Privacy Policy
Last updated: 30 September 2026 · Web and Android editions
This policy explains how StudioBooks (also listed as Studio Books App), provided by Beamz Pixelz (“we”, “us”), handles information when you use our scheduling, business records and client gallery services.
1. Information we handle
- Account information: your email address, account identifier, sign-in provider, verification status and any profile details supplied by that provider. Firebase Authentication processes sign-in credentials. Our administration records include registered email addresses and first/last service-use timestamps.
- Business and client records: bookings, client names and contact details, shoot dates and locations, notes, invoices, payment instructions, income, expenses, receipts, event types, branding and settings that you enter or attach. Financial records may contain bank details if you include them.
- Galleries: uploaded proofs, edited photos and videos, filenames, gallery titles, sharing settings, access credentials and client selections/favourites.
- Notifications and technical information: device push tokens, account association, time zone, reminder delivery records, and technical connection information processed by our hosting and authentication providers, such as IP addresses and request/device information.
- Support: information you send when you ask for help or exercise your privacy rights.
Only upload client information and images you have permission or another lawful basis to use. Studio businesses are responsible for explaining their own use of client information to their clients.
2. How we use information
We use information to authenticate you, save and synchronise your records, display your calendar and reports, generate invoices, host and share galleries, deliver reminders, manage storage allowances, secure the service and respond to support and privacy requests. We do not sell your personal information or use your uploaded records for advertising.
Where data-protection law requires a legal basis, we rely on providing the service you request, legitimate interests in operating and securing it, legal obligations where applicable, and consent where required. Optional device permissions can be withdrawn in your device settings.
3. Device storage, document processing and app lock
The apps keep local records, settings and sign-in state on your device or in your browser so they can remain signed in and support continued use. Bookings, expenses, invoices, event types and settings are synchronised with our server when connected. Uploaded client galleries are stored on our server.
The Tax Only import and OCR tools process supported statements and receipts locally in the browser or Android app. Tax Only records are not included in the standard cloud synchronisation; protect any backups or exports you create. Receipts attached to synchronised expense records can be included in cloud storage.
Optional fingerprint, face or device-credential authentication is handled by Android. StudioBooks receives an authentication result, not your fingerprint images, face templates or device PIN. Device backups may include app data depending on your Android backup settings.
4. Service providers and sharing
- Google/Firebase: account authentication and Firebase Cloud Messaging for push delivery. Notification payloads can include booking information. See Google’s privacy policy.
- Cloudflare: website and API hosting, database storage and file storage for synchronised records and galleries. See Cloudflare’s privacy policy.
- Sign-in and messaging services you choose: Google or Apple where sign-in is available; WhatsApp or your SMS application when you choose to share a reminder or message. These services apply their own privacy policies.
- Your recipients: clients and other people to whom you share invoices, receipts, exports or gallery links. If you create a private client website link, anyone holding it can see the selected booking’s client name, session type, date, time, media type, session location/address, payment totals, receipt summary and delivery status/date, plus its linked gallery photos and videos. Holders can change photo favourites. The private-link API allows these details to appear on beamzpixelz.co.uk and www.beamzpixelz.co.uk. Internal notes, phone numbers and email addresses are excluded. Links expire and can be revoked in the booking summary; revocation cannot remove copies already saved by recipients or revoke separately shared gallery links. Gallery passwords, expiry and download settings still apply. Canvas watermarks provide display protection, not a guarantee against saving underlying images. Titles and studio branding may appear in gallery link previews. Protect client links and passwords.
Authorised administrators and service providers can process information as needed to operate and support StudioBooks. We may disclose information when required by law or necessary to protect users and the service. Providers may process information outside your country under their applicable data-protection arrangements. The current subscription screen is a preview and does not take payment-card details or charge payments.
5. Notifications and your choices
Booking reminders may appear while the app is closed and on your lock screen. You can control notification permission and lock-screen visibility in Android settings, and reminder settings where provided in the app. Sharing a WhatsApp or text reminder opens the selected messaging service; it is not an automatic WhatsApp messaging service.
You can edit or delete records using available controls, export supported records, revoke optional permissions, or contact us. Signing out or uninstalling the app does not delete your cloud account or server records. Downloads and copies shared with clients remain under the recipients’ control.
6. Retention and security
Account and cloud records are retained while you use the service unless deleted or a deletion request is completed. Deleting a synchronised record removes it from normal use, but the current system also retains previous record versions for recovery; it does not automatically purge all historic copies. Gallery deletion removes the associated hosted photos, while edited-gallery expiry depends on its settings and server cleanup. Local copies, exports and device backups must be managed separately.
We use authenticated access checks and HTTPS for server communications. This is not an end-to-end encrypted service, and no system can guarantee absolute security. During a verified deletion request we will explain any information that must be retained for legal, security or dispute-resolution reasons and the applicable retention period. Recovery history must also be considered when completing deletion.
7. Request account or data deletion
To request deletion of your StudioBooks account and associated data, email [email protected] with the subject “StudioBooks account deletion”. You do not need to sign in or reinstall the app.
If the email link does not open, copy the address into your email service. Opening the link alone does not submit a request: you must send the email.
Send the request from your registered email address where possible, and say whether you want the whole account deleted or only specific data. Do not send passwords, verification codes or financial documents. We may ask for proportionate confirmation of account ownership before acting.
Requests are handled manually. We will acknowledge your request, explain any ownership checks or retention exceptions, and give you an expected completion time. After ownership is verified and account deletion begins, access and shared galleries are blocked while the removal is completed. We will confirm the outcome; submitting a request is not confirmation that deletion is complete.
Full account deletion covers your Firebase authentication account, registered-user record, synced business records and all stored recovery versions, hosted gallery files and selections, branding, storage accounting and push registrations/delivery records associated with that account. A minimal account-identifier block record and deletion timestamps remain while the service operates to prevent old sessions or devices from recreating deleted cloud data. They do not contain your email, business records or photos. Any separate legal retention or provider backup limitations will be explained to you.
Before requesting deletion: export anything you need. Deletion cannot be undone. We cannot erase copies already downloaded by other people, support messages held outside the app, or backups held on your own devices through the account-deletion tool. Support correspondence is handled separately as part of your request.
Remove local copies too: after exporting anything you need, clear StudioBooks app storage in Android settings, and clear site data for studiobooksapp.com in each browser you used. This removes local-only Tax Only records as well, so export those first. Separately remove unwanted downloads, exports and device backups. Uninstalling or signing out alone does not request cloud deletion.
You may also request access, correction or restriction of your personal information, or raise a privacy concern. Rights depend on applicable law. If you are a client of a studio using StudioBooks, contact that studio first about its records; you may also contact us for assistance. You can complain to your local data-protection authority; in the UK this is the Information Commissioner’s Office.
8. Children and changes
StudioBooks accounts are intended for adults aged 18 and over. A studio may upload images of children as part of its client work and is responsible for the necessary permissions and lawful handling. Contact us if you believe information has been uploaded improperly.
We may update this policy as the service changes. The date above identifies the current version. Material changes will be communicated through the service where appropriate.
Activity tracking discontinued
StudioBooks no longer collects daily testing activity or feature-use reports. Android version 1.8.15 removes the reporting code, calendar notice and sharing controls. Once the updated backend is deployed, reports from older versions are also rejected.
Previously collected activity remains subject to the existing 30-day retention period and scheduled deletion. Account deletion also removes it. This change does not disable account authentication, normal record syncing, booking reminders or operational security logs.