This Privacy Policy explains how ClickIt Studio ("ClickIt", "we", "us", "our"), the Data Fiduciary in respect of the personal data described below, collects, uses, discloses, and protects information when you use the ClickIt mobile application (the "App"), whether as a customer or as a photographer. It applies to both roles unless stated otherwise.
1. Information we collect
1.1 Account information
- Name, email address, and role (customer or photographer)
- Phone number and a short bio, if you choose to add them
- A profile photo, if you upload one
1.2 Location information
- Customers: the shoot location you set, used to identify and rank nearby photographers
- Photographers: your declared working location and travel radius, used so customers can find you
- Emergency/SOS: if you use the in-app safety button, your device's location at that moment is logged to our systems and may be shared with your nominated trusted contact
1.3 Booking and activity information
- Booking details: session length, scheduled time, price, and payment status
- In-app chat messages exchanged between a customer and a photographer in connection with a booking
- Ratings and written reviews (customers rate photographers; photographers rate customers)
- Self-reported counts of photographs/videos taken during a session — not the underlying media, which is exchanged directly between customer and photographer outside the App
- Cancellation and reliability history, used to apply the fair-play policies described in our Terms of Service
1.4 Photographer-specific information
- Portfolio images you upload, or select from a connected Instagram Business/Creator account
- Equipment/add-on selections and hourly rate, if listing as a Professional
- Payout details submitted to request payment for a completed booking: email address, phone number, and UPI ID. Under the SPDI Rules, financial information of this kind is treated as Sensitive Personal Data or Information and is handled with additional access restrictions — see Section 6
1.5 Payment information
Payments are processed by Razorpay Software Private Limited, a Payment Aggregator authorised by the Reserve Bank of India, through a nodal/escrow account mechanism governed by RBI's Payment Aggregator and Payment Gateway directions. ClickIt does not receive or store your card number, UPI PIN, net-banking credentials, or bank account details. We retain only the transaction status, amount, and the order/payment reference IDs Razorpay issues, for verification and reconciliation.
1.6 Device and technical information
- Authentication session data managed by Firebase Authentication (Google)
- A push-notification device token, where notifications are enabled
2. Legal basis and purpose limitation
We process personal data on the basis of your consent, given at the time you create an account or take the relevant in-app action (e.g. granting location access, submitting a payout request), and, where applicable, for the performance of the booking contract between you and the other party to it. Consistent with the DPDP Act's principles of purpose limitation and data minimisation, we collect only the data reasonably necessary for the purposes described in this policy, and do not use it for materially different purposes without seeking fresh consent.
Note: as of the effective date above, the substantive consent, notice, and security provisions of the DPDP Act are undergoing phased notification by the Government of India. This policy is drafted to align with the DPDP Act's requirements in anticipation of those provisions taking full effect, and in the interim is also governed by the IT Act, 2000 and the SPDI Rules, 2011.
3. How we use information
- To create and operate your account, and to route bookings between customers and photographers
- To rank nearby photographers by distance for customers
- To process payments and refunds through Razorpay, and to pay photographers
- To maintain trust and safety: ratings, dispute resolution, and the cancellation/reliability policies described in our Terms of Service
- To provide the SOS safety feature
- To send booking-related notifications, where enabled
- To investigate and resolve disputes filed by either party
- To comply with applicable law, respond to lawful requests from public authorities, and enforce our Terms of Service
4. Disclosure to third parties
| Third party | Purpose |
|---|---|
| Google Firebase / Google Cloud | Authentication, database, file storage, and backend functions that power the App |
| Razorpay Software Pvt. Ltd. | RBI-authorised payment aggregation, processing, and refunds |
| Google Sign-In & Google Maps/Places | Optional sign-in method; address search and mapping for setting locations |
| Instagram (Meta Platforms, Inc.) | Optional, photographer-initiated: importing portfolio photos from a connected Instagram Business/Creator account |
We do not sell personal data. Information is shared with the other party to a booking only to the extent necessary to complete it (for example, a customer's name and chosen location are visible to the photographer they book, and vice versa). We may also disclose information where required by law, court order, or a lawful request from a government or regulatory authority.
5. Cross-border storage and transfer
Our backend infrastructure (Firebase/Google Cloud) primarily processes data in Google Cloud's asia-south1 (Mumbai) region; however, some processing by our sub-processors (including Google and Meta) may occur outside India. We take reasonable steps to ensure such transfers are made only to jurisdictions and entities capable of providing an adequate standard of protection, consistent with the DPDP Act's cross-border transfer regime (which permits transfer to all countries except those specifically restricted by the Central Government) and the SPDI Rules' requirement of contractual safeguards for onward transfer of sensitive personal data.
6. Security safeguards
We maintain reasonable security practices and procedures as contemplated by Section 43A of the IT Act and the SPDI Rules, including encryption of data in transit and at rest, role-based access controls, and database security rules that restrict sensitive fields — for example, a photographer's payout details (email/phone/UPI ID) are readable only by that photographer and by an authorised ClickIt administrator, never by customers or other photographers.
7. Retention and deletion
You may delete your account at any time from within the App. Doing so removes your profile and, where applicable, your public photographer listing. Certain records — including completed booking, payment, and dispute records — may be retained after account deletion for as long as reasonably necessary to comply with applicable law (including tax, accounting, and consumer protection record-keeping requirements), to resolve disputes, and to enforce our agreements, after which they are deleted or anonymised.
8. Your rights as a Data Principal
Subject to applicable law, you have the right to:
- Access a summary of the personal data we hold about you and the processing activities undertaken;
- Correct or update inaccurate or incomplete personal data;
- Erase personal data that is no longer necessary for the purpose it was collected, subject to Section 7 above;
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- Grievance redressal, as described in Section 9; and
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, contact us using the details in Section 14. We will verify your identity before acting on a request and will respond within the timelines set out in Section 9.
9. Grievance Officer
In accordance with the IT Rules 2021, the Consumer Protection (E-Commerce) Rules, 2020, and the DPDP Act, we have appointed the following Grievance Officer:
Name: Noel Jackson
Designation: CTO
Address: Bengaluru, India
Email: therealdrbw@gmail.com
Hours: Monday–Friday, 10:00–18:00 IST
The Grievance Officer will acknowledge a complaint within 48 hours of receipt and endeavour to resolve it within one month from the date of receipt, in accordance with the Consumer Protection (E-Commerce) Rules, 2020 (and, where the complaint concerns content or access to the App as an intermediary, within the timelines prescribed by the IT Rules 2021).
10. Children's data
ClickIt is not directed at, and must not be used by, anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will delete it promptly.
11. Data breach notification
In the event of a personal data breach that is likely to affect you, we will notify you and the Data Protection Board of India (once constituted and operative) in the manner and within the timelines required by the DPDP Act and its rules.
12. Analytics and tracking
The App does not currently use third-party advertising trackers. Firebase Analytics is disabled. This section will be updated if that changes.
13. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or applicable law. Material changes will be notified in-app or by updating the effective date above, and, where required by law, by seeking fresh consent.
14. Contact us
Questions about this policy or your data, and requests to exercise your rights under Section 8, can be sent to therealdrbw@gmail.com.