Privacy Policy
Last updated: March 30, 2026
1. Introduction
Phodo ("we", "us", "our") operates the website at phodo.ca and related services (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your choices.
2. Information We Collect
2.1 Account Information
When you register, we collect your email address and the password you create. You may also provide a username, display name, bio, and avatar image.
2.2 Waitlist
If registration is full, you may join a waitlist by providing your email address, country (United States or Canada), and optionally opting in to email about product updates when more accounts become available. We store this information to notify you about access to the Service; it is not used to create an account until you complete registration yourself.
2.3 Photos & Collections
When you upload photos, we store the image files along with associated metadata such as filename, file size, dimensions, content type, and any captions or capture dates you provide. We also store collection information (names, descriptions, visibility settings).
2.4 Billing Information
If you subscribe to a paid plan, payment processing is handled by Stripe. We store your Stripe customer ID, subscription status, and plan details. We do not store your full credit card number — that is held securely by Stripe.
2.5 Tip Configuration
If you enable tips on your portfolio, you may provide an e-transfer email address and/or an external tip URL. This information is displayed publicly on your portfolio at your discretion.
2.6 Usage Data
We track your storage usage (bytes used and limit) to enforce plan limits. We do not use third-party analytics services. We do not track your browsing behaviour across other websites.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service.
- Authenticate your identity and secure your account.
- Process subscription payments and manage billing.
- Display your public portfolio and photos to visitors.
- Enforce storage limits and acceptable use policies.
- Communicate with you about your account (e.g. password resets, billing receipts).
- Manage the waitlist and, if you opt in, send email when we can offer you access or relevant product updates.
Where required by law, our legal bases for processing include performance of our contract with you, compliance with legal obligations, our legitimate interests in operating and securing the Service, and your consent where applicable.
4. How We Store Your Data
Your account data is stored in a Supabase-hosted
database. Your uploaded photos are stored on Cloudflare R2
object storage and served via cdn.phodo.ca.
We take reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS), httpOnly session cookies, and access controls. However, no method of transmission or storage is 100% secure.
5. Cookies
We use cookies for authentication and for a single optional preference: your reported IANA timezone (so we can format dates and times on our servers in line with your device). That preference is a first-party cookie, not used for advertising or cross-site tracking. For full details, see our Cookie Policy.
6. Data Sharing
We do not sell your personal information. We share data only in these cases:
- Service providers: Stripe (payments), Supabase (database), and Cloudflare (hosting and storage) process data on our behalf.
- Legal requirements: We may disclose information if required by law, regulation, or legal process.
- Your public content: Photos and collections you mark as public are visible to anyone with the link.
We do not sell or share personal information for cross-context behavioral advertising.
7. Data Retention
We retain your data for as long as your account is active. When you delete photos or collections, they are moved to a recycle bin and permanently deleted after a retention period. If you delete your account, we will remove or de-identify your personal data and uploaded content within a reasonable timeframe, except where retention is required by law or reasonably necessary for legitimate business purposes such as fraud prevention, security, tax/accounting obligations, backup integrity, or dispute resolution.
Waitlist entries are kept until they are no longer needed for that purpose (for example, after you register, or after a reasonable period if you do not join). You may contact us to request removal from the waitlist before then.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your account and data.
- Export your photos and data.
- Withdraw consent where processing is based on consent.
- Opt out of targeted advertising, sale, or sharing of personal information (where applicable).
- Not be discriminated against for exercising your privacy rights.
To exercise these rights, contact us at support@phodo.ca.
We may need to verify your identity before fulfilling certain requests. You may designate an authorized agent to submit requests on your behalf where permitted by law.
9. Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from users who are not old enough to consent to data processing under applicable law in their jurisdiction. If you believe a child has provided personal information without proper parental or guardian consent, contact us and we will review and delete the data where required.
10. International Transfers
Our service providers may process data in Canada, the United States, and other jurisdictions where they operate. When data is transferred across borders, we take reasonable steps to ensure appropriate safeguards are in place as required by applicable law.
11. Region-Specific Disclosures (Canada and U.S.)
Residents of certain U.S. states and Canadian provinces may have additional privacy rights under applicable law. If there is a conflict between this Policy and mandatory local law, the local law will control to the extent of the conflict.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on the Service. The "Last updated" date at the top indicates the most recent revision.
13. Contact
If you have questions or concerns about this Privacy Policy, contact us at support@phodo.ca.