ShootHarbor Privacy Policy
How ShootHarbor handles studio records, connected services, client pages and choices.
This policy explains the local-first operator app, synchronized workspace, public booking and client links, diagnostics, communications, purchases and privacy controls.
Overview
Blue Sparrow is a solo developer based in India and operates ShootHarbor for independent photographers and owner-operated studios. ShootHarbor includes the mobile app, synchronized API, public booking pages, tokenized client pages, support, notifications and related services. This policy is written for global use and applies data-minimisation, transparency, purpose-limitation, security and individual-rights principles supported by the EU General Data Protection Regulation and other applicable privacy requirements.
The photographer or studio normally decides why client, location, session, image, invoice and communication information is entered or shared. That operator is generally responsible for an appropriate basis, notices, permission, accuracy, retention and recipients for its professional records. Blue Sparrow handles connected copies to provide ShootHarbor and separately determines how account security, service operations, purchases, analytics, diagnostics and support information are handled.
ShootHarbor is local-first, not local-only. An ordinary on-device SQLite database and app-private media folder support offline work. Signed-in features synchronize supported records to the ShootHarbor API, and some publishing, messaging, subscription and notification features require other providers.
Data we handle
Depending on what an operator or public visitor uses, ShootHarbor may handle:
- Firebase and Google sign-in details such as user identifier, email, display name, profile image, authentication state and account timestamps.
- Studio details such as public slug, business and owner names, email, city label, timezone, currency, branding, contact preferences and public presentation settings.
- Offerings, prices, durations, availability, campaigns, slots, templates, automation preferences, policies and intake copy.
- Client and contact details such as names, email addresses, phone numbers, organisation labels, roles and notes.
- Property, venue or shoot information such as addresses, access notes, schedules, service selections, intake answers, workflow notes, checklists and operational history.
- Booking information such as requested time, confirmation code, status, referral channel, source URL, referrer and campaign context.
- Imported image files held in the app's local media folder and media metadata such as file name, type, size, dimensions, local path, upload state, storage key and selected delivery order.
- Delivery information such as title, client message, selected item identifiers, cover choice, publication state, public token and publication time.
- Shoot reports and invoices such as PDF content, file name, hash, selected image identifiers, line items, discounts, tax, totals, due date, payment state and communication status.
- Studio-supplied payment details such as account-holder name, IBAN, BIC, UPI identifier, payee name, provider or payment URLs, instructions, reference text and uploaded QR images. ShootHarbor does not receive a client's online-banking password and does not settle client funds.
- Public-link information such as raw bearer tokens, expiry or revocation state where supported, document identifiers and generated file-storage keys.
- Local synchronization information such as pending mutations, conflicts, retry state, device identifier and locally cached entitlement or usage status.
- Firebase Cloud Messaging token, notification permission and preference state, local reminder settings, queued message details, recipient, status, retries, provider identifier and limited audit metadata.
- Google Play, RevenueCat and Blue Sparrow subscription-gateway details such as product, transaction, receipt, entitlement, trial, renewal, cancellation and delivery state. Full payment-card details remain with the purchase provider.
- Firebase Analytics events such as authentication mode, app version, named screen and feature events. The mobile implementation can associate analytics with the Firebase user identifier after sign-in.
- Firebase Crashlytics crash, device, app-version and diagnostic information in non-debug builds where collection is active.
- Optional public-web analytics events when a GA4 measurement identifier is configured, including booking-page opens and submit progress or delivery-page opens with studio slug, workflow category and aggregate item counts.
- Support or feedback content such as message, subject, rating, reply email, account identity, generated idempotency value and a one-way hash of the requesting IP address used for rate limiting.
- API and hosting information such as request identifier, route, response status, timing, network address, security event and operational log entries.
The audited media-registration path sends metadata rather than the original imported image bytes and creates server-side preview placeholders. Report and invoice PDFs and payment QR images can be sent to backend storage. Product behavior may change only with an appropriate product and policy update.
The app deliberately removes the Android advertising-ID permission. It does not request contacts, location, microphone, camera or broad storage permission. It asks for notifications when the user enables them and opens the system image picker only after a user chooses an import action.
How we use data
Information is used to authenticate operators; maintain the local workspace; provide offerings, clients, locations, bookings, shoots, templates, delivery, reports, invoices and external-payment instructions; synchronize queued changes; publish public pages; generate or deliver documents; send operational email and notifications; validate plans and entitlements; support users; enforce quotas; prevent abuse; diagnose failures; measure feature use; protect the service; and meet applicable operational requirements.
Blue Sparrow does not sell or rent personal information and does not use ShootHarbor records for targeted advertising.
Where an appropriate basis is required, processing may be necessary to provide requested services, respond to a request, support a legitimate interest in secure and reliable operation, meet an applicable obligation, or act on consent. Operators remain responsible for the basis on which they handle client and photography information.
Storage and residency
The app stores its working database as an ordinary SQLite file and imported images as ordinary files in app-private storage. Application-level database or media encryption is not implemented in the audited build. Android platform backup and device-transfer extraction are disabled for app data, but device security, screenshots, rooted devices, user-created exports and files shared to other apps remain outside ShootHarbor's control.
Supported studio, client, booking, shoot, delivery, invoice, payment, notification, subscription and support records synchronize to PostgreSQL. Generated previews, report and invoice PDFs and QR images may be written to backend-managed file storage. Transport uses configured HTTPS endpoints in normal production use; this does not mean every stored file is application-encrypted.
Blue Sparrow-controlled synchronized content is intended to remain in European Union infrastructure, subject to verification of the live database, media root, backups, worker configuration and offsite copies. This is a qualified infrastructure commitment, not a statement that every ShootHarbor-related datum always stays in the EU.
Google, Firebase, RevenueCat, Google Play, analytics, crash, notification, mail and user-selected services may process limited data in other regions. Blue Sparrow support or operational access may occur from India.
Public links
A studio booking page is available through a public studio slug and may show studio identity, location label, offerings, prices and available times. Visitors can submit their contact, location, intake and scheduling information without an operator account.
Delivery, invoice and shoot-report URLs act as bearer links. Anyone who obtains a valid link can normally open the selected page or file without identity verification. Invoice and report links support expiry and revocation in the audited service. Delivery tokens are stored in raw form and the audited delivery schema does not define a separate expiry timestamp. Raw public tokens can also be synchronized into the local working copy.
The audited delivery frontend does not add an explicit no-index instruction for search engines. Operators should treat client links as shareable rather than secret, send them only to intended recipients, remove unnecessary sensitive detail and replace or disable access when a control is available. Recipients may save, forward, screenshot or otherwise retain content outside ShootHarbor.
Retention
Studio records are generally kept while the account is active and until the operator edits, removes or deletes the related workspace data. No single implemented schedule currently covers every account, synchronization, analytics, crash, security, notification, support and public-link record.
Hosted invoice and shoot-report links use a configurable expiry, with a service default of 60 days. File cleanup has a configurable grace period, but the cleanup worker defaults to disabled and dry-run unless production configuration enables actual deletion. Delivery tokens do not have a separate expiry field in the audited schema. Provider analytics, crash, purchase, message and delivery records follow provider or operational settings.
Account deletion first asks for recent Google confirmation, unregisters notification access where reachable, requests deletion of the PostgreSQL workspace and related cascading records, then deletes the Firebase Auth user and clears the local database. A minimal deletion tombstone is retained to prevent later subscription delivery from recreating the account. Google Play subscription cancellation is separate.
The audited deletion path does not explicitly remove every imported file from the local media folder or every backend file object after its database row is removed. Backups, security logs, provider records, already delivered email and recipient-held exports or links may also remain for a limited period or outside Blue Sparrow's control. These are release and deletion-verification gaps rather than promises of complete immediate erasure.
Security
ShootHarbor uses Google and Firebase authentication for operator access, HTTPS endpoints in normal production use, workspace-scoped API checks, queued-change validation, idempotency controls, restricted storage paths, high-entropy public tokens, notification token cleanup, safe diagnostic copy and Android backup exclusion. The backend encrypts selected operational secret values such as provider credentials under configured service keys.
No system is risk-free. Raw bearer tokens, an unencrypted local database, ordinary local media files, user-created exports, recipient forwarding, configuration mistakes and compromised devices remain meaningful risks. Operators should secure devices and Google accounts, minimise client information, review public content, use expiry or revocation where available and share links carefully.
Your rights
Depending on location and context, an individual may request access, correction, deletion, export, restriction, objection, withdrawal of consent or information about relevant processing. Operators can update many records in the app, share a redacted JSON export of the local working copy, disable notifications in system settings and manage subscriptions in Google Play.
The JSON export excludes media bytes, generated PDF bytes, credentials, provider tokens, private queue diagnostics and server-only history. It becomes an ordinary user-controlled file once shared.
Clients and public visitors should normally contact the photographer or studio first because that business decides how its professional records are used. Questions about Blue Sparrow's role or a request directed to ShootHarbor may be sent to [email protected]. Identity and authority may be verified before acting, and some information may be retained where reasonably necessary for security, purchase reconciliation or an applicable obligation.
Children and minors
ShootHarbor is a business tool for photographers and is not directed to children. Operators must be old enough to manage the account and must obtain appropriate authority before entering or publishing information about a child or minor.
Portrait, family, school, event or mini-session work may include names, scheduling details or images of minors. The photographer or studio is responsible for guardian permission, appropriate notices, image and usage rights, careful recipient selection and removal when required. Public links should not include more information than needed. Contact the responsible photographer first about a particular session and [email protected] about Blue Sparrow's processing.
International transfers
Blue Sparrow is based in India, its intended core connected infrastructure is in the EU, and its providers may operate globally. When limited data is processed across regions, Blue Sparrow uses provider agreements, access controls, data minimisation and other safeguards reasonably available for the transfer. Operators remain responsible for safeguards that apply to their own international client work and recipients.
ShootHarbor is designed to support EU GDPR principles and applicable global privacy rights. Compliance also depends on operator choices, deployed configuration, provider settings and the facts of each use; this policy is not a guarantee that every use is automatically compliant.
Changes
This policy may be revised when features, providers, risks or requirements change. The updated date will change, and a meaningful update may also be communicated in the app or on the Blue Sparrow website. An archived or translated copy may be provided for convenience, with the current English source controlling where permitted.
Contact
Blue Sparrow is operated by a solo developer based in India. Contact is provided online through the website and email channels below.
- Website: https://bluesparrow.dev
- General enquiries: [email protected]
- Privacy enquiries and requests: [email protected]
For a specific booking, photograph, delivery or invoice, contact the photographer or studio that created or shared it first.