Privacy Policy
Last updated: July 19, 2026
Lnsly ("we", "us", "our") provides studio management software for photographers. This policy explains what personal data we collect, how we use it, and your rights. By using Lnsly you agree to the practices described here.
1. Data we collect
We collect three categories of data: (a) Account data — your name, email, phone number, business name, and profile photo, provided during signup or in settings; (b) Studio data you create — clients, bookings, contracts, payments, packages, and any files or photos you upload; (c) Technical data — IP address, browser, device, and usage events, collected automatically to keep the service secure and reliable.
2. Google user data (Google Calendar integration)
If you choose to connect your Google account, Lnsly integrates with Google Calendar so that bookings you create in Lnsly appear on your calendar. This section discloses exactly what Google user data Lnsly accesses, how we use it, whether we share it, how we protect it, and how long we keep it.
- What Google user data we access
- With your explicit consent, Lnsly accesses (a) the list of calendars in your Google account — calendar names and IDs — so you can choose which one to sync to, and (b) permission to create, update, and delete calendar events on the single calendar you select. Lnsly also receives a Google OAuth access token and refresh token that authorize these actions. We do NOT read, import, or store the contents of events you or others create outside Lnsly.
- How we use Google user data
- We use this data solely to provide the calendar-sync feature you enabled: reading your calendar list so you can pick a target calendar, and creating, updating, or deleting events that mirror your Lnsly bookings and sessions. We do NOT use Google user data for advertising, we do NOT sell it, and we do NOT use it to develop, improve, or train generalized artificial-intelligence or machine-learning models.
- Whom we share, transfer, or disclose Google user data to
- We do NOT share, transfer, or disclose your Google user data to any third party for their own purposes. The Google OAuth token is stored only in our database provider (Supabase) and processed on our hosting provider (Vercel), which act strictly as our service providers to run this feature on our behalf and are bound by their own data-protection terms. Lnsly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- How we protect Google user data
- We treat Google OAuth tokens as sensitive data. They are transmitted only over encrypted TLS/HTTPS connections, stored server-side, protected by row-level access controls and service-role-restricted access, and never exposed to the browser or to other customers. Access to the underlying secrets follows least-privilege practices.
- How long we retain Google user data and how to delete it
- We retain your Google OAuth token only while your Google account stays connected. When you disconnect from Settings → Integrations, or when you delete your Lnsly account, we delete the stored Google token and selected-calendar ID from our database, which stops all further calendar access. You can also revoke Lnsly's access at any time from your Google Account permissions page at myaccount.google.com/permissions. Calendar events already created by Lnsly remain on your Google Calendar under your control; deleting the corresponding booking or session in Lnsly removes its event.
3. How we use your data
We use your data to operate the service (let you log in, store your bookings, send transactional emails), to keep the service secure (detect abuse, prevent fraud), and to improve the product (anonymous usage analytics). We do not sell your data.
4. Service providers
We share data with vendors strictly to operate Lnsly: Supabase (database + auth), Vercel (hosting), Resend (transactional email), Google (Calendar sync, if enabled), and Sentry (error monitoring). Each receives only the data needed to perform its function and is bound by its own data-protection terms.
5. Data retention
We keep your account data while your account is active. If you delete your account, we delete personal data within 30 days, except records we must retain for legal, accounting, or fraud-prevention reasons. Backups are purged within 90 days.
6. Your rights
You can access, correct, export, or delete your personal data at any time from Settings, or by emailing us. You can also disconnect any third-party integration. EU/UK users have additional rights under GDPR; we honour those on request.
7. Security
We use industry-standard practices — encrypted database connections, hashed passwords, row-level access controls, and least-privilege secrets management. No system is perfectly secure; if a breach affects you, we will notify you promptly as required by law.
8. Children
Lnsly is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
9. Changes
We may update this policy. Material changes will be announced by email or in-app at least 14 days before they take effect.
10. Contact
Questions or requests: email support@lnsly.com. We aim to respond within 7 days.