Legal

Data Collection Policy

📅 Effective: April 1, 2026 🇮🇳 IT Act, 2000 Compliant ✉️ legal@fotofast.co
Effective DateApril 1, 2026
Data ControllerFotoFast Services, Hyderabad, Telangana, India
Data Contactlegal@fotofast.co
Applicable LawInformation Technology Act, 2000 (India) and IT (Amendment) Act, 2008

1. Data Collection Principles

FotoFast collects only the data that is strictly necessary to provide, improve, and secure our services. We are guided by the following principles:

2. Complete Data Inventory

2.1 Client Data

Data ElementPurposeRetention
Full NameBooking identity, messaging, invoice3 years
Mobile NumberOTP delivery, booking confirmation3 years
Event NameBooking record, photographer briefing3 years
Event LocationPhotographer assignment by area3 years
Booking DateSession scheduling, billing3 years
Session OTPsSession authentication30 days post-session
Payment IDTransaction verification, refunds7 years (tax law)
Session DurationBilling calculation3 years
Client RatingPhotographer quality management3 years

2.2 Photographer Data

Data ElementPurposeRetention
Full NameNetwork identity, client communicationEngagement + 1 year
Mobile NumberLogin authentication, admin communicationEngagement + 1 year
Email AddressApplication communication, approvalsEngagement + 1 year
Area of OperationBooking assignment algorithmEngagement + 1 year
Skills & EquipmentService matching, profileEngagement + 1 year
FotoFast FF IDSession authentication, unique identifierPermanent record
GPS LocationActive session safety and accountability90 days then deleted
Session HistoryPerformance record, payment calculation3 years
Rating ScoreQuality management, removal decisions3 years

2.3 Session Data

Data ElementPurposeRetention
Session Start TimeBilling, dispute resolution3 years
Session End TimeBilling, dispute resolution3 years
Session DurationInvoice generation3 years
GPS Location LogsSafety, dispute resolution90 days
OTP Verification LogAuthentication audit trail90 days
Payment StatusFinancial records7 years

3. Technical Data Storage

3.1 Firebase Firestore (Google Cloud)

All booking, session, photographer, and application data is stored on Google Firebase Firestore. This data is subject to Google's data processing terms. FotoFast has a data processing agreement with Google ensuring your data is handled to international standards.

3.2 Browser LocalStorage

The following data is stored in your browser's localStorage only — never transmitted to FotoFast servers:

3.3 Third-Party Data Processors

RazorpayPayment processing — razorpay.com/privacy
Firebase / GoogleDatabase and hosting — firebase.google.com/support/privacy
ImgBBTemporary image hosting (AI Studio only) — imgbb.com/tos
ReplicateAI model processing (AI Studio only) — replicate.com/privacy
WhatsAppNotification delivery — whatsapp.com/legal/privacy-policy

4. GPS Location Data — Full Disclosure

📍 GPS Tracking — Complete Transparency

WHEN: GPS tracking activates ONLY after the photographer enters the client's verified Start OTP. It stops ONLY when the client's End OTP is confirmed.

WHAT: Latitude, longitude, accuracy radius, and timestamp. Updated every 10 seconds during active session.

WHO CAN SEE IT: FotoFast admin panel only. Clients can view current location via a Google Maps link during active sessions.

STORAGE: Location coordinates are stored in Firebase under the booking record and overwritten with each update. Historical location logs are purged after 90 days.

CONSENT: All FotoFast photographers explicitly consent to GPS tracking during sessions as a condition of joining the network.

5. Data Access Controls

ClientsCan view their own booking details and session status
PhotographersCan view only their assigned bookings and session data
FotoFast AdminFull access via Firebase Auth protected admin panel
Third PartiesNo access unless required by law or explicitly consented to

6. Data Breach Procedure

In the event of a data breach that may affect your personal information:

  1. FotoFast will assess the breach within 24 hours of detection
  2. Affected users will be notified via WhatsApp within 72 hours
  3. Notification will include what data was affected, when it occurred, and what steps to take
  4. If required by Indian IT law, we will report to the appropriate authority
  5. A breach report will be published on fotofast.co within 7 days

7. Your Data Rights — How to Exercise Them

Access RequestEmail legal@fotofast.co — "Data Access Request" — responded within 14 days
Correction RequestEmail — "Data Correction" — corrected within 7 days
Deletion RequestEmail — "Delete My Data" — processed within 30 days
Portability RequestEmail — "Data Export" — CSV/JSON provided within 14 days
Opt-Out of MarketingReply STOP to any FotoFast WhatsApp message — immediate

8. Legal Compliance

🇮🇳 Compliance Statement

FotoFast operates in compliance with the Information Technology Act, 2000 (India), the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and aligns with international best practices including GDPR principles. We are committed to protecting your data and will continue to update our practices as Indian data protection law evolves.

9. Contact

Emaillegal@fotofast.co
Websitehttps://fotofast.co
AddressFotoFast Services, Hyderabad, Telangana — 500001, India
Response TimeAll enquiries responded to within 48 hours on business days

Document Version: 1.0  |  Effective: April 1, 2026  |  © 2026 FotoFast Services. All rights reserved.