Privacy policy
Last updated: 16 September 2026
This policy explains what Shootlog collects about you and the people you record in it, why, where it's stored, and the rights you have over it. It's written to follow the principles of Canada's private-sector privacy law, PIPEDA (the Personal Information Protection and Electronic Documents Act), in plain words rather than as a legal checklist. It applies to your account, your workspace, and the client and team records you keep inside it.
1. What we collect
We collect four kinds of information:
- Account information: your email address, your studio's name, and a password hash. We never see or store your actual password — Supabase, our authentication provider, holds only a one-way hash of it.
- The business records you enter: clients, bookings, team members (names, and optionally an email and phone number for each), payments and expenses — everything you put into Shootlog to run your business.
- Billing identifiers from Stripe: a customer id and subscription status, so we know what plan you're on. Never your card number — Stripe handles and stores that directly.
- Technical information: your sign-in session, server logs that include your IP address (kept for security purposes, such as investigating abuse), and cookieless page-view counts from Vercel Analytics. Shootlog sets no tracking cookies — only the sign-in session cookie and a cookie that remembers your light/dark theme choice.
That's the whole list. We don't collect anything beyond what's needed to run the service, bill you and keep it secure — no browsing history from outside Shootlog, no device fingerprinting, and no data bought or gathered from anywhere else.
2. Why we collect it
We use what we collect for four purposes, and nothing beyond them:
- To run the service: storing your records, showing them back to you, and calculating your reports.
- To bill you, on a paid plan, through Stripe.
- To send the emails you've asked for — account and password emails, and, on Max and Max AI, the daily reminder digest you've switched on.
- To keep the service secure — for example, using server logs to investigate suspicious activity.
We don't use your data for advertising, and we don't build profiles of you to sell to anyone.
3. Our legal basis
Under Canadian privacy law, we collect and use your information with your consent — given when you create a workspace — and for the reasonable business purposes described above: running the service you've signed up for, billing you for it, and keeping it secure.
4. Where your data is stored and processed
Your database lives with Supabase in the Canada (Central) region — that's where your clients, bookings, team members, payments and expenses are physically stored. Some of the processors we rely on to run Shootlog — Stripe, Resend, Vercel and, if you connect it, Google — may process data outside Canada, including in the United States, under their own privacy and security safeguards. This is typical for a small Canadian software business: rather than build our own payment processor, email sender and hosting infrastructure, we use established providers who handle that part of the work for many companies, and who each publish their own privacy and security commitments. If you use Create from notes, whatever you paste or upload is sent to Anthropic's servers in the United States for the length of that one request.
5. Who we share it with
We share your information only with the processors we need to run Shootlog, each doing one specific job and none of them free to use your data for anything else:
- Supabase stores your database and handles sign-in.
- Stripe processes payments and holds your billing and card details.
- Vercel hosts the app and provides the cookieless analytics counts described above.
- Resend delivers the emails Shootlog sends you.
- Google, only if you connect Calendar, to create the calendar events you ask for.
- Anthropic reads the notes, transcripts and contracts you choose to send through Create from notes, on Max AI and the free tries on Pro and Max. That text is sent to Anthropic's servers in the United States for the length of one request; Anthropic does not use it to train its models. We keep a count of runs and a token tally, not the text.
We never sell your data, we never share it with data brokers or advertising networks, and we never hand it to anyone outside this list without telling you first, except where the law requires it.
6. The people in your records
Your clients and team appear in Shootlog because you've entered them — a client's name, a team member's name and optionally their email or phone number. Team members in Shootlog are records, not logins: they don't sign in, and nothing is sent to them automatically except a calendar invite if you choose to share a booking to Google Calendar and they have an email on file. You're responsible for having the right to record that information about them, under whatever arrangement you have with them, as their employer, contractor or the studio they work with. We process it on your behalf, as part of running the service for you, and don't use it for any purpose of our own — we don't contact your clients or team directly, and we don't use their details for anything beyond showing them back to you inside your workspace.
If one of your clients or team wants to know what we hold about them, or has a concern about it, they — or you, on their behalf — can reach us through our contact page.
7. Google Calendar data
If you choose to connect Google Calendar (Max, owner only), we only ever share what you explicitly choose to share to a calendar you pick — a booking's days and the team assigned to them — and we only request the Google scopes needed to do that: managing calendar events, and reading the list of calendars you can write to. We never read your existing Google Calendar events, your email, or anything else in your Google account.
Your Google refresh token is encrypted at rest and only ever decrypted on our server at the moment a share happens. You can disconnect Google at any time from Settings, which removes the stored connection immediately.
Shootlog's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. How long we keep data
We keep your data while your account is open. If you delete a booking, client or team member, it's kept for 30 days (so it can be recovered if that was a mistake), then permanently purged; the same 30-day window applies after you delete your whole account. Routine database backups may retain deleted data for a short additional period beyond that. Stripe and Resend keep their own records — billing history and email delivery logs — according to their own retention practices, independent of Shootlog.
9. Security
We protect your data with several layers:
- Row-level security in the database means one workspace can never read another's data — every query is checked against who's signed in, at the database level, not just in the app's own code.
- All data is encrypted in transit between your browser and our servers.
- Your Google Calendar refresh token is encrypted at rest, and can only be read by our server.
- Your password is never stored as plain text — Supabase, our authentication provider, stores only a salted hash of it, which can't be reversed back into your actual password.
- Your card details never touch our servers at all — Stripe collects and stores them directly.
- Access to production data is limited to the operator of Shootlog.
No system is completely secure, and we can't guarantee one hundred percent protection. If a breach affecting your data ever happens, we'll notify affected users and, where the law requires it, the Office of the Privacy Commissioner of Canada, as soon as we reasonably can and with as much detail as we have at the time.
10. Your rights
You can, at any time:
- Access the data we hold about you and your workspace.
- Correct anything that's wrong, directly inside Shootlog.
- Export your data as a CSV file (Pro and above, from the Money page; a full year-end export on Max and Max AI).
- Ask us to delete your account and its data.
- Withdraw your consent to our processing your data, which in practice means closing your account, since the service can't run without it.
- Ask us what personal information we hold about you specifically, and who we've shared it with.
Most of this you can already do yourself inside the app — editing or deleting a record, exporting your data, or deleting your account — without waiting on us. For anything you can't do yourself, we'll respond within a reasonable time, and won't charge you for a reasonable request.
To exercise any of these, get in touch through our contact page. If you're not satisfied with how we've handled your information, you can complain to the Office of the Privacy Commissioner of Canada.
11. Children
Shootlog is a business tool and isn't intended for anyone under 18. We don't knowingly collect information from children.
12. Changes to this policy
We may update this policy as the service changes. For a material change, we'll tell you by email or with a notice inside the app at least 30 days before it takes effect.
13. Contact
Questions about this policy, or a request about your data? Get in touch through our contact page, or by mail at 1 Applewood Crescent, Unit 3A, Concord, ON L4K 4K1, Canada.