Privacy Policy
Effective July 25, 2026 · Operated by [SportFramePro — legal entity name] (“SportFramePro”, “we”, “us”) · sportframepro.com
This Policy explains how SportFrameProcollects, uses, shares, and protects personal information, and the rights you have. It applies to our website, apps, and services (the “Services”). SportFrameProprovides booking, gallery, payments, and messaging software to independent sports photographers (“Businesses”).
Our roles (controller vs processor)
For a Business's account data and for visitors to sportframepro.com, SportFramePro is the data controller. For the personal data a Business collects from its own customers through the Services (bookings, athlete details, messages, photos), SportFramePro acts as a data processor / service provideron that Business's behalf; that Business is the controller and its own privacy notice governs. Contact the Business directly for requests about that data, or contact us and we will route it.
Contents
- 1. Information we collect
- 2. Facebook & Instagram data
- 3. How and why we use information (legal bases)
- 4. Cookies & similar technologies
- 5. How we share information / sub-processors
- 6. International data transfers
- 7. Data retention
- 8. Your privacy rights (GDPR, UK, CCPA/CPRA, others)
- 9. Security
- 10. Children
- 11. Automated processing & AI
- 12. Changes & contact
1. Information we collect
From Businesses (our direct users)
Name, email, mobile number, business name and details, login credentials/authentication identifiers, subscription and billing records, and payout details. Card and bank details are handled by Stripe; we do not store full card numbers.
From website visitors
Device and usage data (IP address, browser/OS, pages viewed, timestamps, referring page) and cookie identifiers (see §4).
From connected accounts (Facebook / Instagram)
When a Business connects a Facebook Page and/or Instagram professional account, we receive Page/account identifiers, the linked account username, an access token (stored server-side, never exposed to browsers), and the content and sender identifiers of messages sent to that Page/account so we can deliver them to the Business's inbox. See §2.
From a Business's customers (processed on the Business's behalf)
Contact details, athlete details (name, team, jersey number, position, age group as provided by the booking adult), booking and payment records, uploaded/captured photos, and the content of messages exchanged over SMS, email, Facebook, or Instagram.
2. Facebook & Instagram data
If a Business connects Facebook/Instagram via Facebook Login, we use Meta Platform data only to operate the unified inbox for that Business:
- list the Pages the person manages so they can choose one to connect;
- subscribe the chosen Page to receive message webhooks;
- receive incoming Messenger/Instagram direct messages and show them in the Business's inbox, with the sender's name/handle where permitted;
- send the Business's replies back to the sender.
We do not sell Meta Platform data, use it for advertising, or share it except with the infrastructure sub-processors in §5 that host the Services. Access tokens are stored encrypted at rest and server-side only. A Business can disconnect at any time (which removes the stored token and routing), and anyone may request deletion of their data (see our Data Deletion instructions). Our use of information received from Meta APIs follows the Meta Platform Terms and Developer Policies.
3. How and why we use information (legal bases)
We use information to provide, secure, and improve the Services; process bookings and payments; route and deliver messages across channels; send transactional communications; provide support; prevent fraud/abuse; and comply with law. Where the EU/UK GDPR applies, each purpose relies on a specific legal basis:
- Providing the Services, accounts, bookings, payments, and message delivery — performance of a contract.
- Securing and maintaining the Services, preventing fraud/abuse, and improving our product — legitimate interests (kept proportionate and balanced against your rights).
- Transactional messages about your account and bookings — performance of a contract; optional SMS/email marketing and non-essential/analytics cookies — consent (withdrawable at any time).
- Keeping tax, accounting, and other records the law requires — legal obligation.
We do not sell personal information or share it for cross-context behavioral advertising.
4. Cookies & similar technologies
We use cookies and similar technologies in these categories:
- Strictly necessary — sign-in/session, security, and core functionality. Always on; cannot be disabled.
- Functional — remember preferences (e.g. operator preview).
- Analytics — help us understand usage to improve the Services. Set only with your consent where required.
In the EU/UK and similar jurisdictions we request consent before setting non-essential cookies via our cookie banner, and you can change or withdraw your choice at any time using the Cookie preferences link. Necessary cookies are used on the basis of our legitimate interest in operating the Services.
5. How we share information / sub-processors
We share personal data only with service providers that process it on our behalf under contract, and as required by law. Core sub-processors:
- Google Cloud / Firebase — hosting, database, storage, authentication.
- Stripe — payment and subscription processing.
- Twilio — SMS delivery and receipt.
- Brevo — transactional email (outbound and inbound routing).
- Meta Platforms — Facebook/Instagram messaging (for connected accounts).
- Google (Generative AI) — optional photo tagging/culling assistance.
- Cloudflare — content delivery and security.
We may also disclose information to comply with law, enforce our terms, protect rights and safety, or in connection with a merger or acquisition (with notice where required).
6. International data transfers
We operate globally and process data on servers in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. Contact us for more information.
7. Data retention
We keep personal data only as long as needed for the purpose it was collected for:
- Billing, tax & accounting records — for the period the law requires (typically up to ~7 years).
- Booking, gallery, and message data — while the Business's account is active, then deleted or anonymized within 90 days of account closure unless you ask us to delete it sooner.
- Facebook/Instagram tokens & message routing — until you disconnect, then removed.
- Backups — overwritten on our rolling backup cycle, generally within 90 days.
You may request earlier deletion (see §8 and our Data Deletion page).
8. Your privacy rights
Depending on where you live, you may have the right to:
- Access a copy of your personal data;
- Correct inaccurate data;
- Delete your data (“right to erasure”);
- Restrict or object to certain processing;
- Portability — receive your data in a portable format;
- Withdraw consent at any time (e.g. cookies, SMS marketing);
- Opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of, but you may still contact us;
- Limit use of sensitive information (CPRA) — we treat authentication credentials, the contents of your messages, and any information about minors as “sensitive” personal information, and use it only to provide and secure the Services (a permitted purpose for which no separate “limit” option is required) — never to infer characteristics or for advertising;
- Non-discrimination for exercising your rights (CCPA/CPRA);
- Complain to your data protection authority (EEA/UK) — though we'd appreciate the chance to help first.
To exercise a right, email privacy@sportframepro.com or use our Data Deletion page. We will verify your request and respond within the time required by law. If your request concerns data a Business collected through us, we will refer you to, or coordinate with, that Business.
9. Security
We use administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit and at rest for sensitive credentials, access controls, and tenant isolation. No method of transmission or storage is 100% secure.
10. Children
The Services are not directed to children and are intended for use by adults. Bookings are made by a parent/guardian, who provides any athlete details for the session. We do not knowingly collect personal data directly from children under 13 (or the minimum age in your jurisdiction). If you believe a child provided us data, contact us and we will delete it.
11. Automated processing & AI
We may use AI tools (e.g. Google's generative AI) to assist Businesses with tasks like photo tagging and culling. These assist a human; we do not make decisions producing legal or similarly significant effects about you solely by automated means.
12. Changes & contact
We may update this Policy; we will post the new effective date and, for material changes, provide additional notice. Contact us at privacy@sportframepro.com or support@sportframepro.com, or by mail at [Company mailing address]. EEA/UK users may also contact our representative at [EU/UK representative — if appointed].
⚠️ Draft for review. Replace bracketed placeholders and have counsel review before relying on this document.