Privacy Policy & Cookie Policy
Last updated: 29 August 2026
1. Data Controller
The data controller for headshotqueue.com is:
TimmiStudio di VD
Trading as PortraitDesk / Headshot Queue
Italy
Email: info@headshotqueue.com
For any questions relating to this policy or to exercise your rights, contact us at the email above.
2. Data We Collect
2.1 Data you provide directly
- Account registration: name, email address, password (hashed), studio name.
- Payment: billing name and email. Card details are processed directly by Stripe and never stored on our servers.
- Support enquiries: any information you include when contacting us by email.
2.2 Data collected automatically
- Usage data: pages visited, time on page, referring URL, browser type, operating system, screen resolution, approximate geographic location (country/city level) — collected via Google Analytics 4.
- Cookies and similar technologies: see the Cookie Policy section below.
- Server logs: IP address, request timestamp, HTTP status code. Retained for 30 days for security purposes.
2.3 Data about your clients (photographers only)
If you are a photographer using the platform, you may upload or collect data about your own clients (names, email addresses, photographs, booking details). In this context you are the data controller for your clients' data and we act as a data processor on your behalf. We process this data solely to provide the platform service and never use it for our own purposes.
If you use the Sales Report feature, we also store client purchase records (product type, quantity, price, Stripe session ID, payment status) on your behalf. These records are visible to you in the Sales Report and are deleted when the associated job data is deleted.
3. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR): processing your account and payment data to provide the service you subscribed to.
- Legitimate interests (Art. 6(1)(f) GDPR): server log retention for security and fraud prevention.
- Consent (Art. 6(1)(a) GDPR): analytics and non-essential cookies, collected only after you accept via the cookie consent banner.
- Legal obligation (Art. 6(1)(c) GDPR): retaining transaction records as required by Italian fiscal law.
4. How We Use Your Data
- To create and manage your account.
- To process payments and send transaction receipts.
- To operate, maintain and improve the platform.
- To send transactional emails (gallery notifications, password resets). We do not send marketing emails without explicit opt-in.
- To measure and analyse platform usage (only with your consent).
- To detect, investigate and prevent security incidents and abuse.
- To comply with legal obligations.
5. Third-Party Services
We share data with the following third parties to operate the platform. We do not sell your data to any third party.
5.1 Stripe
Payment processing. When you subscribe, you are redirected to Stripe's secure payment form. Stripe collects and processes your card data under their own privacy policy. We receive a payment confirmation and customer reference only. Stripe is certified to PCI DSS Level 1.
Privacy policy: stripe.com/privacy
5.2 Stripe Connect
If you use the Sales Report, you connect your own Stripe account via Stripe Connect. When your clients make purchases, their payment data is processed directly by Stripe under Stripe's own privacy policy. We receive only payment confirmation metadata (session ID, status) — we never receive card details or funds. Stripe acts as an independent data controller for payment processing.
Privacy policy: stripe.com/privacy
5.3 Google Analytics 4
Used to analyse website traffic and user behaviour — only when you have given consent. Depending on our current configuration, this may load directly or through Google Tag Manager; either way it only runs after consent, and Google Tag Manager itself does not collect personal data independently. Google may process data in the United States. We have enabled IP anonymisation and do not use Google Analytics advertising features.
Privacy policy: policies.google.com/privacy
Opt out: Google Analytics Opt-out Browser Add-on
5.4 Google Fonts
We load the DM Sans typeface from Google Fonts. When your browser requests the font file, your IP address is transmitted to Google's servers. We use the standard Google Fonts API with display=swap.
Privacy policy: policies.google.com/privacy
5.5 Hosting provider
The platform is hosted on a server based in the European Union. The hosting provider processes server access logs containing IP addresses for security purposes.
5.6 Amazon Web Services (AWS) S3
Photos, logos, and other files uploaded to the platform are stored on Amazon S3, a cloud storage service, in a data center in the European Union. AWS processes this data solely to store and serve these files on our behalf, under AWS's own data processing terms, and does not access or use the content for its own purposes.
Privacy policy: aws.amazon.com/privacy
5.7 IP geolocation (cookie consent logging)
When you accept or reject cookies, we look up the approximate country your IP address is from, using ip-api.com, and record it as part of that consent log entry. The last segment of your IP address is removed before this lookup is made, and this service does not place cookies or track you across visits.
Privacy policy: ip-api.com/docs/legal
6. Data Retention
- Account data: retained for the duration of your account and for 2 years after account deletion, to comply with legal obligations.
- Payment records: retained for 10 years as required by Italian fiscal law.
- Client data uploaded by photographers: deleted within 30 days of account deletion or on written request.
- Minimal completion records (initials, photo count, and status kept after a photographer removes an individual client — see Section 7): retained indefinitely as a business record, since they contain no personal identifiers.
- Analytics data: retained for 14 months in Google Analytics, then automatically deleted.
- Server logs: retained for 30 days.
- Consent records: retained for 3 months as evidence of consent, then automatically deleted.
7. If You're the Subject of a Photo Gallery
If a photographer used this platform to deliver your photos, you access your gallery through a private link rather than a login. This section explains what that means for your data.
- Your gallery link is your access credential. Anyone who has it can view your gallery, your name, and your contact details, the same as anyone who has your email password could read your email. Don't forward or publicly post your gallery link if you'd rather keep it private.
- The photographer is the data controller for your information — not us. They decide why and how your registration details and photos are used for their business. We process this data on their behalf as their service provider.
- You can request a copy or deletion of your personal data (your name, email, and any answers you gave when registering) directly from your gallery, via the "My Data & Privacy" link. Exporting your data happens immediately. A deletion request does not: the photographer is notified and reviews it, since they may have a legal obligation — such as a contractual or tax record-keeping requirement — to retain certain information for a set period. If a photographer doesn't respond to a request in a reasonable time, we can step in and action it directly as the platform operator.
- A photographer can also remove you from their dashboard directly, separately from the request process above. When they do, your name, email, and any other identifying details are removed everywhere they appear, including from photo filenames. A minimal record is kept in place of the full one — your initials, how many photos were delivered, your final status, and the date you originally registered — so the photographer can still document completed work for their own business records (for example, to a company that hired them) without retaining your identity.
- Your photos themselves are not deleted through this process, under any circumstance. The photographs are the photographer's own copyrighted work, created and delivered as part of the service you already received — deleting your name and contact details doesn't undo that delivery. You hold a license to use your photos, not ownership of them; that license isn't affected by a data deletion request. If you have questions about your photos specifically, contact the photographer directly.
8. Your Rights Under GDPR
As a data subject in the EU you have the following rights. To exercise any of them, contact us at info@headshotqueue.com. We will respond within 30 days.
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate data.
- Right to erasure (Art. 17): request deletion of your data where there is no legal obligation to retain it.
- Right to restriction (Art. 18): request that we limit how we use your data.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to withdraw consent: withdraw consent for analytics cookies at any time via the cookie settings link in the footer.
- Right to lodge a complaint: you may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at garanteprivacy.it.
9. International Data Transfers
Google Analytics and Google Tag Manager may transfer data to the United States. These transfers are made under the EU-US Data Privacy Framework and Google's Standard Contractual Clauses, which provide appropriate safeguards under Art. 46 GDPR. Stripe operates under Standard Contractual Clauses for any transfers outside the EEA.
10. United Kingdom and United States Users
We're based in Italy and this policy is written primarily around the GDPR, since that's our home framework. Many of our photographers and their clients are in the UK and US, so this section covers what applies there specifically, and what doesn't.
10.1 United Kingdom
If you're in the UK, your data is protected under the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA). In practice this gives you the same core rights described in section 8 of this policy. One addition under the DUAA: you have a right to submit a formal data protection complaint directly to us, which we'll acknowledge promptly and respond to without undue delay — see our Data Protection Complaints page. You can also complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk at any time.
10.2 United States
There's no single federal privacy law in the US — instead, a growing number of states (including California, Virginia, Colorado, Connecticut, Texas, and others) have their own comprehensive privacy laws, each with different consumer rights and different rules about who they apply to. Most of these laws only apply to businesses above a certain size (typically $25 million or more in annual revenue, or data from 100,000 or more residents) — thresholds we don't meet today. A small number of states, including Texas and Nebraska, don't set a minimum size at all.
Regardless of which specific state law technically applies to us, we extend the same core rights to every US user as a matter of practice: access, correction, deletion, and portability, all described in section 8. If you're a California resident, note that we do not sell your personal information and have no plans to.
If your gallery includes anyone under 13, US federal law (COPPA) treats a photo or video of a child as personal information in its own right, and may require verifiable parental consent before it's collected. This is addressed further in our Terms & Conditions, since it's primarily something our photographers need to manage at the point of registration.
10.3 What we can and can't guarantee
We work hard to keep this platform privacy-compliant, and we build features — data export, deletion requests, consent logging, this complaints process — specifically to help both us and the photographers using our platform meet their obligations. That said, we can't guarantee that every photographer's use of the platform, for every one of their own clients, in every location, will automatically satisfy every law that might apply to them. Photographers are independently responsible for their own compliance with the laws of the places they and their clients are located, as set out in our Terms & Conditions. If you're a photographer with specific compliance requirements — for a particular state, a particular client, or a particular situation — please get in touch and tell us what you need; we're glad to talk through it.
11. Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- HTTPS encryption on all pages (TLS 1.2+).
- Passwords stored as bcrypt hashes — never in plain text.
- Payment card data never stored on our servers — handled entirely by Stripe.
- Access to production systems limited to authorised personnel only.
- Regular security reviews and dependency updates.
No method of transmission over the internet is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33–34 GDPR.
12. Cookie Policy
Cookies are small text files stored on your device by your browser. Below is a full list of cookies used on headshotqueue.com.
10.1 Strictly necessary cookies
These cookies are required for the platform to function. They do not require consent under GDPR.
| Cookie name | Provider | Purpose | Duration |
|---|---|---|---|
PHPSESSID | Headshot Queue | Maintains your login session. Without this cookie the platform cannot identify you between page loads. | Session (deleted when browser closes) |
10.2 Analytics cookies (require consent)
These cookies are only set after you accept analytics cookies via the consent banner.
| Cookie name | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics | Distinguishes unique users by assigning a randomly generated number as a client identifier. | 2 years |
_ga_* | Google Analytics 4 | Used to persist session state for GA4. | 2 years |
_gid | Google Analytics | Distinguishes users. Used to throttle request rate. | 24 hours |
10.3 Managing and withdrawing consent
You can change your cookie preferences at any time by clicking "Cookie settings" in the footer of any page. You can also refuse or delete cookies through your browser settings — note that refusing strictly necessary cookies will prevent you from using the platform.
13. Changes to This Policy
This policy is subject to change at any time, and we encourage you to check back here regularly. We may update this policy from time to time to reflect changes in our practices or applicable law. When we make material changes we will update the effective date at the top of this page and notify you by email at the address on your account. Continued use of the platform after changes constitutes acceptance of the updated policy.
14. Contact
For any questions about this policy or to exercise your rights:
TimmiStudio di VD (trading as Headshot Queue / PortraitDesk)
Italy
info@headshotqueue.com
We aim to respond to all requests within 30 days. For complex requests we may extend this by a further two months, in which case we will inform you of the extension within the first 30 days.