HITBOOK
PricingCommunity
Sign InGet Started

Privacy Policy

Your privacy is important to us. This policy explains how Hitbook collects, uses, and protects your information across all our platforms.

Last Updated: March 15, 2026 15 min read

Quick Navigation

1. Data We Collect2. Legal Basis3. How We Use Data4. AI & Automated Processing5. Messaging Integration6. Third-Party Services7. Data Retention8. Data Security9. Your Rights (GDPR)10. Your Rights (CCPA)11. US Privacy Law12. Cookies13. Children's Privacy14. International Transfers15. Changes to Policy16. Contact Us

Introduction

Welcome to Hitbook ("we," "our," or "us"), operated by HITBOOK INC, a Delaware C-Corporation with its principal office at 1111 B South Governors Ave, STE 2885, Dover, DE 19904, USA. We are committed to protecting your personal information and your right to privacy.

This Privacy Policy applies to all information collected through our web application (app.hitbook.io), client portal, marketing website (hitbook.io), mobile applications (iOS and Android), desktop application, and any related services, integrations, or communications (collectively, the "Service").

By using Hitbook, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

1. Data We Collect

We collect information that you provide directly to us, information we collect automatically, and information from third parties.

Information You Provide Directly

  • Account Information: First name, last name, email address, phone number, password (stored hashed, never in plain text), date of birth, and profile photo
  • Professional Profile: Business name, professional roles, skills, portfolio links, location/address, and work experience
  • Financial Information: Billing address, subscription plan, and payment method details (processed by Stripe; we do not store full credit card numbers)
  • Project & Client Data: Job details, client information, event dates, crew members, contracts, proposals, and invoices you create within the platform
  • Gallery & Media: Photos, videos, and documents you upload to galleries, albums, or the file transfer system
  • Community Content: Posts, comments, reactions, and multimedia content shared in the community feed
  • Communications: Messages sent through our in-app messenger, feedback, and support requests
  • Contracts & Signatures: Digital contracts, terms of engagement, and electronic signatures
  • AI Conversations: Text you enter in our AI assistant chatbot for registration, lead generation, or support

Information Collected Automatically

  • Device Information: IP address, browser type and version, operating system, device type, and unique device identifiers
  • Usage Data: Pages and features visited, actions taken, time spent on pages, click patterns, and navigation flow
  • Location Data: General geographic location derived from your IP address; precise location only if you grant explicit permission
  • Cookies & Similar Technologies: Session cookies, authentication tokens, referral tracking cookies, and local storage data (see our Cookie Policy)
  • Push Notification Tokens: If you enable push notifications, we store your device token to deliver notifications via Firebase Cloud Messaging (FCM)
  • Error & Performance Data: Application errors, crash reports, and performance metrics collected through Sentry for service improvement
  • Mobile Device Permissions: If you use our mobile application, we may request access to your device camera and photo library (for profile photos, post media, and gallery uploads), microphone (for voice input and video recording), and contacts (if you choose to invite contacts). Specific permissions vary by platform and device settings. You can manage these permissions at any time through your device settings.
  • Biometric Identifiers: If you enable biometric login (fingerprint or facial recognition), biometric data is processed and stored on your device only; Hitbook never receives, transmits, or stores your biometric data on our servers
  • Advertising Identifiers: On mobile devices, we may collect your device advertising identifier (such as Android AD_ID) for attribution and install tracking. You can reset or disable this identifier in your device settings

Information from Third Parties

  • Google Authentication: If you sign in with Google, we receive your name, email address, and profile picture from your Google account
  • Messaging Platforms: If you or your clients interact with us through WhatsApp, Instagram, or Facebook Messenger, we may receive message content, sender information, and conversation metadata through Meta's Business API (see Section 5)
  • Referral Data: If you were referred by an affiliate partner, we receive the referral identifier to attribute your registration

2. Legal Basis for Processing (GDPR Article 6)

Under the EU General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

Contract Performance (Art. 6(1)(b))

  • Creating and managing your account
  • Providing the core platform features (projects, jobs, calendar, gallery, contracts, invoicing)
  • Processing payments and managing subscriptions via Stripe
  • Delivering in-app messaging and notifications
  • Providing the client portal for your clients

Consent (Art. 6(1)(a))

  • Sending marketing emails and promotional communications
  • Processing messages from WhatsApp, Instagram, or Messenger for lead generation
  • Using non-essential cookies (analytics, marketing)
  • Sharing community feed content publicly

Legitimate Interest (Art. 6(1)(f))

  • Improving the Service through usage analytics
  • Detecting and preventing fraud, abuse, and security incidents
  • Error monitoring and crash reporting via Sentry
  • Enforcing our Terms of Service
  • Maintaining referral and affiliate program integrity

Legal Obligation (Art. 6(1)(c))

  • Tax reporting and invoicing requirements
  • Responding to lawful requests from authorities
  • Record-keeping obligations under applicable commercial law

3. How We Use Your Data

We use your information to provide, maintain, and improve our Service, and to communicate with you.

πŸ”§

Service Delivery

To operate your account, manage projects, process payments, deliver galleries, and provide customer support

πŸ€–

AI Assistant

To power our conversational AI for registration assistance, lead generation, and platform support

πŸ”’

Security

To detect and prevent fraud, abuse, rate-limit violations, and security incidents

πŸ“§

Communication

To send transactional emails, OTP codes, push notifications, and marketing communications (with consent)

4. AI & Automated Processing

Hitbook uses artificial intelligence to enhance the platform experience. This includes:

How AI Is Used

  • Conversational AI Assistant: Our AI chatbot helps new users register, answers platform questions, and assists with lead generation. Conversations with the AI are processed by third-party AI providers (currently Google Gemini).
  • Lead Analysis: When enabled, incoming messages from WhatsApp, Instagram, or Messenger may be analyzed by AI to identify potential client leads for your business.

Your Rights Regarding AI Processing

  • You have the right to know when you are interacting with an AI system rather than a human
  • No binding decisions about your account, access, or pricing are made solely by AI without human review
  • You may request to opt out of AI-powered lead analysis by contacting us at privacy@hitbook.io
  • AI conversation data is generally retained for a limited period for service improvement and may be periodically purged

5. Messaging Platform Integration

Hitbook integrates with Meta's Business API to help creative professionals manage client communications and generate leads. This integration may involve the following platforms:

  • WhatsApp Business
  • Instagram Direct Messages
  • Facebook Messenger

What Data Is Processed

  • Message content and metadata (sender name, phone number or profile, timestamps)
  • Conversation context for lead identification
  • Delivery and read receipts

How This Data Is Used

  • To display incoming messages within Hitbook's unified inbox
  • To analyze message content for lead generation (with the photographer's consent)
  • To send replies on behalf of the photographer

Important Information for Message Senders

  • If you send a message to a business using Hitbook through WhatsApp, Instagram, or Messenger, your message may be received, stored, and processed by Hitbook on behalf of that business
  • Your message may be analyzed by AI to identify if you are a potential client
  • You can request deletion of your messages by contacting the business directly or by emailing us at privacy@hitbook.io
  • This processing is governed by Meta's own Platform Terms and data policies in addition to this Privacy Policy

6. Third-Party Service Providers

We do not sell your personal information. We share data with the following categories of service providers who process data on our behalf:

Service Providers

  • Stripe (USA) - Payment processing, subscription billing, and financial operations. Stripe receives your name, email, and payment method details. See Stripe's Privacy Policy.
  • Google Cloud Platform (USA/Global) - Cloud hosting, data storage, and compute infrastructure
  • Cloudflare R2 (Global) - Media file storage for photos, videos, and documents you upload
  • Pusher (UK) - Real-time messaging infrastructure for in-app chat
  • Firebase / Google FCM (USA) - Push notification delivery to mobile devices
  • Twilio (USA) - SMS delivery for OTP verification codes
  • SendGrid (USA) - Transactional and marketing email delivery
  • Google Gemini (USA) - AI language model for the conversational assistant, lead analysis, and content generation
  • Sentry (USA) - Error monitoring and crash reporting
  • Meta Business API (USA/Global) - WhatsApp, Instagram, and Messenger message delivery and receipt

Other Sharing Scenarios

  • Your Clients: When you share galleries, contracts, or project details through the client portal, your clients can access that content
  • Community & Public Activity: Content you post in the community feed (including posts, replies, comments, albums, and embedded media) is visible to other Hitbook users. Your professional profile information may also be visible to other users through search, browsing, and discovery features, depending on the feature and your settings
  • Affiliate Partners: If you participate in our affiliate program, we share referral attribution data with the referring partner (no personal details of referred users are shared)
  • Legal Obligations: We may disclose data when required by law, court order, or government request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity

Data Controller & Processor Responsibilities

Hitbook's data processing role varies depending on the type of data involved:

  • Hitbook as Controller: For data collected directly from you in connection with your use of the Service (e.g., your account information, usage data, community posts, billing information, and communications with us), HITBOOK INC acts as the data controller. We determine the purposes and means of processing this data as described in this Privacy Policy.
  • Hitbook as Processor/Service Provider: When you use the platform to store, manage, or process personal data about your clients, contacts, leads, crew members, event participants, or other third parties (e.g., client CRM data, project participant information, gallery recipients, contract signers, or Meta messaging contacts), Hitbook acts as a data processor or service provider on your behalf. You remain the data controller for this data.

As the data controller for client, contact, and business data you upload or process through the platform, you are solely responsible for:

  • Ensuring you have a lawful basis (e.g., consent, contractual necessity, or legitimate interest) to collect, store, process, and share personal data through the platform
  • Providing appropriate privacy notices to your clients, contacts, and other data subjects about how their data will be processed
  • Obtaining any required consents from individuals whose data you upload, store, or process through the platform
  • Responding to data subject access requests, deletion requests, and other privacy rights requests from individuals whose data you control
  • Ensuring your use of the platform complies with applicable data protection laws (including GDPR, CCPA, and other local privacy regulations)
  • Evaluating whether the platform's technical and organizational measures are appropriate for the types of personal data you process

Hitbook will process such data solely in accordance with your instructions as implemented through the Service's features and settings, and in compliance with applicable law.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law.

Retention Periods

  • Account Data: Retained for the lifetime of your account. After a deletion request, data is removed within a reasonable period, subject to legal retention obligations
  • Financial Records: Retained for 7 years as required by applicable tax law and commercial regulations
  • Chat Messages: Retained for the lifetime of your account; generally deleted within a reasonable period of account closure
  • Gallery & Media Files: Retained until you delete them or close your account; deleted within a reasonable period of account closure
  • AI Conversation Logs: Generally retained for a limited period for service improvement, then periodically purged
  • Meta Messaging Data: Incoming messages retained for a limited period or until the lead is converted or dismissed
  • Lead Data: Retained for the lifetime of the business user's account who generated or received the lead, or until explicitly deleted by the business user
  • Error & Performance Logs: Retained for a limited period consistent with our service provider retention policies
  • Cookies: Session cookies expire when you close your browser; persistent cookies expire after 7 days (authentication) or 30 days (referral)
  • Community Feed Posts: Retained until you delete them or close your account

Important: Backup Responsibility

You are solely responsible for maintaining independent backups of all files, media, contracts, communications, galleries, and business records that you store on the platform. While we take reasonable precautions to protect your data, we do not guarantee against data loss from accidental deletion, system failures, third-party infrastructure issues, security incidents, or account closure. We strongly recommend keeping your own copies of all important documents and files.

8. Data Security

We implement industry-standard security measures to protect your information:

TLS/SSL Encryption in Transit
Industry-Standard Password Hashing
Periodic Security Reviews
Rate Limiting & CSRF Protection

We also employ a range of technical and organizational security measures, which may include Content Security Policy (CSP) headers, HTTP-only cookies with SameSite protection, input sanitization, webhook signature verification, and role-based access controls, depending on the feature and context. Despite our efforts, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

Our Service relies on third-party infrastructure and service providers (including cloud hosting, file storage, payment processing, and messaging services). The security and availability of your data also depends on these third-party providers and their own security practices. We are not responsible for security incidents or data loss caused by vulnerabilities or failures in third-party infrastructure.

9. Your Rights Under GDPR (EU/EEA Residents)

If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation:

Access

Request a copy of all personal data we hold about you (Art. 15)

Rectification

Request correction of inaccurate or incomplete data (Art. 16)

Erasure

Request deletion of your personal data ("right to be forgotten") (Art. 17)

Portability

Receive your data in a machine-readable format (Art. 20)

Objection

Object to processing based on legitimate interest (Art. 21)

Restriction

Request limited processing of your data (Art. 18)

To exercise any of these rights, you can:

  • Account Deletion: Request deletion of your account through your account settings or by contacting us. Your account will be deactivated and permanently deleted after a reasonable grace period, during which you may cancel the request.
  • Data Export: Request a copy of your data by contacting us at privacy@hitbook.io.
  • Other Rights: Contact us at privacy@hitbook.io for any other privacy request.

We aim to respond to all requests within 30 days where required by applicable law, or as soon as reasonably practicable. In complex cases or where we receive a high volume of requests, we may extend the response period by an additional 60 days, in which case we will inform you of the extension and the reasons for the delay. You also have the right to lodge a complaint with your local Data Protection Authority.

10. Your Rights Under CCPA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:

Your CCPA Rights

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you
  • Right to Delete: You can request that we delete your personal information, subject to certain exceptions
  • Right to Opt-Out: We do not sell your personal information. If this changes, we will provide a "Do Not Sell My Personal Information" link
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To exercise your CCPA rights, contact us at privacy@hitbook.io or use the contact information in Section 16.

11. US Privacy Compliance

HITBOOK INC is incorporated in Delaware, USA. We comply with applicable US federal and state privacy laws. Under US law:

  • You have the right to access your personal data held in our systems
  • You may request correction or deletion of inaccurate data
  • You may opt out of the use of your data for direct marketing purposes
  • We maintain appropriate security measures to protect your personal information

For privacy inquiries, contact us at privacy@hitbook.io.

12. Cookies & Tracking

We use cookies and similar technologies to enhance your experience, maintain your session, and track referrals. For detailed information about each cookie we use, its purpose, and duration, please see our Cookie Policy.

13. Children's Privacy

Hitbook is designed for professional use and is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18 (or 16 in the EU/EEA). If we discover that we have inadvertently collected data from a child, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at privacy@hitbook.io.

14. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States (where our company is incorporated and many of our service providers are located).

For transfers from the EU/EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable and as required by law
  • Adequacy decisions where applicable
  • Data Processing Agreements with sub-processors that include appropriate safeguards

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending an email notification for significant changes that affect your rights
  • Displaying an in-app notification upon your next login

Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please contact us:

Email: privacy@hitbook.io
WhatsApp: +1 (302) 342-6683
Company: HITBOOK INC, 1111 B South Governors Ave, STE 2885, Dover, DE 19904, USA

We aim to respond to all privacy-related inquiries within 30 days.

Hitbook

The operating system for creative professionals. Manage your entire business in one place.

Product

  • Features
  • Project Management
  • Client CRM
  • Payments
  • Digital Contracts
  • Pricing

Solutions

  • For Photographers
  • For Videographers
  • For Studios
  • For Freelancers

Resources

  • Help Center
  • Download Apps
  • Contact Us

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Accessibility

Β© 2026 Hitbook. All rights reserved.

Made with❀️for creatives worldwide
πŸ”’ Admin