Back to Krovel
Privacy • Global Data Protection & Governance

Privacy Policy

Effective Date: September 19, 2026 • Version 2.0 (Commercial Release)

Privacy Principles & Commitments

Krovel is built for professional photography studios. We never sell or rent your personal information or your clients' photos to third-party data brokers or advertisers. We process client gallery data strictly on behalf of the photography studio (as a Data Processor under GDPR and a Service Provider under CCPA).

1. Scope & Legal Roles (Controller vs. Processor)

This Privacy Policy describes how Krovel ("Krovel", "we", "us", or "our") collects, uses, stores, and protects personal information across our website, dashboard, and client proofing galleries.

Under global data protection laws, including the European Union General Data Protection Regulation (EU GDPR), the UK GDPR, and the California Consumer Privacy Act / Rights Act (CCPA/CPRA), our legal role depends on the category of data being processed:

1. Studio as Data Controller

For all photographs, client names, selection records, and gallery content uploaded to Krovel, the Photography Studio is the Data Controller (or "Business" under CCPA). The studio determines how photos are captured and shared with clients.

2. Krovel as Data Processor

Krovel acts strictly as a Data Processor (or "Service Provider" under CCPA) on behalf of the studio. We process, store, and stream photos only pursuant to the studio's contractual instructions and gallery settings.

Krovel acts as an independent Data Controller solely for studio account holder details (e.g., photographer email, billing credentials, and direct support communications).

2. Information We Collect

We collect information across three distinct categories:

  • Photographer & Studio Account Data: Email address, hashed password (salted bcrypt), studio business name, custom logo, theme accent colors, billing address, and transaction identifiers. Payment card details and UPI tokens are handled directly by our certified payment processor (Razorpay) and are never stored on Krovel servers.
  • Client Gallery Content & Proofing Data: Client event names, client contact tags (email or phone for gallery attribution), photographic images, preview files, client heart selections, selection timestamps, and image notes.
  • Technical, Log & Security Information: Device user-agent, operating system, browser type, and masked IP addresses. IP addresses are processed strictly on server endpoints to enforce brute-force rate limits (e.g., locking out attackers after 5 failed passcode attempts) and protect against automated denial-of-service attacks.

3. How We Use Your Information & Legal Bases (GDPR)

We process personal information under the following legal bases pursuant to GDPR Article 6:

  • Contract Performance (Art. 6(1)(b)): Providing the proofing service, generating presigned S3 upload URLs, streaming 1600px web previews, recording selections, and exporting deliverable ZIP archives.
  • Legitimate Business Interests (Art. 6(1)(f)): Enforcing gallery passcodes, preventing brute-force attacks, diagnosing platform latency, and maintaining high-availability cloud infrastructure.
  • Legal Compliance (Art. 6(1)(c)): Generating tax receipts, complying with statutory financial record-keeping (IRS, HMRC, EU VAT OSS), and fulfilling statutory reporting obligations.

4. Biometric & Facial Recognition Disclaimer

Biometric Data Disclaimer (BIPA, CUBI & WA Compliance)

Krovel does NOT scan face geometry, extract facial vectors, create biometric templates, or utilize artificial intelligence facial recognition systems on uploaded photographs. Standard photographs and downsampled web previews hosted on Krovel do not constitute biometric identifiers under the Illinois Biometric Information Privacy Act (740 ILCS 14/ "BIPA"), Texas CUBI, or similar biometric statutes.

If facial search features are ever introduced in future updates, they will operate strictly on an explicit, affirmative opt-in consent basis with temporary, ephemeral vector deletion following search completion.

5. Subprocessors & International Data Transfers

To deliver high-availability cloud infrastructure, Krovel engages trusted third-party service providers ("Subprocessors"). Each subprocessor is vetted for compliance with international data security standards:

SubprocessorLocationRole & PurposeTransfer Safeguards
Amazon Web Services (AWS)USA (us-east-1)S3 Object Storage, RDS PostgreSQL, CloudFront CDNAWS DPA + EU Standard Contractual Clauses (SCCs)
Razorpay Software Private LimitedIndia / GlobalPayment processing, UPI/Card gateway & subscription billingPCI-DSS Level 1 Certified, ISO/IEC 27001, Data Processing Agreements
Amazon Web Services (AWS SES)USA (us-east-1)Transactional emails (passcode resets, invites)AWS Customer Agreement + DPA

Cross-border data transfers to the United States are governed by the European Commission's Standard Contractual Clauses (SCCs - Module 2) and the UK International Data Transfer Addendum (IDTA).

6. California Privacy Rights (CCPA / CPRA Notice)

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA):

  • No Sale or Sharing: Krovel does not "sell" or "share" personal information or photographs of California residents to third parties for monetary or other valuable consideration.
  • Service Provider Certifications: We certify that we retain, use, and disclose personal data uploaded by studios solely for the specific business purpose of providing the proofing service, and will not retain or use it outside the direct commercial relationship.
  • Consumer Rights: California residents have the right to know what personal data is collected, request deletion, and not be discriminated against for exercising their rights. Since gallery photos are controlled by the photography studio, consumer requests regarding gallery content should be directed to the studio.

7. Data Retention & Right to Erasure (GDPR Art. 17)

We adhere to strict data minimization and retention policies:

  • Active Account Retention: We store photographs and client proofing data for the active duration of the studio's subscription and gallery status.
  • Studio Deletion & Recycle Bin: Studios can delete individual images, client selections, or entire shoots at any time. Individual photo deletions enter a 15-day safety Recycle Bin before permanent S3 purge (unless immediately emptied by the studio), while full gallery deletions initiate immediate irreversible removal from Amazon S3 and PostgreSQL.
  • Expired & Cancelled Accounts: Following account cancellation, studios have a 14-day grace period to export selections. After 30 days of prolonged non-payment, stored assets are permanently scheduled for S3 deletion.
  • Financial & Tax Records: Invoices, transaction identifiers, and tax records are retained for seven (7) years to comply with statutory legal and accounting obligations.

8. Security Architecture & Safeguards

Krovel employs defense-in-depth technical safeguards to protect photographic assets and user data:

  • Presigned S3 Access Controls: Uploads and downloads are authenticated via short-lived AWS S3 presigned URLs, ensuring images are never publicly browsable or enumerable.
  • Cryptographic Passcode Security: Client gallery passcodes are protected using salted scrypt key derivation and constant-time server-side verification (with backward-compatible SHA-256 support).
  • PostgreSQL Tenant Isolation: Data access is partitioned by photographer ID, ensuring strict tenant isolation across queries.
  • Encryption in Transit & at Rest: All web traffic is encrypted using TLS 1.3 / HTTPS. Storage on Amazon S3 and Amazon RDS is encrypted at rest using industry-standard AES-256 encryption keys.

9. Cookies & Tracking Technologies

Krovel uses strictly necessary cookies and local storage tokens required for platform security and operation:

  • Strictly Necessary Auth Cookies: The HTTP-only krovel_session cookie verifies user authentication and maintains secure session state. These cookies do not require prior consent under the EU ePrivacy Directive.
  • Client Gallery Selections (Local Storage): Client selections are cached locally in the browser to provide optimistic UI updates and prevent selection loss during mobile network fluctuations.
  • Zero Third-Party Ad Trackers: We do not deploy third-party advertising cookies, cross-site trackers, or surveillance pixels (e.g. Meta Pixel, Google AdSense) on client galleries.

10. Children's Privacy (COPPA Compliance)

The Service is a commercial business-to-business platform designed for professional photography studios. We do not knowingly collect personal registration data from children under the age of 13. When studios photograph family events involving minors, the studio warrants that it has secured appropriate parental or guardian consent under applicable law.

11. Contact & Data Protection Officer

For inquiries regarding this Privacy Policy, data subject rights requests, or to execute a Data Processing Agreement (DPA), please contact:

Krovel Privacy & Data Governance Office
Data Protection Email: privacy@krovel.com
Security & Legal: legal@krovel.com
© 2026 Krovel Platform • All Rights Reserved.