SaffronPix legal
Global Privacy Policy
This Policy explains how SaffronPix handles personal data across the Service. It is written for users in India and globally and applies together with the Cookie & Analytics Policy and, where relevant, the Data Processing Terms.
1. Our roles
- SaffronPix is a controller (or equivalent business) for account administration, security, billing, support, product operations and optional public-site analytics.
- A studio or business user is normally the controller for client records, galleries, films, CRM content, team data and instructions it uploads. For that content, SaffronPix acts as its processor or service provider.
- GrinWe participants may each be independent controllers for information they lawfully receive after a booking or assignment.
2. Data we collect
- Identity and contact: name, username, email, telephone/WhatsApp number, profile, business and verification information.
- Workspace and CRM: clients, leads, projects, bookings, tasks, team roles, notes, documents, finance and support records.
- Media: photos, video, audio, posters, thumbnails, metadata, selections, favourites, downloads and viewing progress.
- Sensitive or contextual data when enabled: approximate availability area, assignment-time location milestones, face search or similar derived templates, chat moderation signals and device permissions.
- Payments and integrations: transaction references and limited provider status; OAuth tokens or app credentials for services you connect. We do not intentionally store complete card details.
- Technical data: IP address, device/browser/app data, logs, diagnostics, security events, cookie choices and public-site interaction analytics where you consent.
3. How data is collected
- Directly from you, your studio, team members or clients.
- Automatically from apps, devices, cookies, logs and enabled permissions.
- From connected providers such as payment, identity, storage, calendar, messaging, maps, app store and sign-in services.
- From another SaffronPix workspace only where an authorised sharing, assignment or client flow permits it.
4. Purposes and legal bases
- Perform the contract: create accounts, deliver media, run CRM and marketplace workflows, sync devices, provide support and process authorised transactions.
- Consent: optional analytics, precise or background location where required, face-related features, marketing communications and device permissions.
- Legitimate interests: secure the Service, prevent fraud, diagnose faults, improve non-sensitive operations and protect legal rights, balanced against your rights.
- Legal obligation: tax, accounting, lawful requests, complaint handling and compliance.
- We do not use private client media or face templates to train public or general-purpose AI models.
5. Analytics, behaviour and SEO tools
- Google Tag Manager only loads optional public-site measurement tags after consent. Google Analytics 4 may measure page traffic, referral sources, device information and conversions. Advertising storage and personalised advertising are disabled by default.
- Microsoft Clarity may record public-page interactions such as clicks, scrolling and navigation to help us improve usability. SaffronPix loads Clarity only on approved public pages after consent, excludes signed-in dashboards, private galleries, authentication and payment surfaces, and requires the Clarity project to mask sensitive input fields before its project ID is enabled.
- Google Search Console and Microsoft Bing Webmaster Tools help us understand search queries, impressions, clicks, crawl and indexing performance. Their webmaster use does not itself require SaffronPix to place behaviour-replay cookies in your browser.
- You can refuse or withdraw optional analytics through Cookie settings without losing the core Service. We honour Global Privacy Control by keeping optional analytics off.
6. Sharing and service providers
We disclose only what is reasonably necessary to operate the Service, follow your instructions, complete a transaction, prevent harm or comply with law.
- Infrastructure and data: Supabase, Amazon Web Services and Cloudflare.
- Payments and verification: Razorpay and enabled payment or identity providers.
- Messaging and productivity: Meta/WhatsApp, Zoho, Google services and Expo/Apple/Google push services where enabled.
- Measurement: Google Analytics and Microsoft Clarity only after applicable consent; Google Search Console and Bing Webmaster Tools for search administration.
- Professional advisers, authorities, buyers in a genuine corporate transaction and other recipients required by law.
- We do not sell personal data or share it for cross-context behavioural advertising, and we do not operate a financial-incentive programme for personal data.
7. International transfers
Providers and users may process data outside your country. We use contractual, organisational and technical safeguards appropriate to the transfer, including recognised contractual clauses where required. Studios must also ensure that their own international instructions are lawful.
8. Retention
- Account and workspace data: while the account is active, then for the deletion/recovery period and any legally required record period.
- Client media: according to the studio's retention, plan, deletion or archive instructions.
- Security, support and transaction records: for the period needed to resolve issues, prevent abuse, enforce rights and meet accounting or legal duties.
- Face templates and location records: event- or feature-limited retention described in their dedicated policies, followed by deletion or de-identification, subject to backups and lawful holds.
- Consent records: for the period needed to demonstrate and administer your choice.
9. Your rights
Depending on location and applicable law, you may request access, correction, completion, deletion, portability or restriction; object to or withdraw consent for processing; appeal or nominate another person; and complain to a regulator. India's Digital Personal Data Protection Act and Rules apply as their relevant provisions come into force. EEA/UK GDPR, California privacy law and other local laws apply where their jurisdictional conditions are met.
- Account users can start an export or deletion request from Privacy settings where available.
- A client should normally contact the studio that provided the gallery because the studio controls that content. We will assist the studio as required.
- Send unresolved privacy requests to [email protected]. We may verify identity and authority before acting.
10. Children and automated decisions
The business Service is not directed to children. Studios must obtain parental or guardian authority before uploading children's data where law requires it. We do not make solely automated decisions that produce legal or similarly significant effects on users without notice, safeguards and a lawful basis.
11. Security and incidents
We use access controls, encryption in transit, least-privilege policies, signed links, logging, backups and other safeguards appropriate to risk. No system is perfectly secure. We will assess incidents and notify affected parties and authorities where law requires.