Shelby Vilate Studios

Shelby Vilate Studios

Privacy Policy

Last updated: 1 April 2025

1. About this Policy

Shelby Vilate Studios (ABN 86 570 632 160) ("we", "us", "our") is committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we collect, hold, use and disclose your personal information when you use our website or book a photography session with us.

We also endeavour to meet the spirit of the EU General Data Protection Regulation (GDPR) where clients may be located in or have connections to the European Economic Area.

2. Information We Collect

We collect the following personal information:

  • Contact details — full name, email address, phone number, and suburb.
  • Baby's date of birth — to schedule your session within the optimal newborn window (5–14 days after birth).
  • Booking and payment information — session date, package selection, deposit and payment records. Payment card details are processed directly by Stripe and are never stored by us.
  • Contract information — electronic signature records via Adobe Sign.
  • Marketing preferences — whether you have consented to receiving future communications from us, and when that consent was given.
  • Referral source — how you heard about us (Google, Instagram, word of mouth, etc.), collected to understand how clients find us.
  • Correspondence — messages sent via our contact form or directly by email.

We collect information directly from you when you submit an enquiry, make a booking, or communicate with us. We do not collect sensitive information (as defined by the Privacy Act) unless specifically required and with your consent.

3. Purpose of Collection

We use your personal information to:

  • Process and manage your booking and session scheduling.
  • Communicate with you about your upcoming session, including preparation tips, reminders, and payment requests.
  • Process payments and issue receipts via Stripe.
  • Generate and manage your session contract via Adobe Sign.
  • Schedule your session in our calendar via Google Calendar.
  • Respond to enquiries and provide customer support.
  • Send marketing communications — only where you have given explicit consent.
  • Maintain business records as required by law.

4. Storage and Security

Your personal information is stored securely in Supabase, a cloud database platform that uses industry-standard encryption at rest and in transit. Access to your data is restricted to authorised personnel only.

We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification, or disclosure. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

We retain your personal information for as long as necessary to fulfil the purposes described in this policy, or as required by law. If you request deletion of your data, we will remove it within 30 days unless retention is required for legal or tax compliance purposes.

5. Third-Party Service Providers

We share your information with the following third-party providers solely to deliver our services. Each provider is bound by their own privacy policies and data protection obligations.

  • Stripe — payment processing. Stripe handles all payment card data in accordance with PCI-DSS Level 1 standards. We do not store your card details. See Stripe's Privacy Policy.
  • Adobe Sign — electronic signature for your session contract. Your name and email address are shared with Adobe Sign to facilitate contract generation and signing. See Adobe's Privacy Policy.
  • Google Calendar — session scheduling. Your name and session details are used to create a calendar event. See Google's Privacy Policy.
  • Resend — transactional email delivery. Your email address is used to send booking confirmations, reminders, and receipts. See Resend's Privacy Policy.
  • Supabase— database hosting. Your data is stored in Supabase's secure, encrypted cloud infrastructure. See Supabase's Privacy Policy.

We do not sell, rent, or trade your personal information to any third party for marketing purposes.

6. Marketing Communications

We will only send you marketing or promotional communications if you have explicitly opted in. You may withdraw your consent at any time by:

Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal. Transactional emails (booking confirmations, receipts, reminders) are not marketing communications and will be sent regardless of marketing consent.

7. Your Rights

You have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request that we correct inaccurate or incomplete information.
  • Deletion — request that we delete your personal information, subject to any legal obligations requiring retention.
  • Portability — request a copy of your data in a structured, machine-readable format.
  • Objection — object to the use of your data for direct marketing at any time.

To exercise any of these rights, please contact us at bookings@shelbyvilatestudios.com.au. We will respond within 30 days.

8. Cookies and Analytics

Our website may use cookies and similar tracking technologies to improve your browsing experience. We do not use cookies for advertising or cross-site tracking. You can control cookie settings through your browser preferences.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Your continued use of our services after changes are made constitutes acceptance of the updated policy.

10. Contact Us

If you have any questions, concerns, or complaints about how we handle your personal information, please contact us:

Shelby Vilate Studios
52 Rialto St, Coorparoo QLD 4151
bookings@shelbyvilatestudios.com.au
+61 400 755 000

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.