Privacy Policy
This Privacy Policy explains how Studio Print (“we”, “us”, “our”) collects, uses, stores and protects information when you use our website at studioprint.pages.dev and the related backend API (together, the “Service”).
1. Information we collect
a. Account information
- Name and Gmail address you provide when signing up.
- A one-way hashed password (we never store your password in plain text).
- A 6-digit email verification code (OTP), stored only as a salted hash and deleted after use.
b. Usage information
- The number of A4 sheets you download or print per day (used only to enforce plan limits).
- Plan type (Free / Weekly / Monthly) and the date it expires.
- Timestamps of account creation and verification.
c. Payment information
- Payments are processed by Razorpay. We receive only the
order_id,payment_id, signature and plan name. - We never receive or store your card number, CVV, UPI PIN, netbanking credentials or bank account details.
d. Photos you upload
- All passport-photo processing (background removal, cropping, A4 sheet generation) runs entirely in your browser.
- Your photos are never uploaded to our servers, never stored, and never shared with anyone.
2. How we use your information
- To create and secure your account.
- To verify that the email you provided is actually yours (one-time OTP).
- To enforce the daily limits of your current plan.
- To process subscription payments through Razorpay and activate the plan you purchased.
- To respond to your support requests when you email us.
3. Legal bases
We process your personal data because it is necessary to perform the contract you enter into with us when you create an account, to comply with applicable law, and on the basis of your consent where required.
4. Sharing with third parties
We do not sell your personal data. We share the minimum information required with:
- Razorpay Software Private Limited — to process subscription payments. See Razorpay’s privacy policy.
- Our email provider (Gmail SMTP) — to deliver the 6-digit verification code to your Gmail address.
- Our hosting provider — to serve the Service.
5. Cookies & local storage
We do not use tracking cookies. The Service uses your browser’s localStorage to remember:
- Your auth token after login (so you don’t have to log in on every page load).
- Your language preference.
- A local copy of your plan and daily download count.
You can clear this at any time from your browser settings.
6. Data retention
- Account data is kept for as long as your account is active.
- Pending signup OTPs expire after 10 minutes and are then deleted.
- Daily download counters are retained for operational and anti-abuse purposes.
- When you delete your account from the in-app My Account screen, your user record, payment history and download counters are permanently removed from our database and the same Gmail address becomes free to sign up again.
7. Your rights
You have the right to:
- Access the personal data we hold about you (use My Account or email us).
- Correct inaccurate data (edit your name by emailing support).
- Delete your account and data (in-app button or by emailing us).
- Withdraw consent at any time by deleting your account.
8. Security
All traffic is served over HTTPS. Passwords are hashed with bcrypt. Auth tokens are signed with a server-side secret. Access to the production database is restricted to the service itself.
9. Children
The Service is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has created an account, please contact us and we will remove it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date above will reflect the most recent changes. Material changes will be notified via email where possible.
11. Contact
See the Contact page for full details.