Media Suite
Privacy policy
What Media Suite collects, why it collects it, who else sees it, and what you can ask us to do about it.
Last updated 20 September 2026.
Who this covers
Media Suite is a platform that media and photography businesses use to run their own websites, bookings, quotes and payments. That gives two kinds of person an interest in this policy, and they are not the same.
If you run a business on Media Suite, we handle your data as described below and you are our customer. If you are somebody's customer who booked a shoot or accepted a quote, the business you dealt with decides what happens to your details; we hold them on their behalf, and a request about them is best sent to that business first.
What we collect
We collect what the product needs to work, and we are specific about it.
- Account details: your name, email address and a hash of your password. We never store the password itself.
- Two-step verification: if you enrol an authenticator app, its seed is encrypted at rest and is never displayed again after enrolment.
- Session records: a hash of each session token, when it was created and last used, and the IP address and browser string it came from.
- Activity log: an append-only record of security-relevant events, such as sign-ins, permission changes and any support access to a workspace.
- Business content: whatever you put into your workspace, including site text, contact channels, availability, bookings, quotes and the customer details attached to them.
- Files: media you upload, stored under a prefix belonging only to your workspace.
What we do not collect
There is no analytics service, no advertising network and no third-party tracking script in this product. We do not sell data, and we do not use your business content or your customers' details to train anything.
We never see or store card numbers. Payments run through Stripe, which collects those details directly.
Cookies and local storage
We set a session cookie when you sign in, and a second cookie carrying a token that protects form submissions against cross-site request forgery. Both are strictly necessary: without them you cannot stay signed in or safely submit anything.
Your light or dark theme preference is kept in your browser's local storage and never leaves your device. There are no other cookies.
How your data is kept separate
Every workspace is a separate tenant, and the separation is enforced by the database itself through row level security rather than by application code remembering to filter. A query that forgets to scope itself returns nothing rather than returning somebody else's rows.
Stored files live under a prefix belonging to one workspace only. Platform operators connect with an unprivileged database role that cannot bypass those rules.
When we look at your workspace
Support staff can open a workspace to investigate a problem. Doing so writes an entry to that workspace's own activity log before anything can be read, and the entry names who opened it and why. You can read those entries yourself from your dashboard.
Who else processes it
We use a small number of providers to run the service, and share with them only what their job requires.
- Stripe, for payments. Your customers' card details go to Stripe, not to us, and funds settle into the connected account belonging to the business.
- An email provider, to deliver verification links, booking confirmations and quotes.
- An object storage provider, to hold uploaded files.
- A hosting provider, to run the application and its database.
How long we keep it
Account and workspace data is kept while the workspace exists. Archiving a workspace is reversible and keeps everything. Deleting one permanently removes its bookings, quotes, customers, staff logins and file records in a single cascade.
The activity log is deliberately exempt from that cascade. It is append-only and cannot be edited or deleted by anyone, including us, because a security log that can be rewritten is not a security log.
Session records expire on their own schedule and are revoked immediately when you sign out or change your password.
What you can ask for
You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete your account and its workspace. Write to the address below and we will confirm what will and will not survive the request, including the activity log entries that by design will.
Changes
If we change this policy in a way that affects what we collect or who we share it with, we will say so rather than quietly updating the date at the top.
Getting in touch
Questions about this document, or a request about your own data, go to [email protected].
See also our privacy policy and terms of use.