TriPrism, Inc. / PhotoTouch, Inc.
In the course of providing the PhotoTouch platform, TriPrism, Inc. engages certain third-party service providers ("sub-processors") that may process, store, or transmit data on behalf of our customers. This page lists all current sub-processors organized by category.
We maintain this list as part of our commitment to transparency and compliance with our SOC 2-aligned control framework, GDPR Article 28, CCPA/CPRA, and applicable data protection regulations.
Last updated: August 24, 2026 • Customers are generally notified of material changes in advance (target: 30 days where practicable).
These providers are integral to platform operations and process data for all accounts.
These providers are engaged only when a photographer enables the corresponding feature. The photographer controls activation and may provide their own credentials.
When photographers enable AI-powered features (email template generation, customer service assistance), data is processed by one of the following providers at the photographer’s discretion. Photographers may use platform-provided access or connect their own API credentials.
| Provider | Location | Compliance |
|---|---|---|
| Anthropic, PBC (Claude) | United States | SOC 2 Type II, GDPR DPA available |
| OpenAI, LLC (ChatGPT / GPT) | United States | SOC 2 Type II, GDPR DPA available |
| Google LLC (Gemini) | United States | SOC 2 Type II, ISO 27001, GDPR DPA available |
What is sent depends on the feature. Template and campaign generation sends the content being written. AI support-ticket triage sends the ticket together with a case file assembled from that customer’s own record, which includes their name, contact details and order, gallery and correspondence history. No photographs and no payment card data are ever sent to an AI provider. These features are off unless a photographer turns them on, and a photographer may connect their own provider credentials instead of using platform-provided access.
Photographers select their preferred payment gateway for processing customer orders on their storefront. Each photographer enables one or more of the following:
| Provider | Data processed | Compliance |
|---|---|---|
| Stripe, Inc. | Customer payment card data, billing address, card token and last four digits | PCI DSS Level 1, SOC 2 Type II |
| PayPal, Inc. | Customer payment card data, billing agreements, order amounts | PCI DSS Level 1 |
| Block, Inc. (Square) | Customer payment card data, transaction records | PCI DSS Level 1 |
| Worldpay (FIS) | Customer payment card data, transaction records | PCI DSS Level 1 |
When photographers enable customer-facing text messaging (gallery notifications, marketing campaigns), messages are delivered via:
| Provider | Coverage | Compliance |
|---|---|---|
| Twilio, Inc. | Global (primary: United States, Canada) | SOC 2 Type II, ISO 27001 |
| CellCast Pty Ltd | Australia & New Zealand | Australian Privacy Act compliant |
The platform conducts no third-party tracking of its own. Where a photographer or partner organization installs their own marketing tag, that tag runs on their storefront and the following providers receive data. The photographer is the controller of that data and their chosen provider’s own privacy notice applies alongside ours. The setting accepts validated identifiers only, so no arbitrary script can be introduced through it.
| Provider | Engaged when | Compliance |
|---|---|---|
| Google LLC (Analytics, Tag Manager, Ads) | A photographer supplies their own GA4 measurement id, Tag Manager container id, or Google Ads conversion id | SOC 2 Type II, ISO 27001, GDPR DPA available |
| Meta Platforms, Inc. (Facebook pixel) | A photographer supplies their own Meta pixel id | GDPR DPA available |
Tags are off unless a photographer turns them on, and are scoped to that photographer’s own accounts, locations and events. Where a photographer additionally supplies server-side conversion credentials, order and booking conversion events are sent from our servers to the provider they nominated; those credentials are stored encrypted. Live chat is disclosed separately: a photographer may install a widget from a vendor on a maintained host allow-list of recognized chat providers, and no session-recording or heatmap product appears on that list.
The PhotoTouch platform provides an API Integration Builder that allows photographers to create their own connections to third-party services (CRM systems, data warehouses, venue management platforms, analytics tools, etc.).
These integrations are configured, authorized, and controlled entirely by the photographer. TriPrism acts as the data conduit but does not select, manage, or maintain contractual relationships with these third-party services.
Photographers are responsible for establishing their own data processing agreements with any third-party services they connect via the API Integration Builder. All photographer-configured integrations include destination validation, data encryption in transit, per-record audit logging, and configurable annual compliance reviews.
TriPrism targets 30 days' advance notice where practicable before engaging a new platform sub-processor or making material changes to existing sub-processor relationships. Notifications are sent via email to all active account administrators.
Questions about our sub-processors or data handling?
Contact our compliance team at
security@triprism.com
or your dedicated account representative.
© 2026 TriPrism, Inc. All rights reserved.