Privacy Policy

Smritivan — a product of Navigo Software Solutions

Effective Date: 27 July 2026 · Last Updated: 27 July 2026

This Privacy Policy explains how Navigo Software Solutions ("Company", "we", "us", or "our") collects, uses, stores, shares, and protects information in connection with Smritivan (the "Service"), a wedding and event photo hosting and studio management platform available at smritivan.in. This Policy does not apply to third-party websites or services (e.g., WhatsApp, payment processors) that may be linked from within the Service.

1. Introduction & Scope

Smritivan involves three distinct groups, and this Policy addresses data collected from and about each:

  • Studios — photography businesses that register as paying customers, upload wedding or event photos, and manage their own portfolio/business presence on the platform.
  • Couples — the bride and groom (or, for a non-wedding album, the client), who receive a private album for their wedding or event and are the primary account holders for that album.
  • Guests — friends and family who view a wedding or event album via a time-limited share link, without creating any account.

A Studio uploads wedding or event photos to a Couple's album as part of the photography service it was hired to provide. By uploading photos, the Studio represents to us that it has the necessary rights and consent — including from the Couple and, where required by law, other individuals photographed at the event — to have those photos hosted and shared through the Service. The Company acts as the Studio's and Couple's service provider for hosting and delivering this content; the Company is not a party to the photography contract between the Studio and the Couple.

By using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Service.

2. What Information We Collect

2.1 Studio Account & Business Data

  • Email address and password (via Firebase Authentication)
  • Studio/business name, WhatsApp/contact phone number, city, and state (collected at sign-up)
  • Studio logo, tagline, and free-text photography-style tags (collected during portfolio onboarding)
  • Payout details for renewal-commission payouts (see Section 2.7)

2.2 Couple Account Data

  • Groom's phone number and bride's phone number (used together for account sign-in)
  • Wedding year (or event year, for a non-wedding album)
  • Couple names, used to set the album name

2.3 Wedding & Event Photos & Media

All photos a Studio uploads to a Couple's album, including photos depicting the Couple, their family, and wedding or event guests. Photos are compressed to WebP format on upload. Depending on Studio configuration, photos may be organized into event sections (e.g., Mehendi, Sangeet, Ceremony, Reception, etc).

2.4 Face Recognition Data (Biometric)

To power the "face search" feature, the Service extracts a 128-dimension mathematical descriptor ("face vector") for each face detected in an uploaded photo, running in the uploading Studio's browser. Face vectors are stored alongside each photo's metadata and are used only to match faces within that Couple's own album when a Couple or Studio searches by face.

Face vectors are generated for every identifiable face in an uploaded photo — including guests, family members, and children who are not Smritivan account holders and did not sign up for the Service. These individuals do not have a direct account relationship with us; the Studio and Couple are responsible for ensuring any consents required by applicable law for photographing and processing images of event attendees (including minors) have been obtained. Face vectors are mathematical representations, not photographs, and are not used for any purpose beyond within-album search.

2.5 Sharing & Guest Access Data

  • Share-link tokens (signed JWTs) and the expiry duration a Couple selects (1 hour to 1 week)
  • Guest-side usage data: link open counts, lead-tap counts, and download counts, associated with the share link rather than with a named Guest
  • We do not log Guest IP address or device/browser information — Guest activity is tracked only in aggregate, tied to the share link itself, never to an individual device or identity.

2.6 Analytics & Engagement Data

  • Per-album statistics visible to Studios: whether/when an album was opened, photos viewed, most-viewed photos, and which photos a Couple favourited
  • Guest-to-studio lead banner tap counts, and any lead-inquiry details a Guest chooses to send via WhatsApp
  • When a Guest taps the lead banner button, we record that the tap occurred before redirecting to WhatsApp — we do not see or store anything the Guest subsequently sends within WhatsApp
  • We do not use any third-party web analytics tool (e.g., Google Analytics) on the Service — all analytics above are first-party.

2.7 Payment & Wallet Data

  • Studio payment for new album creation and plan upgrades: processed via Razorpay Checkout (UPI, cards, netbanking, wallets), or recorded manually for exempted accounts
  • Couple renewal payments are handled manually — our team contacts the Couple directly to explain the renewal and collect payment; there is no automated checkout for renewals at this time
  • Studio wallet balance and transaction history (credits from Couple renewals, debits for new album uploads)
  • Studio payout details (UPI ID, or bank account holder name/account number/IFSC/bank name) — stored in a restricted record used only to send the Studio its earnings

2.8 Communications

Studio-to-Couple review-request messages are sent via WhatsApp deep links (wa.me) with a pre-filled message that the Studio reviews and sends manually from their own WhatsApp account. We do not transmit these messages ourselves and do not receive Couples' or Guests' replies sent within WhatsApp.

3. How We Collect Information

  • Directly from Studios — at sign-up, business/portfolio onboarding, and album/photo uploads
  • Directly from Couples — at album sign-in, when favouriting photos, generating share links, and submitting reviews
  • Automatically, client-side — face vectors are extracted in the browser at upload time, then saved to our database along with photo metadata
  • Automatically via Guest link usage — view/download/lead tap counts tied to a share link's activity, without requiring a Guest account
  • From Razorpay — transaction outcome data (paid/unpaid, amount, payment method, date) when a Studio completes a payment

4. How We Use Your Information

We use collected information only for the following specific purposes:

  • To create and manage Studio and Couple accounts, and to deliver private wedding or event albums
  • To power face search within a Couple's own album
  • To generate, validate, and expire Guest share links per the settings a Couple chooses
  • To display Studio-branded delivery pages, and — where a Studio opts in — to feature selected photos on that Studio's public portfolio page
  • To operate the public Studio directory so couples can discover photographers
  • To show Studios analytics about their own albums
  • To process Studio and Couple payments, and to manage Studio wallet balances and payouts
  • To contact Couples directly regarding the post-1-year renewal option
  • To respond to support requests and communicate service-related updates
  • To detect, prevent, and address technical issues, fraud, or abuse

We do not use personal data for purposes beyond those stated above without seeking further consent.

5. Legal Basis for Processing

Where applicable (e.g., under India's DPDP Act 2023, or GDPR if you have EU users), we process personal data on the following bases:

  • Consent — for Studio portfolio/directory opt-ins, and for any marketing-style outreach beyond direct service communications
  • Contractual necessity — to deliver the paid wedding or event album service a Studio or Couple has signed up for
  • Legitimate interest — e.g., guest-link security, fraud prevention, and product analytics
  • Legal obligation — where required by applicable law

6. Data Sharing & Third Parties

We do not sell personal data. We share information only with the following categories of third parties, strictly as needed to operate the Service:

  • Google Firebase / Google Cloud — authentication and database (Firestore, hosted in India). Application compute runs on Google Cloud Run.
  • Cloudflare R2 — stores all uploaded wedding or event photos and studio assets, in a private bucket, delivered through a token-gated Cloudflare Worker.
  • Razorpay — processes Studio payments for new album creation and plan upgrades. We receive only the transaction outcome.
  • WhatsApp — messages are only sent if and when a Studio or Guest taps to send a pre-filled message from their own WhatsApp account.

Each third party is bound by its own privacy/data-processing terms consistent with this Policy. We may also disclose information if required by law, court order, or governmental request.

7. Data Storage & Security

  • Wedding and event photos are stored on Cloudflare R2 in a private bucket; photo URLs are served through a token-gated Cloudflare Worker rather than raw storage links.
  • Storage moves through a lifecycle: active storage for the first 2 years, lower-cost storage afterward, and a frozen/archive tier if a renewal goes unpaid — photos remain stored and are not deleted, only access mode changes.
  • Studio payout details are stored in a dedicated, restricted record, readable and writable only by the owning Studio or an authorized admin.
  • Transport is encrypted via HTTPS/TLS everywhere. Data at rest is encrypted by default by our infrastructure providers.
  • Firestore security rules restrict cross-account access — a Studio can only read/write its own albums, profile, and payout record; a Couple can only access their own album.

8. User Rights

Subject to applicable law (including India's DPDP Act 2023), you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data ("right to erasure")
  • Withdraw consent at any time, where processing is based on consent
  • Opt out of non-essential communications

Our default hosting model keeps wedding and event albums stored indefinitely, and unpaid albums are frozen (read-only) rather than deleted. This does not override your legal right to request deletion of your personal data — if a Couple, Guest, or individual depicted in a photo submits a valid deletion request, we will honor it in accordance with applicable law.

To exercise any of these rights, contact us at grievance@navigosoftwares.com We will respond within 15 days after contact.

9. Cookies & Tracking Technologies

We use browser storage technologies for:

  • Authentication/session management — Firebase Auth tokens for Studio and Couple sign-in
  • Caching face-detection model files in the browser for performance

We do not currently use any analytics or advertising cookies/scripts on the Service, and we do not use third-party advertising cookies or cross-site tracking.

10. Children's Privacy

Smritivan accounts (Studio and Couple) are intended for adults. We do not knowingly create accounts for children. However, wedding and event photos frequently depict children and other minors who are not account holders (see Section 2.4). The Studio and Couple are responsible for ensuring any necessary parental/guardian consent for photographing and processing images of minors at the event has been obtained. If a parent or guardian wishes to have a minor's photos or face data removed, contact us at grievance@navigosoftwares.com.

11. International Data Transfers

Our database (account, album, and business data) is hosted in India. Wedding and event photos and studio- uploaded assets are stored on Cloudflare R2. Because our primary user base is in India, we are evaluating data-residency options for this component of our infrastructure.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified via an in-app notice and/or a website banner, at least 5 days before taking effect. The "Last Updated" date above will always reflect the most recent revision.

13. Contact Information

For privacy-related questions, requests, or grievances, contact:

  • Levin Xavier, Grievance Officer
  • Navigo Software Solutions
  • 114/3 89/4 Door 7/528 Manayath (H), Nayarambalam, Near Lobelia HSS, Pin: 682 509.
  • grievance@navigosoftwares.com
  • +91 80755 17050