Legal
Privacypolicy
This policy explains what we collect when you use this site or book a session, why we hold it, and who else touches it. We collect what the work requires and nothing more, and we do not sell your information to anyone.
Last updated 19 August 2026
What we collect
When you enquire, request a quote, or book a session, you give us:
- Your name, email address and, if you provide it, your phone number.
- The details of the session: service, date, time, location, hours, and any add-ons.
- Anything you write in a message, a questionnaire answer, or a booking note.
- Your answers to any pre-session questionnaire we send you.
If you have a client portal account, we also hold a password that is stored only as a one-way hash. We never store it in a form we could read, and we cannot tell you what your password is.
We keep records of your quotes, contracts, invoices and payments, because we are required to keep proper business records and because you need to be able to see them in your portal.
What we do not collect
We do not use advertising trackers, analytics pixels, or third party scripts that follow you around the internet. This site loads no Google Analytics, no advertising pixel, and no social media tracker.
We never see or store your full card number. Card details are entered on our payment provider's own page and are handled entirely by them.
Cookies
We set one cookie, and only after you sign in. It keeps you signed in as you move between pages of the client portal or the studio admin. It is not used for advertising and it is not shared.
Browsing the public site sets no cookie at all. Your browser may keep a note that you have already seen the opening animation, so it is not replayed on every page, and that note is held only for the current browsing session and never sent to us.
Why we hold it
- To answer your enquiry and prepare a quote.
- To take a booking, hold your date, and price the session correctly.
- To issue contracts, invoices and receipts, and to take payment.
- To deliver your finished images and let you select extras.
- To send you the messages a booking needs: confirmations, reminders, and delivery notices.
- To keep the business records the law requires us to keep.
We do not send marketing email unless you have asked for it, and if we ever do, every such message will carry a way to stop it.
Who else touches it
We use a small number of services to run the studio. Each one sees only what it needs to do its job, and none of them are permitted to use your information for their own purposes.
- Our payment provider, to take card payments and confirm they succeeded.
- Pic-Time, to host and deliver your finished gallery.
- Our email provider, to send booking confirmations, reminders and delivery notices.
- Our e-signature provider, where a contract is signed electronically.
- Our database and hosting providers, which store the site and its records.
Some of these providers operate outside Trinidad and Tobago, which means your information may be stored on servers in other countries. We otherwise share nothing with anyone, except where the law requires us to.
Photographs
Your photographs are personal information too, and we treat them that way. How they may be used, by you and by us, is set out in our terms of service. If you have asked us not to show your session publicly, that instruction is recorded against your file and applies to the portfolio, social media and any submission.
How long we keep it
- Enquiries that do not become bookings: up to 2 years, then deleted.
- Booking, contract, invoice and payment records: 7 years, to meet record keeping obligations.
- Finished galleries: for the period stated when your gallery is delivered.
- Working files and unedited frames: a limited period after delivery, then deleted.
Your rights
You can ask us at any time to:
- Tell you what we hold about you, and give you a copy.
- Correct anything that is wrong. You can edit most of it yourself in your client portal.
- Delete what we hold, where we are not required to keep it as a business record.
- Stop using your images publicly, at any time, including after we have already posted them.
Email us and we will action it. We will not charge you for it and we will not ask you why.
Keeping it safe
Access to client records is restricted to the studio and is checked on the server for every single page, not merely hidden from the menu. Passwords are hashed, connections are encrypted in transit, and administrative actions are written to an audit log.
No system is perfectly secure. If a breach ever affected your information, we would tell you what happened and what to do about it, rather than quietly hoping you did not notice.
Children
We photograph children regularly, and we do it only with a parent or guardian booking the session and present at it. We do not knowingly take booking information directly from a child.
Changes and contact
If this policy changes materially, we will say so on this page and update the date at the top. Questions, requests, and anything you want removed should go to info@kerwynjoseph.org.