Find Your Pictures

Privacy Policy

TriPrism, Inc. / PhotoTouch, Inc.

Effective: August 24, 2026

TriPrism, Inc., doing business as PhotoTouch, Inc. ("we," "us," or "our") operates the PhotoTouch platform, a suite of applications serving professional photographers and their customers. This Privacy Policy describes how we collect, use, disclose, and protect personal information across all PhotoTouch services.

By using any PhotoTouch service, you acknowledge that you have read and understood this policy. If you are a photographer using our platform, you are a data controller for your customers' information and are responsible for providing your own privacy disclosures. See our Data Processing Agreement for details on our role as processor.

1. Information We Collect

1.1 Photographer Account Information

When you register for a PhotoTouch account, we collect:

  • Name, company name, email address, phone number
  • Billing address and payment information (processed by Stripe)
  • Login credentials (passwords stored using one-way hashing)
  • Account configuration preferences and settings
1.2 Customer Information (Processed on Behalf of Photographers)

When photographers use our platform to serve their customers, we process:

  • Customer names, email addresses, phone numbers
  • Photo codes and gallery access credentials
  • Photographs uploaded by the photographer
  • Order and transaction records
  • Registration data collected at photography events
  • Support ticket communications
  • Model release consent records

We process this data as a data processor on behalf of the photographer (data controller). See our Data Processing Agreement.

1.3 Automatically Collected Information
  • IP addresses and browser user agent strings (for security and audit logging)
  • Login timestamps and session activity
  • Theme preference (light/dark mode, stored in browser localStorage)

2. How We Use Information

  • Service delivery: Operating the PhotoTouch platform, processing uploads, delivering galleries, fulfilling print orders, and sending communications on behalf of photographers
  • Account management: Managing photographer subscriptions, billing, and support
  • Security: Detecting and preventing unauthorized access, fraud, and abuse through audit logging, rate limiting, and anomaly detection
  • AI-powered features (opt-in): When enabled by the photographer, generating email templates and assisting with customer service triage. No customer photographs are shared with AI providers.
  • Communications: Sending transactional emails (password resets, account alerts) and photographer-initiated customer communications (gallery notifications, marketing campaigns)
  • Compliance: Maintaining SOC 2-aligned audit trails and controls, responding to lawful data requests, and supporting GDPR/CCPA obligations

3. How We Share Information

We do not sell personal information. We share data only as follows:

  • Sub-processors: Third-party service providers that assist in operating the platform (infrastructure, email delivery, payment processing, SMS). See our Sub-Processor Disclosure for the complete list.
  • Photographer-configured integrations: When a photographer connects their own third-party services (CRM, analytics, venue systems) via the API Integration Builder, data flows to those services under the photographer's control.
  • Legal requirements: When required by law, subpoena, court order, or to protect the rights, safety, or property of TriPrism, our users, or others.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to affected users.

4. International Data Transfers

The platform is hosted in the United States. If you access the platform, or have your photograph taken at an event run by a photographer using the platform, from outside the United States, your information is transferred to and stored in the United States.

Where data is held
  • Photo files and the application database: United States, in all cases, for all accounts and all regions.
  • Transactional email: United States.
  • Text messaging: Messages to Australian and New Zealand numbers can be routed through an Australian carrier (CellCast Pty Ltd) rather than offshore, at the photographer’s election.
Safeguards we apply
  • Data is encrypted in transit (TLS 1.2+) and at rest.
  • Every sub-processor is engaged under a written agreement imposing confidentiality and security obligations no less protective than those we owe you. See our Sub-Processor Disclosure.
  • Where personal data is transferred from the European Economic Area or Switzerland, we apply the EU Standard Contractual Clauses together with supplementary technical measures (encryption in transit and at rest). Transfers from the United Kingdom rely on the UK International Data Transfer Addendum to those Clauses. See our Data Processing Agreement, section 8.
Canada, Mexico and the United States territories

Puerto Rico and Guam are United States territories, so hosting for those accounts is domestic rather than a cross-border transfer; Puerto Rico’s Citizen Information on Data Banks Security Act and Guam’s own breach-notification requirements still apply. For personal information collected in Canada, PIPEDA provides no adequacy regime, so the transfer rests on contractual measures securing a comparable level of protection, together with our obligation to tell you that your information is processed outside Canada; where Quebec’s Law 25 applies, a privacy impact assessment precedes the transfer. For personal information collected in Mexico, transfer rests on the privacy notice given to you and on contractual measures binding the recipient to the same notice and purposes, under the Federal Law on the Protection of Personal Data Held by Private Parties.

Australia, New Zealand and Japan

For personal information collected in Australia, this United States hosting is a cross-border disclosure under Australian Privacy Principle 8. We take reasonable steps to ensure that overseas recipients handle personal information consistently with the Australian Privacy Principles, including by contract. By using the platform you acknowledge that your information will be handled in the United States and that United States law will apply to it. New Zealand personal information is disclosed overseas on the same basis under Information Privacy Principle 12 of the New Zealand Privacy Act 2020.

For personal information collected in Japan, cross-border provision is made under Article 28 of the Act on the Protection of Personal Information, on the basis of contractual measures requiring the recipient to maintain protections equivalent to those the Act requires.

5. Data Retention

  • Photographer accounts: Data is retained for the duration of the active account plus 90 days after closure to allow for reactivation and final billing.
  • Customer galleries and images: Held for the period the photographer configures, with a platform default of approximately 180 days, after which they are deleted. The period is configurable per account and per event.
  • Customer contact and registration data: By default this follows the lifecycle of the gallery it belongs to and is removed with it. Both periods are configurable by the photographer or operator running the event, so their own settings can separate the two — leaving contact details in place after the images have gone, or the reverse. The exceptions are consent records, opt-out state and model releases, which are kept so that a deletion elsewhere cannot erase the proof of what a person agreed to, and order records, which are kept for tax and financial record-keeping.
  • Photographer control: These are platform defaults. Photographers control their own retention through platform tools, may configure automatic deletion schedules, and may perform manual erasure at any time using the built-in GDPR tools.
  • Audit logs: Retained for a minimum of 7 years to support contractual, security, and regulatory obligations.
  • Security logs: Login attempts, rate limiting records, and IP logs are retained for 7 days and automatically purged.
  • Backup data: Backups follow the same retention schedule as primary data and are encrypted at rest.

6. Your Rights

For Photographers (Account Holders)
  • Access: View all data associated with your account through the platform dashboard
  • Correction: Update your account information at any time via My Account settings
  • Deletion: Request account closure by contacting support@phototouchinc.com
  • Portability: Export your account data in standard formats
  • Objection: Opt out of non-essential communications at any time
For Customers (End Users of Photographer Services)
  • Access & Deletion: Contact the photographer who collected your information. Photographers have built-in GDPR tools to export and delete your data.
  • Model release revocation: If you signed a model release, you can revoke consent at any time using the revocation link provided in your release email.
  • Escalation: If a photographer does not respond to your request within 30 days, contact us at support@phototouchinc.com and we will facilitate.
California Residents (CCPA/CPRA)
  • We do not sell personal information as defined under the CCPA.
  • We do not use personal information for cross-context behavioral advertising.
  • You may exercise your right to know, delete, or opt out by contacting support@phototouchinc.com.
European Economic Area (GDPR)

Our lawful bases for processing are: (a) performance of a contract (photographer accounts), (b) legitimate interest (security, fraud prevention), and (c) consent (where applicable). You may lodge a complaint with your local supervisory authority.

7. Children's Privacy

PhotoTouch is a business tool for professional photographers. We do not knowingly collect personal information directly from children under 13. Photographers who photograph minors (school photos, sports, events) are responsible for obtaining appropriate parental or guardian consent and complying with COPPA, FERPA, and applicable child protection laws.

No facial recognition or biometric processing. PhotoTouch does not perform facial recognition, biometric template generation, or cross-photo identity matching on any photographs, including those of minors.

8. Cookies & Local Storage

Type Purpose Duration
Session cookie Authentication and CSRF protection 2 hours (expires on inactivity)
Theme preference Remember light/dark mode choice Persistent (localStorage)
UI state Sidebar collapse, menu preferences Persistent (localStorage)

We conduct no third-party tracking of our own. We set no third-party tracking, advertising or analytics cookies, we operate no analytics property or advertising account against your traffic, and we share no data with advertising networks. Photographers and partner organizations are, however, given the opportunity to install their own tags on their own storefronts. Where a photographer does so, they are the controller of the data their tag collects and their chosen provider's privacy notice applies alongside this one. See Security Overview for what that setting accepts and how it is constrained.

9. Security

We implement industry-standard security measures to protect personal information. For detailed information about our security practices, see our Security Overview.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to active account holders in advance where practicable (target: 30 days before taking effect). The "Effective" date at the top of this page indicates when the policy was last revised. Continued use of the platform after changes take effect constitutes acceptance of the revised policy.

11. Contact Us

For privacy inquiries, data requests, or concerns:

Email
support@phototouchinc.com
Company
TriPrism, Inc. dba PhotoTouch, Inc.
Address
San Diego, California, United States

© 2026 TriPrism, Inc. All rights reserved.

Terms of Use  •  Sub-Processors  •  DPA  •  Security  •  RoPA  •  Back to Login