Legal

Privacy Policy & Cookie Policy

Last updated: 29 August 2026

Effective date: 29 August 2026  ·  Applies to: headshotqueue.com
If you're a client of one of our photographers — someone whose photo was taken at a session using this platform — and you've ended up here, this document describes how we, the platform, handle data. Your actual relationship is with your photographer directly: they're the ones who booked your session, deliver your photos, and control what happens with your information day to day. For anything about your session, your photos, a purchase, or your own personal data, please contact your photographer directly rather than us — they're best placed to help, and in most cases we won't have the answer ourselves. Section 7 below has more on your specific rights as the subject of a gallery.

1. Data Controller

The data controller for headshotqueue.com is:

TimmiStudio di VD
Trading as PortraitDesk / Headshot Queue
Italy
Email: info@headshotqueue.com

For any questions relating to this policy or to exercise your rights, contact us at the email above.

2. Data We Collect

2.1 Data you provide directly

2.2 Data collected automatically

2.3 Data about your clients (photographers only)

If you are a photographer using the platform, you may upload or collect data about your own clients (names, email addresses, photographs, booking details). In this context you are the data controller for your clients' data and we act as a data processor on your behalf. We process this data solely to provide the platform service and never use it for our own purposes.

If you use the Sales Report feature, we also store client purchase records (product type, quantity, price, Stripe session ID, payment status) on your behalf. These records are visible to you in the Sales Report and are deleted when the associated job data is deleted.

4. How We Use Your Data

5. Third-Party Services

We share data with the following third parties to operate the platform. We do not sell your data to any third party.

5.1 Stripe

Payment processing. When you subscribe, you are redirected to Stripe's secure payment form. Stripe collects and processes your card data under their own privacy policy. We receive a payment confirmation and customer reference only. Stripe is certified to PCI DSS Level 1.
Privacy policy: stripe.com/privacy

5.2 Stripe Connect

If you use the Sales Report, you connect your own Stripe account via Stripe Connect. When your clients make purchases, their payment data is processed directly by Stripe under Stripe's own privacy policy. We receive only payment confirmation metadata (session ID, status) — we never receive card details or funds. Stripe acts as an independent data controller for payment processing.
Privacy policy: stripe.com/privacy

5.3 Google Analytics 4

Used to analyse website traffic and user behaviour — only when you have given consent. Depending on our current configuration, this may load directly or through Google Tag Manager; either way it only runs after consent, and Google Tag Manager itself does not collect personal data independently. Google may process data in the United States. We have enabled IP anonymisation and do not use Google Analytics advertising features.
Privacy policy: policies.google.com/privacy
Opt out: Google Analytics Opt-out Browser Add-on

5.4 Google Fonts

We load the DM Sans typeface from Google Fonts. When your browser requests the font file, your IP address is transmitted to Google's servers. We use the standard Google Fonts API with display=swap.
Privacy policy: policies.google.com/privacy

5.5 Hosting provider

The platform is hosted on a server based in the European Union. The hosting provider processes server access logs containing IP addresses for security purposes.

5.6 Amazon Web Services (AWS) S3

Photos, logos, and other files uploaded to the platform are stored on Amazon S3, a cloud storage service, in a data center in the European Union. AWS processes this data solely to store and serve these files on our behalf, under AWS's own data processing terms, and does not access or use the content for its own purposes.
Privacy policy: aws.amazon.com/privacy

5.7 IP geolocation (cookie consent logging)

When you accept or reject cookies, we look up the approximate country your IP address is from, using ip-api.com, and record it as part of that consent log entry. The last segment of your IP address is removed before this lookup is made, and this service does not place cookies or track you across visits.
Privacy policy: ip-api.com/docs/legal

6. Data Retention

If a photographer used this platform to deliver your photos, you access your gallery through a private link rather than a login. This section explains what that means for your data.

8. Your Rights Under GDPR

As a data subject in the EU you have the following rights. To exercise any of them, contact us at info@headshotqueue.com. We will respond within 30 days.

9. International Data Transfers

Google Analytics and Google Tag Manager may transfer data to the United States. These transfers are made under the EU-US Data Privacy Framework and Google's Standard Contractual Clauses, which provide appropriate safeguards under Art. 46 GDPR. Stripe operates under Standard Contractual Clauses for any transfers outside the EEA.

10. United Kingdom and United States Users

We're based in Italy and this policy is written primarily around the GDPR, since that's our home framework. Many of our photographers and their clients are in the UK and US, so this section covers what applies there specifically, and what doesn't.

10.1 United Kingdom

If you're in the UK, your data is protected under the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA). In practice this gives you the same core rights described in section 8 of this policy. One addition under the DUAA: you have a right to submit a formal data protection complaint directly to us, which we'll acknowledge promptly and respond to without undue delay — see our Data Protection Complaints page. You can also complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk at any time.

10.2 United States

There's no single federal privacy law in the US — instead, a growing number of states (including California, Virginia, Colorado, Connecticut, Texas, and others) have their own comprehensive privacy laws, each with different consumer rights and different rules about who they apply to. Most of these laws only apply to businesses above a certain size (typically $25 million or more in annual revenue, or data from 100,000 or more residents) — thresholds we don't meet today. A small number of states, including Texas and Nebraska, don't set a minimum size at all.

Regardless of which specific state law technically applies to us, we extend the same core rights to every US user as a matter of practice: access, correction, deletion, and portability, all described in section 8. If you're a California resident, note that we do not sell your personal information and have no plans to.

If your gallery includes anyone under 13, US federal law (COPPA) treats a photo or video of a child as personal information in its own right, and may require verifiable parental consent before it's collected. This is addressed further in our Terms & Conditions, since it's primarily something our photographers need to manage at the point of registration.

10.3 What we can and can't guarantee

We work hard to keep this platform privacy-compliant, and we build features — data export, deletion requests, consent logging, this complaints process — specifically to help both us and the photographers using our platform meet their obligations. That said, we can't guarantee that every photographer's use of the platform, for every one of their own clients, in every location, will automatically satisfy every law that might apply to them. Photographers are independently responsible for their own compliance with the laws of the places they and their clients are located, as set out in our Terms & Conditions. If you're a photographer with specific compliance requirements — for a particular state, a particular client, or a particular situation — please get in touch and tell us what you need; we're glad to talk through it.

11. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

No method of transmission over the internet is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33–34 GDPR.

12. Cookie Policy

Cookies are small text files stored on your device by your browser. Below is a full list of cookies used on headshotqueue.com.

10.1 Strictly necessary cookies

These cookies are required for the platform to function. They do not require consent under GDPR.

10.2 Analytics cookies (require consent)

These cookies are only set after you accept analytics cookies via the consent banner.

10.3 Managing and withdrawing consent

You can change your cookie preferences at any time by clicking "Cookie settings" in the footer of any page. You can also refuse or delete cookies through your browser settings — note that refusing strictly necessary cookies will prevent you from using the platform.

13. Changes to This Policy

This policy is subject to change at any time, and we encourage you to check back here regularly. We may update this policy from time to time to reflect changes in our practices or applicable law. When we make material changes we will update the effective date at the top of this page and notify you by email at the address on your account. Continued use of the platform after changes constitutes acceptance of the updated policy.

14. Contact

For any questions about this policy or to exercise your rights:

TimmiStudio di VD (trading as Headshot Queue / PortraitDesk)
Italy
info@headshotqueue.com

We aim to respond to all requests within 30 days. For complex requests we may extend this by a further two months, in which case we will inform you of the extension within the first 30 days.