Privacy Policy
This Privacy Policy explains what personal data Studio Sarthi processes, why it is used, when it may be shared and the choices available to users.
Studio Sarthi respects the privacy of studio owners, their authorised users, clients, team members and website visitors. This Policy applies to studiosarthi.com, app.studiosarthi.com, sign.studiosarthi.com and related support services.
Studio Sarthi processes personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules brought into force from time to time.
Who we are
Studio Sarthi is a photography-studio CRM service operating from Rajkot, Gujarat, India. References to “we”, “us” and “our” mean Studio Sarthi.
Privacy and grievance contact: Customer Support Manager, help@studiosarthi.com, +91 9909012324, support hours 10:00 AM to 6:00 PM IST. Business address: [ADD COMPLETE REGISTERED OR BUSINESS ADDRESS BEFORE PUBLISHING].
Our role for different data
For account registration, billing, support, security and website operation, Studio Sarthi determines why and how personal data is processed.
For client, team member, booking, quotation, agreement and studio-business data entered by a studio owner, the studio owner controls the purpose of collection and Studio Sarthi processes that data to provide the requested CRM functions. Studio owners must give appropriate notices and obtain any consent required from their clients and team members.
Personal data we may collect
Account data: owner name, studio name, phone number, email address, city, business address, logo, signature image, plan and account status.
Client and lead data: names, partner names, phone numbers, email addresses, addresses, event details, requirements, follow-up dates and communication notes.
Team data: names, roles, contact details, address, employee or freelancer status, rates, availability and payment records.
Business data: bookings, package values, advances, balances, expenses, team costs, profit estimates, quotations, agreements, terms and delivery status.
Approval data: document identifier, client name, email, OTP request and verification status, approval time and related technical logs.
Technical data: IP address, device/browser information, login and security events, cookies, diagnostic data and service activity.
Payment data: plan, amount, payment status, transaction reference and invoice details. Full card, UPI PIN and net-banking credentials are normally handled by the payment provider and are not stored by Studio Sarthi.
How we collect data
We collect data directly when a user creates an account, completes a form, configures the studio, enters CRM records, contacts support, pays for a plan or uses a feature.
We may receive limited transaction, delivery, security or technical information from payment gateways, email providers, hosting services and other authorised service providers.
Why we use personal data
To create and manage accounts, subscriptions and access permissions.
To provide leads, bookings, calendars, team, quotations, agreements, OTP approvals, finance reports and WhatsApp message preparation.
To process payments, renewals, refunds and account deactivation or reactivation.
To provide support, respond to complaints and communicate important service notices.
To detect misuse, prevent fraud, secure accounts, troubleshoot errors and improve reliability.
To meet legal, tax, accounting, consumer-protection and regulatory obligations.
To improve the service using aggregated or appropriately de-identified information where reasonably possible.
Consent and lawful processing
Where consent is required, we request clear permission for the stated purpose. A user may withdraw consent by contacting us, but withdrawal does not affect processing already completed lawfully and may limit features that require the data.
We may also process data where necessary to perform a subscription contract, comply with law, respond to a user's request, protect the service or use another lawful ground recognised under applicable law.
Cookies and similar technologies
We may use essential cookies or local storage for login sessions, security, language, theme preferences and application functionality. Optional analytics cookies should only be used in accordance with applicable consent requirements.
Blocking essential browser storage may prevent parts of the website or CRM from working correctly.
When data may be shared
We may share only the information reasonably necessary with hosting and database providers, email and OTP delivery providers, payment gateways, security and diagnostic providers, professional advisers and authorities where legally required.
Service providers are expected to process information only for authorised purposes and under appropriate confidentiality and security obligations. We do not sell personal data for money.
International processing
Some service providers may process or store data outside the user's state or outside India. Where cross-border processing occurs, we use reasonable contractual and security safeguards and follow restrictions notified under applicable Indian law.
Data retention and deletion
We retain account and CRM data for as long as reasonably necessary to provide the service, maintain business and security records, resolve disputes and comply with law.
After account closure or a valid deletion request, data is deleted or anonymised within a reasonable period unless retention is required by law, needed to establish legal claims, or temporarily remains in protected backups. Users should export important business records before cancelling or deleting an account.
Security
We use reasonable administrative, technical and organisational safeguards designed to protect personal data. These may include access controls, authentication, secure hosting, transport encryption, logs and restricted service-provider access.
No internet or storage system can be guaranteed completely secure. Users must protect passwords, devices and email accounts, and promptly report suspected unauthorised access.
Your privacy rights
Subject to applicable law, a person may request access to information about their personal data, correction or completion of inaccurate data, erasure where retention is no longer required, withdrawal of consent, and grievance redressal.
Where applicable, a person may also nominate another individual to exercise rights in the event of death or incapacity. We may verify identity before processing a request and may refuse or limit a request where permitted by law.
Children's data
Studio Sarthi is intended for business users who are at least 18 years old. Studio owners should not enter children's personal data unless it is necessary for a legitimate event-service purpose and all legally required permission from a parent or lawful guardian has been obtained.
Studio owner's responsibilities
Each studio owner is responsible for the legality, accuracy and relevance of data uploaded to the CRM; providing privacy information to clients and team members; responding to their requests; and not collecting unnecessary or prohibited information.
A studio owner must not use Studio Sarthi for unlawful surveillance, harassment, spam, discrimination or unauthorised marketing.
Data breach and complaints
If you believe personal data has been compromised or misused, contact help@studiosarthi.com promptly with the account email, a description of the issue and relevant evidence. We will review the matter and take steps required by applicable law.
If a privacy complaint is not resolved through our grievance process, the complainant may use remedies available under applicable law.
Policy updates
We may update this Policy when our service, technology or legal obligations change. Material changes will be communicated through the website, CRM or registered contact details where appropriate.