shotlink.

Privacy Policy

Last updated: July 22, 2026

This policy explains what personal data Shotlink ("we", "us") collects, why we collect it, and what your choices are. It applies to photographers with a Shotlink account and to clients who open galleries shared with them. If you have any questions, email us at [email protected].

1. Data we collect

Account data (photographers)

  • Email address and name — to create your account, sign you in, and send essential service emails.
  • Password — stored only as a secure hash; we never see or store the plain password.
  • Avatar — if you upload one or sign in with Google (see below).
  • Storage usage and plan — to enforce storage quotas.

Sign in with Google

If you sign up or sign in through Google, Google shares your name, email address, and profile picture with us. We use them only to create and identify your account — we do not get access to anything else in your Google account.

Content you upload

Photos you upload and the gallery structure around them (titles, sections, cover photos) are stored so we can display and deliver them. Photos may depict identifiable people — as the photographer, you are responsible for having the right to upload and share them.

Client data

Clients do not need an account. When a client opens a gallery, we set a random token in a cookie on their device to remember their favorite photos; it is not linked to a name or email address. PIN entries for protected galleries are kept in the browser session.

Technical data

Like most web services, our servers and Cloudflare (our proxy) keep short-lived request logs — IP address, browser type, requested pages — used for security and troubleshooting. We do not use analytics or advertising trackers.

2. How we use your data

  • to provide the service: host galleries, deliver photos, remember favorites;
  • to keep accounts secure: sign-in, email confirmation, password reset, bot protection on forms;
  • to send transactional email (confirmation links, password resets) — we do not send marketing email;
  • to enforce quotas and our Terms of Use;
  • to process payments, once paid plans launch.

We do not sell personal data or share it with anyone except the service providers listed below.

3. Cookies

We use only cookies that are necessary for the service to work or that remember a choice you made. There are no analytics or advertising cookies, which is why we show an informational notice instead of asking for consent.

Cookies we set

  • session_id — keeps photographers signed in (signed, persistent).
  • client_token — remembers a client's favorite photos in public galleries (signed, persistent, random token).
  • _shotlink_session — the framework session cookie: protects forms against cross-site request forgery and remembers which PIN-protected galleries you unlocked (expires with the browser session).
  • cookie_notice_dismissed — remembers that you dismissed the cookie notice (persistent).

Cookies set by Cloudflare and Google

  • Cloudflare — our traffic runs through Cloudflare, and sign-in, sign-up, and password reset forms use Cloudflare Turnstile for bot protection. Cloudflare may set its own cookies (such as __cf_bm) for security purposes. See Cloudflare's privacy policy.
  • Google — the "Sign in with Google" button and One Tap prompt are served by Google, which may set its own cookies. See Google's privacy policy.

4. Service providers

We rely on a small number of providers to run Shotlink; each receives only the data needed for its role:

  • Cloudflare — network proxy, bot protection (Turnstile), and photo storage (R2).
  • Google — optional sign-in (OAuth / One Tap).
  • Resend — delivery of transactional email.
  • Stripe — payment processing, once paid plans launch; card details go directly to Stripe and never touch our servers.

5. Data retention

  • Account data — kept while your account exists. Deleting your account permanently removes your profile, galleries, and photos.
  • Photos — kept until you delete them, the gallery, or your account. Free-plan galleries may additionally be subject to a retention period announced in the app.
  • Client favorites — tied to the client's cookie and the gallery; removed with the gallery.
  • Request logs — kept for a short period for security and debugging, then discarded.

6. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict its processing. You can update your name, avatar, and password — and delete your account — in your profile settings. For anything else, including requests about photos of you uploaded by a photographer, contact us at [email protected] and we will respond as required by applicable law.

Note that for photos uploaded by photographers, the photographer decides what is uploaded and shared; where data protection law applies, we generally process those photos on the photographer's behalf. If your request concerns such photos, we may refer you to the photographer or involve them in resolving it.

7. Security

All traffic is encrypted with TLS, passwords are stored as secure hashes, authentication cookies are signed and protected against script access, and gallery links use long random tokens. No online service can guarantee absolute security, but we design Shotlink to keep the attack surface small.

8. Children

Shotlink accounts are intended for adults. We do not knowingly collect personal data from children; photos of children may only be uploaded by photographers who have the necessary permissions from parents or guardians.

9. Changes to this policy

We may update this policy as the service evolves — for example, when paid plans launch. For material changes we will notify you by email or with a notice in the app. The date at the top shows when this policy was last revised.

10. Contact

For privacy questions or requests, email [email protected]. See also our Terms of Use.

We only use cookies that make the site work — no tracking, no ads. Learn more