CamSetu

Privacy Policy

Effective 31 July 2026 · Last updated 31 July 2026

Who we are

Camsetu is an event-photo platform: photography studios upload and organise event photos, and guests view, download and find their own photos in them. It is operated from India under the name Camsetu.

For anything in this policy — questions, requests, complaints — write to [email protected]. This policy explains what personal data we collect, why, where it lives, who else touches it, and what you can ask us to do with it, in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act).

What this policy covers

This policy covers the Camsetu product surfaces: the studio panel where studios manage their events, the guest surfaces (event galleries, join pages, flipbooks and portfolio pages studios share publicly), the Camsetu marketing site, and the Camsetu desktop uploader.

Two roles appear throughout, because we hold different data about each: studios (the photography businesses and their team members, who have accounts with us) and guests (people who attend an event and open a link a studio shared).

The data we collect

From studios: when a studio signs up we collect the studio name, the owner's name and email address, and a mobile number — and if the owner chooses "Continue with Google", Google provides their verified email, name and profile picture instead of a typed form. Studio team members invited later set a password (stored only as a secure hash); self-serve owners sign in with emailed links and have no password at all. We also hold: an optional profile photo; the studio's business details as entered by the studio — business name, address, contact phone, email, WhatsApp number, website and social links, and GSTIN with GST state code; billing records for the studio's plan (what was bought, when, for how much, and the payment gateway's order and payment references — never card or bank details, see "Who else receives data"); support tickets (name, email and the message written); and an activity log of actions taken in the panel, which records who did what, when, and from which IP address and browser.

From guests: the mobile number used to sign in with a one-time code; an optional selfie, described in the next section; the name, email address or phone number a studio entered when inviting them to an event; and when they first and most recently opened an event they were invited to.

Photos: studios upload event photos, and those photos frequently show people — that is the point of the product. For JPEG photos uploaded through the browser, we remove embedded GPS location data before the photo is uploaded; other embedded metadata (such as capture time and camera model) is kept. Photos uploaded through the desktop uploader, and non-JPEG formats such as HEIC, are stored exactly as uploaded — including any GPS location the device recorded.

From visitors to our marketing site who ask to be contacted: the name, studio name and phone number submitted, together with a hashed (not raw) IP address and browser information used to limit abuse of the form.

Sessions: when anyone signs in, we record the session's IP address and browser user-agent as part of keeping accounts secure.

Your selfie and face data

Guests can optionally take a selfie so Camsetu can find their photos in an event. This is the most sensitive data we handle, so here is exactly what happens.

Taking the selfie is optional and can be skipped. The liveness check (blinking at the camera) runs entirely in your browser on your device — the camera feed never leaves your phone or computer during that check. Only the single confirmed photo is uploaded. When you confirm the photo, we record that you agreed to this processing, together with the version of this policy you agreed under.

To match you to event photos, our own self-hosted face-matching service computes a numerical representation of the face in your selfie (a face embedding) and compares it with faces detected in the event's photos. Faces detected in event photos are likewise stored as embeddings, together with small cropped face images. All of this runs on infrastructure we operate — no third-party face-recognition service ever receives your selfie or your face data.

Your selfie is used to find your photos in events you have joined, and it also becomes the profile picture on your guest account, which the studio running your event can see in its guest list. Selfie and photo images are served over unguessable web addresses, but those addresses are not login-protected — treat a link to an image as viewable by anyone the link is shared with.

You can remove your selfie and the face data derived from it yourself, anytime, from your guest dashboard ("Remove" on the face card) — this also withdraws the consent you gave and stops all future matching. Photos already found for you stay in your events. You can also always email [email protected] (see "Your rights").

How we use data

We use the data above to: sign you in and keep your account secure (one-time codes, passwords, sign-in links, sessions); set up a studio's subscription, take its plan payment through our payment provider and keep the billing record; store, organise and deliver event photos to the guests a studio invites; find a guest's own photos with the optional selfie matching described above; display the pages a studio chooses to publish (galleries, join pages, flipbooks, portfolio pages, including the contact details the studio chose to show there); send transactional email, such as sign-in links, team invitations and email-change verification codes; answer support requests; and investigate abuse or security problems using the activity log.

We do not use your data for advertising, we do not profile you for marketing, and we do not sell it.

Where data lives and how it is protected

Photos, selfies and other images are stored in Cloudflare R2 object storage and served through Cloudflare's content delivery network. Everything else — accounts, events, guest lists, face embeddings, billing records, activity logs — lives in databases on servers we manage ourselves.

Protections currently in place: all traffic to Camsetu is encrypted in transit (HTTPS); where passwords exist they are stored only as secure hashes, and self-serve studio owners are passwordless entirely (single-use emailed sign-in links); a studio's GSTIN and contact details are additionally encrypted at rest inside the database; each studio's data is isolated from every other studio's; image web addresses are long and unguessable, though, as noted above, not login-protected.

Who else receives data

We use a small number of service providers to run Camsetu: Cloudflare stores and delivers images and fronts our web traffic; Resend delivers our transactional email (so it processes the email addresses we send to); and Razorpay processes plan payments — when a studio pays for a subscription, the card, UPI or bank details are entered with Razorpay and never touch our systems, and what we keep is the order and payment references and the amount. If a studio owner chooses "Continue with Google" at signup, Google tells us their verified email, name and profile picture; we do not get access to anything else in their Google account. The desktop app checks GitHub for application updates; no personal data is sent in that check.

Our usage analytics are self-hosted on our own infrastructure — gallery pages report events like views and downloads using internal identifiers only, and no analytics data is sent to any third-party analytics company.

Within the product, data is visible to the people it is for: a studio sees the guests of its own events (including names, contact details used for invites, and guest profile pictures), and guests see the photos and pages the studio shared with them. Studios choose what appears on their public pages — the contact details shown on a gallery or portfolio page are there because the studio put them there.

We do not sell personal data, and no ad networks or third-party trackers run on Camsetu pages. We may disclose data if required by law or a competent authority.

Where data is processed

Camsetu is operated from India, and our own servers are managed by us. Razorpay, our payment provider, is an Indian company. Some of our providers are international: Cloudflare (image storage and delivery), Resend (email delivery) and Google (the optional sign-in at studio signup) may store or process data on infrastructure outside India as part of providing their services. We rely on these providers' own security and data-protection commitments, and this processing happens only for the purposes described in this policy.

How long we keep data

We keep data for as long as the account, event or photo it belongs to exists. When a studio deletes a photo or an entire event, the stored image files — including detected face crops for those photos — are removed from storage as part of the deletion. When a guest re-captures their selfie, the previously stored selfie image is deleted from storage. Unfinished sign-up records are deleted automatically: after 30 days if the sign-up never reached payment, or 90 days if a payment step was started but not completed.

Apart from the automatic deletions described here, we do not yet operate a fixed retention schedule that deletes data automatically after a set period. Account records, activity logs and support tickets are kept until we are asked to remove them or no longer need them. If you want something specific removed, email [email protected] — see "Your rights".

Your rights

Under the DPDP Act you can ask us, at [email protected]: what personal data we hold about you (access); to correct data that is wrong or incomplete (correction); to delete your data, including a guest account, a selfie and the face data derived from it (erasure); to withdraw a consent you gave earlier, such as for selfie matching — after which we will stop that processing and remove the associated face data; and to name another person to exercise these rights for you if you are unable to (nomination).

Two of these are self-service for guests today, from the guest dashboard: removing your selfie and face data (withdrawing that consent), and deleting your entire account — which also removes your event memberships and the links between you and matched photos. Every other request — access, correction, nomination, and deletion of a studio account — is currently handled by a person, not a button: email is the way to exercise it. We will act on verified requests and confirm when done.

One honest limitation: a guest appearing in a studio's event photos appears there because the studio photographed the event. Removing your guest account and face data stops Camsetu matching you to photos, but the photos themselves belong to the studio's event; speak to the studio about removing a photo of you, or include it in your request and we will pass it on.

Children

Camsetu accounts are for photography businesses and adult guests; the product is not directed at children, and we do not knowingly collect a child's data directly. Guest sign-up includes confirming you are 18 or older, and we record that confirmation. Event photos may of course include children who attended the event — those photos are uploaded by the studio, which is responsible for having the right to photograph and share them. If you are a parent or guardian and want a child's data or photos removed, email [email protected] and we will treat it with priority.

If something goes wrong

If a personal-data breach affects your data, we will notify you and the Data Protection Board of India as the DPDP Act requires, and tell you what happened, what data was involved, and what we are doing about it.

Grievances

If you believe we have mishandled your data or your request, write to [email protected] with "Grievance" in the subject line. We will acknowledge it and respond as required under the DPDP Act. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

Changes to this policy

When our practices change, this page changes with them, and the "Last updated" date at the top is revised. Meaningful changes — new data we collect, new providers, new uses — will be reflected here before or as they ship.

Questions about this policy or your data: [email protected]