2. Photographer Plus media processing and retention
For Photographer Plus, the Hitbook desktop application reads selected local JPEG files, validates their type, size, dimensions, and checksum, and creates a temporary local preview cache. The local preview cache is stored under the application data area, is not exposed as a local file path to website code, and is removed under cache expiry and logout rules.
Original images may contain EXIF, GPS, camera, copyright, and ICC color profile data. The original remains byte for byte unchanged. Separate thumbnails and display copies may remove sensitive metadata and are processed independently.
Cloud providers and retention
- Providers:Private hot photo objects and display copies are stored in Cloudflare R2. AWS Lambda in Frankfurt (eu-central-1) transiently processes master originals to generate display renditions that return to R2; the temporary processing copy is deleted after the job and is not retained as an AWS storage object. Amazon S3 Glacier Deep Archive stores archived originals in the same region. Stripe processes Photographer Plus web billing.
- Access protection:Photo objects are private and delivered through short lived signed access. We use access controls, encryption in transit, storage encryption, checksums, audit records, and role based permissions appropriate to the workflow.
- Retention:When the 30-day trial ends, the account returns to the free 3 GB plan. Trial originals are not deleted automatically at expiry. Paid accounts receive a 45 day grace period to view, select whole galleries to keep, reactivate and export. If usage remains above 3 GB, the oldest whole galleries may be permanently deleted first, while active selection, design, approval, print or export workflows, disputes and legal holds are protected and reviewed.
- Deletion and exceptions:Deletion includes hot, archived, display, thumbnail, and temporary restored copies. Limited residual backup copies, security records, billing records, consent records, and legal or audit records may remain for controlled periods where required.
- Roles and transfers:The photographer or studio is generally the controller of client image data and Hitbook generally processes it on the business user instructions. Cloudflare and Amazon Web Services may process data internationally under their contractual and legal transfer safeguards.
3. Video Studio media storage and delivery
Video Studio managed storage processes finished MP4 or MOV files uploaded for client review, comments, drawings, frame anchored feedback, revisions, approval, and delivery. Supported video codecs include H.264, H.265, and ProRes at supported 8, 10, or 12 bit depth; audio may be present. Hitbook validates the declared format and may create a short teaser and a playback-compatible copy; the uploaded original remains stored separately. This processing also applies before a video is linked to a project.
Media bytes travel directly between the user device and private Cloudflare R2 through time limited controlled requests. Hitbook application servers may process metadata, ownership, checksums, sizes, codec validation results, review anchors, access records, billing state, and audit events, but the upload and playback media body is not routed through Google Cloud application servers.
The included allowance is 2 GB. Additional paid capacity is measured in decimal 1 TB units. Stored revisions, generated teasers, and playback copies count toward retained physical bytes until deletion completes. Usage warnings are sent at 80% and 95%. At the capacity limit, new uploads are blocked while users can still view, export, and delete existing media.
When paid capacity ends, the entitlement returns to the included allowance after the paid period. Existing media is not automatically deleted solely because usage is above the reduced capacity. Account closure, an authorized deletion request, or other documented lifecycle action can trigger deletion from R2, subject to legal holds, security and audit records, provider deletion completion, and limited backup retention. General files, raw footage, camera originals, and edit projects remain in user connected Google Drive or Dropbox workflows where available.
After the owner confirms deletion of an entire Film Studio workflow, active versions, review comments, drawings, film-specific music references and chat are removed from Hitbook, and exclusive managed Cloudflare R2 media is deleted. Eligible Google Drive files linked only to that film are moved to Drive Trash; files referenced elsewhere and shared music libraries remain. Financial and audit records, limited backups, and legal holds may remain under applicable retention rules. A provider or database failure may leave cleanup partially complete. Hitbook makes up to five automatic processing attempts; unresolved failures require operator review, and the owner can view the deletion status. Recovery from Drive Trash depends on Google and is not guaranteed by Hitbook.
4. Importing selected media from Google Drive
If you choose an accessible Google Drive video or select photos through Google Picker, the Hitbook desktop app temporarily downloads only those selected files to your device and uploads them to private Cloudflare R2 under the applicable Video Studio or gallery rules. The original remains in Google Drive; importing does not delete or change it. A pasted link works only when the connected Google account has access. Selecting a folder does not mean that every file in it has been imported.
Google provides the selected file metadata and a short lived access grant. Hitbook application servers may process identifiers, names, sizes, access status, and upload records, but the media body moves through your device rather than through our Google Cloud application servers. The desktop app removes temporary downloads after a completed or cancelled import; resumable attempts may retain a copy temporarily and abandoned copies are cleaned later. Imported copies count toward your Hitbook storage limits and follow the same retention, export, and deletion rules as files uploaded from your device.
5. Introduction and scope
Welcome to Hitbook. Hitbook is operated by HITBOOK INC, a Delaware C Corporation with its principal office at 1111 B South Governors Ave, STE 2885, Dover, DE 19904, USA. This Privacy Policy explains how we collect, use, share, retain, and protect personal data.
Hitbook is the business side platform used by creative professionals and businesses to manage their operations. Production Book is the client facing portal connected to Hitbook, where clients of Hitbook users may access project details, approve proposals, sign contracts, make payments, select photos, approve albums or videos, request revisions, communicate with the business, and track project status.
This Privacy Policy applies to Hitbook, Production Book, app.hitbook.io, hitbook.io, mobile and desktop applications, client portals, integrations, communications, and related services. Together, these are the Service.
6. Notice when information is collected
Unless we expressly state that a specific disclosure is required by law, you generally have no legal obligation to provide personal data to Hitbook. Providing data is voluntary, but account, billing, security, upload, gallery, collaboration, support, or other required fields may be necessary to enter into or perform the service contract. If you do not provide required data, we may be unable to create the account, complete the transaction, secure access, or provide the requested feature.
The purposes of collection, categories of recipients, international transfers, retention periods, and available rights are described in this Policy, the applicable collection screen, the Subprocessor List, and the Photographer Plus Storage Policy. Business users who submit information about other people remain responsible for giving those people any notice required by law.
7. Photographer, client, and child-media responsibility
Hitbook account services are not directed to children as account holders. Professional event media may include children, guests, family members, and people who never create an account. The photographer or business user determines why that media is collected and shared and must provide required notices, choose a lawful basis, manage gallery recipients, and honor applicable requests.
Hitbook acts as controller for data it determines to process for account, billing, security, support, and service administration. For customer media and client data, Hitbook generally acts as processor, service provider or holder on documented business-user instructions. If the business user is itself a processor, Hitbook may act as its subprocessor.
Where applicable law provides them, a person may opt out of qualifying targeted advertising or sharing, withdraw consent, limit qualifying sensitive-data use, and appeal a denied privacy request. Hitbook does not sell personal data for money. Requests concerning data controlled by a photographer may be referred to that photographer, with reasonable assistance from Hitbook.
8. Our role and business user responsibility
Hitbook may act as a controller for account, billing, security, marketing, support, website, and product usage data that we determine how to process. When a business user uses Hitbook or Production Book to process personal data about clients, leads, contacts, guests, event participants, team members, vendors, subcontractors, collaborators, or other third parties, Hitbook generally acts as a processor or service provider on behalf of that business user.
If your personal data is processed by a business that uses Hitbook or Production Book, that business is usually the controller of your data. We may direct your request to that business or assist the business in responding, depending on our legal role.
Business user responsibility
Business users are responsible for ensuring they have the necessary rights, permissions, consents, notices, and lawful basis to upload, store, share, publish, or otherwise process personal data, photos, videos, contracts, messages, documents, and other content through Hitbook and Production Book.
- Third party data:Business users may add data about clients, leads, guests, family members, minors, employees, contractors, vendors, designers, editors, print houses, and other people who do not create a Hitbook account.
- Legal basis:Business users must provide required privacy notices, obtain required consents, honor applicable privacy rights, and use the Service in compliance with data protection, consumer, communications, intellectual property, and industry laws.
- Sensitive content:Users should not upload unlawful content, content they do not have rights to use, payment card data, government identification documents, medical information, biometric identifiers, special category data, or highly sensitive personal information unless the feature specifically requires it and the user has a lawful basis.
9. Personal data we process
We may process personal data that you provide directly, data collected automatically, data received from business users, clients, integrations, service providers, and connected communication channels.
Account, business, and profile data
- Account data:Name, email address, phone number, password credentials stored in protected form, profile photo, language, account settings, authentication records, and device data.
- Business profile:Business name, professional roles, portfolio links, skills, location, public profile content, marketplace profile data, availability, work history, and business descriptions.
- Subscription and billing:Plan, billing address, tax data, invoices, receipts, payment status, subscription status, referral attribution, affiliate identifiers, conversion status, and payout related metadata.
Client, project, and workflow data
- Client and lead data:Client names, emails, phone numbers, addresses, event details, family or guest data, preferences, notes, messages, project history, proposal data, and CRM records.
- Projects and operations:Projects, schedules, timelines, tasks, positions, checklists, crew assignments, producer workflows, subcontractor engagements, role permissions, files, shared folders, comments, statuses, and business operations.
- Contracts and approvals:Proposals, contracts, electronic signatures, approval records, OTP verification records, signer data, timestamps, IP address, user agent, document hashes, and related audit records.
Media and production data
- Media:Photos, videos, audio, documents, thumbnails, source links, file names, file metadata, gallery selections, favorites, comments, albums, album proofs, video review files, and event footage.
- Album workflows:Selected photos, album design files, revision requests, comments, approval records, designer assignments, production status, print status, delivery status, and related project metadata.
- Video workflows:Video review links, external media links, editor or colorist assignments, music selections, comments, annotations, revision requests, version history, approval records, download logs, and delivery status.
- Print workflows:Album order details, print specifications, quantities, sizes, production notes, assigned print house, secure download records, production status, shipping or delivery status, and related communications.
10. Media, third parties, and minors
Media uploaded to the Service may include photos, videos, audio, documents, gallery selections, album designs, video review files, event footage, and other content that may identify clients, guests, minors, family members, employees, contractors, or other third parties.
The Service is not intended for use by children under 18. However, business users may upload media or project information that includes minors as part of professional photography, videography, event, family, school, album, gallery, or client work. In such cases, the business user is responsible for obtaining any required parental consent, legal basis, authorization, and notices.
11. How we use personal data
Service operation
- Core features:To create accounts, authenticate users, provide Hitbook and Production Book, manage projects, CRM records, calendars, tasks, proposals, contracts, galleries, albums, videos, payments, invoices, teams, and workflows.
- Client portals:To allow clients of business users to view project data, approve proposals, sign contracts, make payments, select photos, review videos, approve albums, request revisions, communicate, and track progress.
- Collaboration:To support employees, freelancers, subcontractors, producers, designers, editors, print houses, vendors, and collaborators according to roles, assignments, workspace settings, and project level permissions.
Legal bases
- Contract:To provide the Service, manage accounts, process payments, deliver requested features, and support business user instructions.
- Consent:For optional marketing, certain cookies, optional integrations, some communication features, and other cases where consent is required.
- Legitimate interests:For security, fraud prevention, product improvement, analytics, support, error monitoring, referral integrity, dispute resolution, and service integrity where permitted by law.
- Legal obligations:For tax, accounting, invoicing, financial, commercial, legal, regulatory, and law enforcement requirements.
12. AI assisted features
Hitbook may use AI assisted features for registration assistance, lead detection, customer support, content generation, message analysis, proposal help, profile building, project summaries, and workflow assistance. AI features may process text, project information, lead information, messages, prompts, support requests, business profile data, source URLs, uploaded attachments, or other information submitted by users for the purpose of providing the requested feature. Current AI infrastructure may include Google Gemini.
Users should not submit sensitive personal data, special category data, confidential client information, payment card data, government identification numbers, medical information, biometric identifiers, or other highly sensitive information into AI features unless necessary for the intended feature and legally permitted.
We do not use business customer data or client data to train our own general purpose AI models. Third party AI providers process data according to their applicable terms, privacy commitments, and data processing agreements. Provider retention and training commitments may vary by provider, product tier, and configuration.
The use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
13. Payments, invoices, and financial records
Payments may be processed by supported third party payment processors such as Stripe or Stripe Connect, Tranzila, PayMe, or other supported processors, depending on region, feature, and configuration. Where available, supported payment methods may include credit card, Apple Pay, Google Pay, Bit, bank transfer, or other local methods. We do not store full credit card numbers.
We may process payment status, invoice data, tax details, payment provider identifiers, masked card details, refund data, payout metadata, manual review records, fraud signals, webhook events, and payment related audit records. Payment providers process payment data under their own terms and privacy policies.
14. Messaging, notifications, and connected channels
The Service may support in app messaging, email, SMS, OTP verification, WhatsApp, push notifications, realtime updates, and connected social or messaging channels. Messaging and OTP verification may be provided through supported providers such as Twilio, Upsend, Telnyx, Sinch, Firebase, Gmail API, SendGrid, Postmark, AWS SES, or other providers depending on region, channel, and configuration. Socket.IO application updates use Hitbook-managed Socket.IO infrastructure.
If you message a business that uses Hitbook through WhatsApp, Instagram, Messenger, or another connected channel, your message may be received, stored, analyzed, and processed by Hitbook on behalf of that business. This may be used to identify leads, create CRM records, support customer communication, generate project records, and help the business respond to clients.
Requests to access or delete such messages may need to be directed to the business user, because the business user is generally the controller of that client or lead data.
16. Collaboration, marketplace, public profiles, and referrals
If a business user invites employees, freelancers, subcontractors, producers, designers, editors, print houses, or other collaborators, we may process their contact information, role, permissions, assignments, availability, activity, project access, task status, workflow status, cancellation records, and related communications. Access to project data may depend on roles, permissions, assignments, workspace settings, and project level sharing configured by the business user.
Marketplace and job features may process job posts, applications, invitations, bids, proposals, availability, work history, ratings, status changes, hiring decisions, cancellation records, and related communications. Information submitted to marketplace or job features may be visible to the business user, invited collaborators, applicants, or other users depending on the feature and settings.
Users may choose to publish portfolio items, albums, videos, business profiles, descriptions, links, posts, comments, reactions, marketplace activity, or other content. Publicly shared content may be visible to other users, clients, search engines, or anyone with the link, depending on the feature and privacy settings. Referral tracking may include referral codes, affiliate identifiers, signup attribution, conversion status, subscription status, and payout related metadata, but not unnecessary client project content.
17. Third party integrations
If you connect third party integrations such as Google authentication, Gmail, Google Calendar, Google Drive, Dropbox, Meta Business integrations, payment providers, storage providers, calendar tools, contact tools, or productivity services, we may process account identifiers, tokens, scopes, file and folder references, calendar events, availability, message data, contact information, metadata, and related records as needed to provide the integration.
You can disconnect many integrations through account settings or the relevant third party service. Some records may remain where needed for legal, security, audit, backup, dispute resolution, or business continuity purposes.
18. Security and audit logs
We use technical and organizational safeguards designed to protect personal data, including TLS encryption in transit, protected password storage, authentication controls, rate limiting, input validation, CSRF and cookie protections where applicable, role based access control, workspace isolation, project level permissions, audit logs, webhook signature verification, and secure handling of payment provider webhooks.
We may collect and maintain activity logs and audit records, such as logins, account changes, role and permission changes, proposal approvals, contract signatures, payment status changes, invoice actions, file access, gallery actions, album approvals, video approvals, revision requests, workflow status changes, download records, and security events. We use these records for security, accountability, dispute resolution, fraud prevention, compliance, and service integrity.
No method of transmission or storage is perfectly secure. We cannot guarantee absolute security.
19. Data retention, export, and deletion limits
We retain personal data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, maintain security, prevent fraud, enforce agreements, and support legitimate business operations. Exact retention may depend on the feature, workspace settings, legal obligations, backup cycles, and whether Hitbook acts as controller or processor.
Typical retention categories
- Account data:Retained while the account is active and then deleted or anonymized after account deletion, subject to legal obligations, security needs, backups, and legitimate retention requirements.
- Financial and tax records:Invoices, payments, tax, accounting, and commercial records are generally retained for 7 years or longer if required by applicable law.
- Contracts and approvals:Contracts, electronic signatures, proposal approvals, album approvals, video approvals, payment records, and related audit records may be retained while the business account is active and as needed for legal, commercial, compliance, and dispute resolution purposes.
- Media and project files:Galleries, photos, videos, albums, documents, and production files are generally retained until deleted by the business user or account closure, subject to backup retention, legal holds, and workspace settings.
- Backups:Backup copies are deleted or overwritten according to backup cycles, generally within up to 90 days unless legal, security, or operational reasons require longer retention.
- Security and error logs:Security, error, performance, and abuse prevention logs are generally retained for 30 to 180 days unless needed for investigation, fraud prevention, legal compliance, or service integrity.
- AI logs:AI related logs are retained only as needed for the feature, security, abuse prevention, debugging, and compliance, subject to provider terms and configuration.
- Messaging data:Meta, WhatsApp, SMS, email, and in app messages may be retained until dismissed, converted into a lead, client, or project, deleted by the business user, account closure, or according to workspace retention settings.
- Audit logs:Audit logs may be retained for a longer period where needed for security, compliance, dispute resolution, fraud prevention, legal defense, and service integrity.
Deletion and export limits
Deletion and export requests may be limited by legal obligations, tax and accounting records, signed contracts, dispute resolution, backup retention, security logs, fraud prevention, audit records, and records controlled by business users. If your personal data is processed by a business user through Hitbook or Production Book, we may direct your request to that business user or assist that business user in responding.
20. Accounting data residency and mandatory retention
The residency cell belongs to the business account, not to the person signing in. The Israeli (IL) accounting cell is the only active accounting cell. Before activation of any future EU or US cell, Hitbook will verify the business legal domicile and tax registration, assign an immutable residency cell, and enforce active-business and cross-cell access controls. Language, device location and IP address never determine the cell.
The active Israeli accounting cell stores its primary database and protected financial documents in Israel. Invoices, receipts, credit documents, allocation records, integrity hashes, audit trails and required backups are retained for at least 7 years, or longer where applicable law requires. Account closure or a deletion request does not erase records that Hitbook or the business must legally retain.
21. Retained accounting evidence, access, and deletion
Retained-evidence features apply when enabled for the business account. Accounting evidence includes issued originals, later allocation copies, uploaded customer-signed credit copies, review decisions and acknowledgement audit records. A later copy does not replace the issued original; uploading or viewing a copy does not establish customer acknowledgement. A recorded review and acknowledgement are separate steps. Historical evidence exports do not determine eligibility for a current report.
Private accounting PDFs and retained credit copies use Google Cloud Storage; linked accounting metadata and review records use MongoDB. This processing includes document identifiers, customer and business details, signatures where present, integrity checks, actor identifiers, timestamps, IP addresses and browser information for accounting, authorized access, verification and audit. The existing Israeli accounting residency commitments apply; other processing and international access remain subject to the disclosed subprocessor and transfer rules.
A business accounting export requires authority over that business. A personal-data access request concerns the requesting person and does not grant access to another business account or all its customer records. Exports can be partial because of size or record limits, missing files, integrity failures or unavailable retained versions; check coverage and warnings and request assistance for missing records. An export describes retained historical evidence, not current report eligibility.
Account cancellation, downgrade, deletion or removal of project media does not erase accounting evidence subject to legal retention or a lawful hold. Retained identifiers can remain necessary to link an original, a copy, a review and an acknowledgement. An interrupted or incomplete deletion requires operator review and must not be treated as completed erasure. Existing legal retention periods and rights of access after cancellation are not reduced by these rules.
Financial evidence is separate from photo, video and DJ audio capacity, archive schedules and restore times. No new capacity entitlement, fee or purchase is created by these disclosures. Exporting a ZIP, retaining a file version or seeing a backup status is not a completed restore. Keep independent copies and request authorized recovery assistance when needed; recovery depends on retained data, access checks and provider availability. No fixed restore time or unlimited storage is promised here, and mandatory backup and recovery duties remain applicable.
22. Your privacy rights
Depending on your location and our role, you may have rights to access, correct, delete, export, object to, restrict, withdraw consent, opt out of certain marketing or sharing, limit certain sensitive data uses, and lodge a complaint with a privacy authority. We do not discriminate against users for exercising privacy rights.
California residents may have rights under CCPA and CPRA, including rights to know, access, correct, delete, opt out of sale or sharing where applicable, limit certain uses of sensitive personal information where applicable, and non discrimination. EU, EEA, UK, Israeli, and other residents may have additional rights under applicable law.
For Hitbook account users, contact privacy@hitbook.io. For clients of a business using Hitbook or Production Book, contact the business first when that business controls the data. We may assist where legally required.
23. Israeli Privacy Protection Law, Amendment 13, and security incidents
Where the Israeli Privacy Protection Law, including Amendment 13, applies, HITBOOK INC may act as a database controller for account, billing, security, marketing, support, and product-administration data that it determines how to process, and as a holder or processor for personal data that a business user submits about clients, guests, workers, and other third parties.
Depending on the size, sensitivity, and nature of the database and processing, Israeli law may require database registration or notification, appointment of a data protection officer, security regulations compliance, documentation, and other duties. Business users remain responsible for their own Israeli privacy compliance for data they control.
If we confirm a security incident involving personal data for which we are responsible, we will take reasonable containment and mitigation steps and provide notice without undue delay to the affected business customer and, where required by applicable law, to the relevant authority or data subjects. Business users who control client data remain responsible for notices they must give their own data subjects.
Israeli residents may lodge a complaint with the Privacy Protection Authority. Privacy requests and questions may be sent to privacy@hitbook.io. For data controlled by a business user, contact that business first; we will assist or route the request where appropriate.
For privacy requests we receive as controller, we aim to respond within 30 days, or longer where permitted by applicable law for complex or numerous requests. We may ask for information reasonably needed to verify the requester.
25. International transfers
Personal data may be processed in the United States, Israel, the EU, the EEA, the United Kingdom, and other locations where Hitbook, affiliates, service providers, subprocessors, or infrastructure providers operate. Transfer locations may depend on hosting, storage, payment, messaging, AI, support, and integration providers.
Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, Data Processing Agreements, contractual commitments, and other lawful transfer mechanisms.
26. Mobile, desktop, device permissions, and biometric login
Mobile or desktop apps may request access to camera, photo library, files, notifications, contacts, calendar, location, microphone, or local storage only when needed for the requested feature and subject to device permissions. You can manage device permissions through your operating system settings.
If you use biometric login on a supported device, biometric verification is handled by your device operating system. Hitbook does not receive or store your fingerprint, face scan, or biometric template.
27. Changes and contact
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Service. We will post the updated policy with a new last updated date and, where required, provide additional notice.
For privacy requests from Hitbook account users, contact privacy@hitbook.io. For clients, guests, leads, or other individuals whose data is processed by a business using Hitbook or Production Book, contact that business first when the business controls the data. You may also contact us at privacy@hitbook.io, and we will route or assist with the request where appropriate.
Company: HITBOOK INC, 1111 B South Governors Ave, STE 2885, Dover, DE 19904, USA. WhatsApp: +1 (302) 342-6683.
28. Messages, voice notes and shared locations
Messages are shared with conversation participants. Sharing your current location sends a single location you choose to send, not continuous tracking. Microphone and location permissions are requested for these optional features; you can cancel before sending. Typing indicators are temporary. Read receipts identify the participant and the recorded read time; they do not prove that a person listened to or understood a message.
New voice notes are compressed and stored in private Cloudflare R2 storage. Playback requires participant authorization and uses temporary links lasting up to 15 minutes. This is not end-to-end encryption: Hitbook processes messages and audio to provide the service. Older voice notes may be copied to private playback storage. Other attachments and previously shared copies can follow different access and retention rules.
The mobile voice cache is account-scoped, capped at 50 MB and retained for up to 7 days; it is cleared on sign-out. The web voice cache is temporary memory, capped at 20 MB and 50 entries, and cleared on account change. These caches are not backups. Sent recordings follow message-history retention. Unattached recordings become eligible for cleanup after 24 hours. Deleting a message does not instantly erase authorized downloaded copies, unexpired links or retained message history. See the retention, international transfers and data-rights sections for applicable rules.