SetBook

Privacy Policy

Last updated: 30 July 2026

1. Who this applies to

This Privacy Policy covers SetBook (“SetBook,” “we,” “us”), the creative-operations platform for photographers, videographers, and production teams. It applies to registered SetBook accounts (“members”), and to the clients, collaborators, and other individuals whose information members store inside SetBook (e.g. Network contacts, contract signers, invoice recipients).

2. Information we collect

Account information. When you sign up, our authentication provider (Clerk) collects your name, email address, and profile image. We store a matching record so the rest of SetBook can reference you.

Business Profile information. Your business name, location, professions, bio, logo, and banking details (used only to display on invoices you generate, see Section 6).

Data about your clients and collaborators. When you use SetBook to manage your own business, you provide us with information about third parties, Network contacts, contract and release signers, invoice recipients, including names, emails, and sometimes addresses or signatures. You are responsible for having a lawful basis to share that information with us; see Section 9.

Content you upload. Portfolio images and videos, project files, business logos, signed documents, and invoice PDFs you upload or that SetBook generates on your behalf.

Usage information. Basic technical information (device/ browser type, IP address, pages visited) and preference cookies (e.g. your light/dark theme choice, sidebar collapsed state) needed to make the app work correctly across sessions.

3. How we use information

To operate SetBook’s core features: Projects, Network, Contracts and Releases, Deliverables, Invoicing, Files, and Notifications; to authenticate you and keep your account secure; to send transactional emails (e.g. a contract awaiting signature, an invoice, a reminder); to respond to support requests; and to improve the product based on aggregate, non-identifying usage patterns. We do not sell your information or your clients’ information to third parties, and we do not use your content to train third-party AI models.

5. Where your data lives

Account authentication is handled by Clerk. Application data (business profiles, projects, contracts, invoices, uploaded files) is stored in Supabase (PostgreSQL + object storage). Both are reputable, security-focused infrastructure providers; we don’t operate our own servers for this data. Access to your business’s data is enforced at the database level (row-level security) so that other SetBook members cannot read it.

Two other processors handle specific things on our behalf: Stripe processes payment card details and billing for your own SetBook subscription (see Section 6), and Resend delivers transactional emails (contracts and releases awaiting signature, invoices, and account/billing notices) on our behalf. Neither uses your data for anything beyond providing that service to SetBook. If we ever engage an additional sub-processor that handles your personal data, we’ll update this list.

If a data breach occurs that’s likely to result in a risk to your rights, we’ll notify affected users and, where legally required, the relevant regulator (e.g. within 72 hours under the GDPR, or as soon as practicable under the Privacy Act’s Notifiable Data Breaches scheme in Australia) without undue delay.

6. Banking details and payments

Your clients’ payments to you.SetBook is not a payment processor for the invoices you send your own clients. Banking details you add in Settings are stored only so they can be printed on invoices you send. SetBook never moves that money, never sees a client’s card or bank details, and has no role in settling that payment. Marking an invoice “paid” inside SetBook is a manual record-keeping action you take yourself.

Your payment for SetBook. This is separate: if you subscribe to SetBook, your card details and billing history for that subscription are collected and processed by our payment processor, Stripe, directly, not by SetBook. We store limited billing metadata (your Stripe customer/subscription id, plan, status, and renewal date) so the product can reflect your subscription, but never your full card number.

7. How long we keep information

We retain your account and business data for as long as your account is active. If you delete your account, we delete or anonymize your data within a reasonable period, except where we’re required to keep records for legal, tax, or fraud-prevention reasons, or where data has already been shared with a third party (e.g. a signed contract’s counterparty) as an inherent part of using the product.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. You can exercise most of these directly from Settings, or submit a Data Subject Access Request (DSAR) to privacy@setbook.app and we’ll respond within a reasonable timeframe (and within any shorter period required by law in your jurisdiction, e.g. 30 days under the EU/UK GDPR).

Australia.We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). If you’re unhappy with how we’ve handled a privacy complaint, you can raise it with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

EU/UK (GDPR). Where the GDPR or UK GDPR applies to you, our legal bases for processing are: performance of a contract (running your account and the features you use), our legitimate interests (keeping SetBook secure and improving it), consent (e.g. optional cookies, where used), and compliance with legal obligations (e.g. tax and billing records). You also have the right to lodge a complaint with your local data protection supervisory authority.

California (CCPA/CPRA).California residents have the right to know the categories of personal information we’ve collected (see Section 2), to delete it, to correct it, and to opt out of the “sale” or “sharing” of it. We don’t sell or share your personal information for cross-context behavioral advertising, and we won’t discriminate against you for exercising any of these rights.

9. If you upload someone else’s information

SetBook is a tool for managing your own business relationships. If you add a client, talent, or collaborator’s information to Network, a contract, or an invoice, you’re confirming you have a lawful basis to do so (e.g. an existing business relationship or their consent) and that you’ll handle their data in line with applicable privacy law. SetBook processes that data on your instructions, as your data processor for that content.

10. International data transfers

Our infrastructure providers (Clerk, Supabase, Stripe, Resend) may store or process data outside your own country, including in the United States. Where we transfer personal information covered by the GDPR/UK GDPR or Australia’s APP 8 (cross-border disclosure) outside its home jurisdiction, we rely on those providers’ own standard contractual clauses and security certifications to keep it protected to a comparable standard.

11. Cookies

We use a small number of first-party cookies strictly to make the app function correctly, keeping you signed in, remembering your light/dark theme, and remembering whether the sidebar is collapsed. We don’t use third-party advertising or tracking cookies.

12. Children

SetBook is a business tool and is not directed at, or intended for use by, children. We don’t knowingly collect personal information from anyone under 16.

13. Changes to this policy

If we make material changes to this policy, we’ll update the “Last updated” date above and, where appropriate, notify you directly.

14. Contact us

Questions about this policy or how your data is handled: privacy@setbook.app. For anything else, see our Help & Support page.