If you sign a contract, we keep the exact text you agreed to, your typed signature, and an audit record: the time, your IP address, and basic device information. That record is what makes the signature hold up later. The photographer sees the contract, not the audit data.
- Questionnaire answers. Your photographer can send you a questionnaire about your session, or about your enquiry before anything is booked. What you write in it is for them. We store it so they can read it and so you can come back through the same link and change what you said. We do not use it for anything of our own and we send it to nobody else. The link opens from your email without a password, so treat it like the rest of your booking links.
- Gallery access data. Your IP address and simple counts of what was viewed or downloaded. This keeps private galleries private, stops the platform being hammered by bots, and gives the photographer basic statistics about their own gallery.
One thing worth stating plainly: a client sign in link shows that client their own bookings, across every photographer they have booked through Xposure. A photographer sees only their own bookings and their own clients, never a client's history with anybody else.
A photographer also sees one record per client. It collects what that client did with them: enquiries, bookings, payments, signed contracts, questionnaire answers, the galleries linked to their sessions, and photographs bought in that photographer's galleries. Nothing from another photographer ever appears on it.
The photographer can add to that record a photo of you and your contact handles, such as Instagram or WhatsApp, as well as your address and their own tags. The photo is stored in their account like their other files.
3. Where it lives
Our servers, our database, and the original files you upload are in the European Union. The machines that run Xposure and hold the database are in Germany. Your original photographs are stored in Western Europe.
When somebody opens one of your galleries, copies of the images they are looking at get cached on servers near them, which may be outside the EU. That is what makes a gallery load quickly for a client on another continent. Those copies are temporary and they are only ever the images. The originals, your account, and everything in the database stay in the EU.
Print orders are the exception. The lab that makes a print receives the order and the file, and the plant that makes it can be outside the EU. Section 4 names the lab.
4. Who else touches it
We do not sell personal data, and we do not share it with anyone for their own purposes. These are the companies that process it in order for the platform to work, and there are no others. If we add or change one, account holders get at least 15 days notice.
- Hetzner, Germany. The servers, the database, and our analytics. Data stays in the EU.
- Cloudflare, United States. Storage for your original photographs, held in Western Europe, plus the network that delivers galleries and shields us from attacks. The cached image copies described above sit here. Transfers outside the EU run on Standard Contractual Clauses.
- Stripe, United States and Ireland. Our own subscription billing, and through Stripe Connect the payments your clients make to you and the payouts back. Stripe holds card details, the buyer's name and email, for print orders the shipping address and phone number, and where VAT applies their billing country, postal code and any VAT number they enter. Transfers run on Standard Contractual Clauses.
- Prodigi (Prodigi Group Ltd), United Kingdom, with production partners in the EU, the UK, the US and elsewhere. Only for print orders, and only in galleries whose photographer sells prints. Prodigi receives the client's name, shipping address, phone number and email address, and the print files, to make and ship the order. The order is made at the plant that serves the delivery address. The United Kingdom has an adequacy decision from the European Commission. Transfers to plants outside the EU and the UK run on Standard Contractual Clauses.
- Resend, United States. Transactional email: password resets, gallery links, booking confirmations. Transfers run on Standard Contractual Clauses.
- Backblaze, United States. Our off-site backups: a nightly copy of the photo storage and encrypted database dumps, held in the EU Central region. Backups are restore material only and nobody reads them in the ordinary course. Transfers outside the EU run on Standard Contractual Clauses.
- Google, United States. For signing in with Google, and for your calendar if you connect one. While you are signed out, our public pages load Google's sign in prompt, which offers to sign you in with the Google account your browser already uses. Loading it sends Google your IP address, your browser details and the address of the page, and Google reads its own cookies to see whether you are signed in to Google. Nothing reaches us unless you choose to continue; then Google sends us what the account data above lists. Basis: our legitimate interest in letting you sign in without a password. If you connect a Google Calendar, we read your busy times to work out availability and write events for confirmed bookings, and disconnecting revokes it. Google is certified under the EU US Data Privacy Framework.
If you add a calendar link, we store the link encrypted and keep only the times you are busy, never event titles or details.
Video in a gallery. A photographer can place a YouTube or Vimeo film in a gallery. Those two are not in the list above, because nothing reaches them while you are only looking at the page. We show a play button, on a still image or on a plain panel, and the film is requested when you press it. From that moment you are dealing with YouTube or Vimeo directly, under their privacy policy rather than ours, and they can see your IP address and set their own cookies. If you never press play, they never hear from you.
Beyond these, we hand over personal data only when the law makes us: a valid order from a court or an authority with the power to compel it. If that ever happens and we are permitted to tell you, we will.
5. Cookies, analytics, and session recording
Cookies we cannot do without. A secure, HTTP only session cookie keeps you signed in and keeps PIN protected galleries shut to everyone else. Cloudflare sets a cookie of its own to tell humans from bots. Neither tracks you anywhere and the platform does not work without them, so no consent banner is required for either.
Google sign in. While you are signed out, our public pages load Google's sign in prompt, and Google reads its own cookies to offer the account your browser is signed in to. We set no cookie for it ourselves; Google's script may set one of its own to remember that you closed the prompt. Section 4 explains what Google receives.
Your currency. If you pick euros or US dollars on a price, a cookie called xp_currency remembers that choice for a year. It holds only the currency. On a subscribed account it follows the currency your plan is billed in. Otherwise it is set only when you pick one.
Analytics. We use Umami, which we run ourselves on our own servers, to count traffic. It sets no cookies, keeps no persistent identifier, sends nothing to anybody else, and cannot follow you to another website. Before anything is sent, gallery and booking links have their secret part stripped out of the recorded URL, so a share link never lands in our statistics. There is no Google Analytics here, no Meta pixel, and no advertising network of any kind.
Embedded video. If you press play on a film in a gallery, YouTube or Vimeo sets its own cookies at that point. Nothing of theirs is set before you press. Section 4 explains what that hands over.
Session recording, and where it does not happen. On our public marketing pages, our pricing page, our comparison and tools pages, we record some sessions to see where the design confuses people: mouse movement, scrolling, clicks, and the shape of the page. This runs only for visitors we can place outside the EU, the EEA, the UK, and Switzerland, because inside those it would need your consent first, and we are not willing to put a cookie banner on the site to collect it.
It never runs anywhere else. Not in the dashboard, not on a client gallery, not on the sign in or sign up pages, and not on this page. Nobody's clients get recorded looking at their own photographs. If you can see this sentence, you are on a page we do not record.
6. Email
Two kinds, and you control one of them.
- Email we have to send. Account and security notices, billing, service and outage warnings, and changes to policies like this one. These are part of running your account or are required of us by law, so they carry on while your account is open and there is no way to switch them off.
- Newsletter and promotions. Only if you ask. The box on the signup form is empty until you tick it, and nothing goes out unless you do, or unless you turn it on later in your settings. So that the choice is provably yours rather than ours, we record when you gave it, which form it came from, and the IP address it came from. Basis: your consent, which you can withdraw at any time.
- Product updates. Real changes to Xposure, sent to account holders on the basis of our legitimate interest in telling customers about the thing they pay for. Off whenever you want.
Every marketing email has an unsubscribe link, and Settings then Emails has the switches. Turning all of it off never affects the first group.
7. How long we keep things
- Your account and photographs. While the account is open. When you delete it, we lock it immediately and permanently erase everything 30 days later. Those 30 days exist so that an account deleted by mistake, or by somebody who should not have had access, can be brought back. The email we send you when you start deletion contains the link that cancels it. Because the account is locked for those 30 days, you cannot sign in to export during them, so take your export before you delete. Nothing survives the 30 days except what the next line covers.
- Invoices, transaction records, and signed contracts. Seven years, which is what Belgian accounting law requires of us. We keep the record, not your photographs.
- Print orders. The order record is kept like other transaction records, for seven years. The shipping name, address and phone number are reduced to the country 90 days after the claim cutoff, the last day on which a problem can still be reported, counted from dispatch. For an order that was rejected, cancelled or never paid, the same period is counted from the day it closed.
- Print files. The files we prepare for the lab are deleted when the period for reporting a problem ends, or 7 days after an order is rejected or cancelled. Prodigi keeps its own copy for 30 days.
- Photos sent with a problem report. Deleted 90 days after the report is closed.
- Dormant free accounts. Deleted after 12 months without a sign in, with warnings by email first. This is described in the terms of service.
- Questionnaire answers. Kept with the booking or the enquiry they belong to, for as long as the photographer's account is open, then erased on the same 30 day path as the rest of it. Answers to an enquiry that never led anywhere go when that enquiry goes.
- Enquiries. One that never led to a client or a booking is deleted 12 months after it last changed. One that did is kept with that client's record for as long as the photographer's account is open. The photographer can delete any enquiry at any time.
- Security and access logs. Up to 12 months, then gone.
- Studio activity log. 90 days. An entry stays for that time even if the person who made it leaves the studio, because it is the studio's record.
- Analytics. Aggregate counts, kept indefinitely because they identify nobody. Session recordings, 30 days.
- Marketing consent records. For as long as we send you anything, plus three years, so we can show the consent was real if anybody asks.
8. Your rights
These apply to everyone in the EU and the EEA. We give them to everybody else as well, because running two standards would mean deciding which of your clients deserved the better one.
- See it. Get a copy of what we hold about you. Photographers can do this without asking us, in Settings under Privacy, which builds a full archive of the account.
- Fix it. Correct anything wrong. Most of it is editable in your settings.
- Delete it. Close the account and have the data erased, on the timetable in section 7.
- Take it elsewhere. The same export is a structured, machine readable archive you can hand to another service.
- Object, or ask us to pause. Where we rely on legitimate interest, you can tell us to stop and we will unless we have a compelling reason not to. For marketing there is no such reason, so objecting always wins.
- Withdraw consent. Wherever we asked for consent, you can take it back at any time. That does not undo anything done before you did.
Write to privacy@xposureapp.net and we will answer within a month. If you are a client of a photographer rather than an account holder, ask the photographer first: they control that data and we act on their instructions. If they cannot help, come to us.
If we get it wrong, you can complain to a data protection authority. In Belgium that is the Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, dataprotectionauthority.be. If you live elsewhere in the EU you can go to your own country's authority instead. Emailing us first is usually quicker, but this is your right and it does not depend on us.
9. Decisions made by machines
Nothing here decides anything about you automatically in a way that has legal or similarly significant effects, and we do not profile people. Spam filtering and abuse detection flag things for a person to look at, and never act on their own. Section 11 of the terms covers what happens when something is flagged.
10. Children
Accounts are for adults, 18 or over. We do not knowingly collect data from children, and if we find we have, we delete it. Photographs of children uploaded by a photographer are the photographer's responsibility, under whatever consent the law where they work requires.
11. Changes
When this policy changes, the version and date at the top change with it. For anything that materially affects you we will email account holders at least 15 days beforehand instead of quietly editing the page.
12. Contact
Data and privacy: privacy@xposureapp.net
Reporting illegal content: abuse@xposureapp.net
Everything else: hello@xposureapp.net
Postal address and company details are in the legal notice.