Privacy policy

What we collect, why, and how to have it removed. Written to be read — if anything here is unclear, that is a fault worth telling us about.

Effective 31 July 2026 · Last updated 8 August 2026

Who we are

CamSetu is an event-photo platform: photography studios upload and organise event photos, and guests view, download and find their own photos in them. It is operated from India by Codeverse Weenggs Solutions LLP (“we”), of 222, Avalon Business Hub, Ambatalavadi, Katargam, Surat, Gujarat 395004, India. CamSetu is the product name; the LLP is the entity accountable for the service and for your data.

For anything in this policy — questions, requests, complaints — write to hello@camsetu.com. This policy explains what personal data we collect, why, where it lives, who else touches it, and what you can ask us to do with it, in line with India’s Digital Personal Data Protection Act, 2023 (DPDP Act).

What this policy covers

This is the only privacy policy CamSetu has, and it covers every CamSetu surface: this marketing site, the studio panel where studios manage their events, the guest surfaces (event galleries, join pages, flipbooks and the portfolio pages studios publish), and the CamSetu desktop uploader.

Two roles appear throughout, because we hold different data about each. Studios are our customers — the photography businesses, wedding planners and event teams who hold an account with us, and the team members they invite. Guests are the people who open a link a studio shared; a guest signs in with a phone number but the studio, not us, decides which photos are in an event and who may see them.

The data we collect

From studios: when a studio signs up we collect the studio name, the owner’s name and email address, and a mobile number — and if the owner chooses “Continue with Google”, Google provides their verified email, name and profile picture instead of a typed form. We never receive a Google password. Studio team members invited later set a password (stored only as a secure hash); self-serve owners sign in with emailed links and have no password at all.

We also hold, for studios: an optional profile photo; the studio’s business details as entered by the studio — business name, address, contact phone, email, WhatsApp number, website and social links, and GSTIN with GST state code; billing records for the studio’s plan (what was bought, when, for how much, and the payment gateway’s order and payment references — never card or bank details, see “Who else receives data”); support tickets (name, email and the message written); operational records such as uploads made, storage used against the plan, and diagnostic logs from the desktop uploader when something fails; and an activity log of actions taken in the panel, which records who did what, when, and from which IP address and browser.

From guests: the mobile number used to sign in with a one-time code; an optional selfie, described in the next section; the name, email address or phone number a studio entered when inviting them to an event; and when they first and most recently opened an event they were invited to.

Photos: studios upload event photos, and those photos frequently show people — that is the point of the product. For JPEG photos uploaded through the browser, we remove embedded GPS location data before the photo is uploaded; other embedded metadata (such as capture time and camera model) is kept. Photos uploaded through the desktop uploader, and non-JPEG formats such as HEIC, are stored exactly as uploaded — including any GPS location the device recorded.

From visitors to this marketing site who ask to be contacted: the name, studio name and phone number submitted, together with a hashed (not raw) IP address and browser information used to limit abuse of the form.

Sessions: when anyone signs in, we record the session’s IP address and browser user-agent as part of keeping accounts secure.

Your selfie and face data

Guests can optionally take a selfie so CamSetu can find their photos in an event. This is the most sensitive data we handle, so here is exactly what happens.

Taking the selfie is optional and can be skipped. The liveness check (blinking at the camera) runs entirely in your browser on your device — the camera feed never leaves your phone or computer during that check. Only the single confirmed photo is uploaded. When you confirm the photo, we record that you agreed to this processing, together with the version of this policy you agreed under.

To match you to event photos, our own self-hosted face-matching service computes a numerical representation of the face in your selfie (a face embedding) and compares it with faces detected in the event’s photos. Faces detected in event photos are likewise stored as embeddings, together with small cropped face images. All of this runs on infrastructure we operate — no third-party face-recognition service ever receives your selfie or your face data, embeddings are used only within the studio’s own events, and they are never compared across studios or against any outside database.

Your selfie is used to find your photos in events you have joined, and it also becomes the profile picture on your guest account, which the studio running your event can see in its guest list. It is not published in the gallery. Selfie and photo images are served over unguessable web addresses, but those addresses are not login-protected — treat a link to an image as viewable by anyone the link is shared with.

You can remove your selfie and the face data derived from it yourself, at any time, from your guest dashboard (“Remove” on the face card) — this also withdraws the consent you gave and stops all future matching. Photos already found for you stay in your events. Face data is also deleted when the photos it came from are deleted. You can always email hello@camsetu.com instead — see Your rights.

How we use data

We use the data above to: sign you in and keep your account secure (one-time codes, passwords, sign-in links, sessions); set up a studio’s subscription, take its plan payment through our payment provider and keep the billing record; store, organise and deliver event photos to the guests a studio invites; find a guest’s own photos with the optional selfie matching described above; display the pages a studio chooses to publish (galleries, join pages, flipbooks, portfolio pages, including the contact details the studio chose to show there); send transactional email, such as sign-in links, team invitations and email-change verification codes; answer support requests; and investigate abuse or security problems using the activity log.

We do not use your data for advertising, we do not profile you for marketing, and we do not sell it. A studio’s photographs are used to run the service for that studio and nothing else — we do not use them to advertise CamSetu, and if we ever wanted to feature a studio’s work we would ask first.

Where data lives and how it is protected

Photos, selfies and other images are stored in Cloudflare R2 object storage and served through Cloudflare’s content delivery network. Everything else — accounts, events, guest lists, face embeddings, billing records, activity logs — lives in databases on servers we manage ourselves.

Protections currently in place: all traffic is encrypted in transit (HTTPS); where passwords exist they are stored only as secure hashes, and self-serve studio owners are passwordless entirely (single-use emailed sign-in links); a studio’s GSTIN and contact details are additionally encrypted at rest inside the database; each studio’s data is isolated from every other studio’s; image web addresses are long and unguessable, though, as noted above, not login-protected.

Who else receives data

We use a small number of service providers, and only for the job named: Cloudflare stores and delivers images and fronts our web traffic; Resend delivers our transactional email (so it processes the email addresses we send to); and Razorpay processes plan payments — when a studio pays for a subscription, the card, UPI or bank details are entered with Razorpay and never touch our systems, and what we keep is the order and payment references and the amount. If a studio owner chooses “Continue with Google” at signup, Google tells us their verified email, name and profile picture; we do not get access to anything else in their Google account. The desktop app checks GitHub for application updates; no personal data is sent in that check.

Our usage analytics are self-hosted on our own infrastructure — pages report events like views and downloads using internal identifiers only, and no analytics data is sent to any third-party analytics company.

Within the product, data is visible to the people it is for: a studio sees the guests of its own events (including names, contact details used for invites, and guest profile pictures), and guests see the photos and pages the studio shared with them — a guest’s details are not visible to other studios. Studios choose what appears on their public pages; the contact details shown on a gallery or portfolio page are there because the studio put them there.

We do not sell personal data, we do not share it for anyone else’s advertising, and no ad networks or third-party trackers run on our pages. We may disclose data if required by law or a competent authority.

Where data is processed

CamSetu is operated from India, and our own servers are managed by us. Razorpay, our payment provider, is an Indian company. Some of our providers are international: Cloudflare (image storage and delivery), Resend (email delivery) and Google (the optional sign-in at studio signup) may store or process data on infrastructure outside India as part of providing their services. We rely on these providers’ own security and data-protection commitments, and this processing happens only for the purposes described in this policy.

How long we keep data

We keep data for as long as the account, event or photo it belongs to exists. When a studio deletes a photo or an entire event, the stored image files — including detected face crops for those photos — are removed from storage as part of the deletion. When a guest re-captures their selfie, the previously stored selfie image is deleted from storage. Backups may lag behind by a short period before they age out. Unfinished sign-up records are deleted automatically: after 30 days if the sign-up never reached payment, or 90 days if a payment step was started but not completed.

A studio can also set an expiry date on an individual event. When it is set, that event and everything in it — photos, videos and the detected face data for them — are deleted automatically the day after that date, and the studio and the event’s admins are notified in the app beforehand. Setting a date is optional and most events do not have one; an event with no expiry date is kept.

When a studio’s plan ends, its account becomes read-only for 30 days, after which we may delete its events, photos and the face data derived from them. That window and what it means are set out in our terms.

Account and payment records are kept while an account is active, and afterwards for as long as tax and accounting rules require. Apart from the deletions described here, we do not operate a platform-wide retention schedule that removes data automatically after a set period — activity logs, support tickets and the diagnostic logs from failed uploads are kept until we are asked to remove them or no longer need them. If you want something specific removed, email hello@camsetu.com; see Your rights.

Your rights

Under the DPDP Act you can ask us, at hello@camsetu.com: what personal data we hold about you (access); to correct data that is wrong or incomplete (correction); to delete your data, including a guest account, a selfie and the face data derived from it (erasure); to withdraw a consent you gave earlier, such as for selfie matching — after which we will stop that processing and remove the associated face data; and to name another person to exercise these rights for you if you are unable to (nomination).

Two of these are self-service for guests today, from the guest dashboard: removing your selfie and face data (withdrawing that consent), and deleting your entire account — which also removes your event memberships and the links between you and matched photos. Studios can delete their events and photos themselves from the panel. Every other request — access, correction, nomination, and deletion of a studio account — is currently handled by a person, not a button: email is the way to exercise it. We will act on verified requests and confirm when done.

If you are a guest, you can come to us directly. You do not have to go through the studio that invited you.

One honest limitation: a guest appearing in a studio’s event photos appears there because the studio photographed the event. Removing your guest account and face data stops us matching you to photos, but the photographs themselves belong to the studio’s event; speak to the studio about removing a photo of you, or include it in your request and we will pass it on.

Children

CamSetu accounts are for photography businesses and adult guests; the product is not directed at children, and we do not knowingly collect a child’s data directly. Guest sign-up includes confirming you are 18 or older, and we record that confirmation. Event photos may of course include children who attended the event — those photos are uploaded by the studio, which is responsible for having the right to photograph and share them. If you are a parent or guardian and want a child’s data or photos removed, email hello@camsetu.com and we will treat it with priority.

If something goes wrong

If a personal-data breach affects your data, we will notify you and the Data Protection Board of India as the DPDP Act requires, and tell you what happened, what data was involved, and what we are doing about it.

Grievances

If you believe we have mishandled your data or your request, write to hello@camsetu.com with “Grievance” in the subject line. We will acknowledge it and respond as required under the DPDP Act.

Our grievance officer is Tushar Navadiya, who can be reached at that address or by post at 221, Avalon Business Hub, Ambatalavadi, Katargam, Surat, Gujarat 395004, India. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

Changes to this policy

When our practices change, this page changes with them, and the “Last updated” date at the top is revised. Meaningful changes — new data we collect, new providers, new uses — will be reflected here before or as they ship, and if a change is significant we will tell account holders by email rather than relying on you to notice.

This page is the single published version. Links to it from inside the product point here, so there is never a second copy to check against.