Privacy Policy

Last Updated: July 27, 2026


1. Introduction

Welcome to TeamShotsPro (“we,” “our,” or “us”). We operate teamshotspro.com and portreya.com (collectively, the “Services”).

We are committed to protecting your data. This policy outlines how we handle your personal and biometric information. We operate under strict data protection principles aligned with the Swiss Federal Act on Data Protection (FADP) and the GDPR.


2. Information We Collect

A. Account & Team Data

Identity: Name, email address, and language preference. If you choose to set a password, it is stored in hashed form. Most accounts use passwordless authentication (one-time codes or magic links) and do not store a password.

Team Data: For teamshotspro.com users, we store team names, roles, and member email addresses managed by Team Admins.

B. Biometric & Image Data

Important: By uploading photos to our Service, you provide explicit consent for us to process your biometric data (facial features) as required under GDPR Article 9 for special category data. This processing is necessary to provide the AI headshot generation service you have requested.

Input Data: We collect the photos (“Selfies”) you upload for the purpose of generating professional headshots.

Process Data: Our AI analyzes facial features in your uploads to map them onto professional styles. We do not use your photos to train any AI models. Your images are processed solely to generate your specific outputs and are not used for model improvement or training.

Output Data: We store the resulting AI-generated images. All generated images are AI-created and are not real photographs.

Content Moderation: Uploaded photos are automatically scanned using AI to detect and reject inappropriate content. This includes, but is not limited to: nudity, sexually explicit material, violent imagery, hate symbols, and content depicting minors. This moderation happens before processing and no inappropriate images are stored.

C. Outfit Capture Browser Extension

Explicit capture: Image capture happens only when you right-click an image and choose the Portreya or TeamShotsPro outfit-capture command. The extension retrieves those image bytes and sends them over HTTPS to our Service so you can continue Outfit Transfer in the web app.

Source URL: The source image URL is kept only in trusted browser session storage for retry for up to ten minutes. It is not sent to our backend, logged, or used for analytics, and is removed after a successful handoff, expiry, browser restart, extension update, or disable.

Local extension data: A limited upload credential, its expiry, and a random installation identifier remain in trusted local extension storage. Web pages and content scripts cannot read this credential. We use this data only to connect the extension and upload an explicitly selected outfit image, consistent with Chrome Web Store Limited Use requirements.

Outfit retention and deletion: A captured outfit is stored by our hosting and storage provider as a person-owned account Asset for as long as the account exists. It is sent to Google Cloud for AI processing only after you start a generation in the web app. You can request deletion through account erasure or by contacting support under Sections 5, 7, and 9.

D. Financial Data

We use Stripe for payment processing. We do not store your credit card details. We only retain a transaction ID and customer reference number to manage your purchases.


3. Infrastructure & Data Transfer

To provide high-performance AI services, your data flows through specific top-tier providers across different jurisdictions. By using the Service, you consent to these transfers:

Data TypeProviderLocationPurpose
Hosting & StorageHetzner Online GmbHGermany (EU)Secure storage of photos and database.
AI ProcessingGoogle Cloud (Vertex AI)USAImage generation.
PaymentsStripeUSA/GlobalPayment processing.
EmailsResendUSATransactional and marketing emails.
Product AnalyticsPostHogEU/USAUsage analytics.
Web AnalyticsGoogle Analytics (GA4)USAWebsite traffic and conversion measurement.
Error MonitoringSentryUSAApplication error tracking and performance monitoring.

For transfers to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, as implemented by our service providers:


4. Cookies & Tracking

We use the following cookies and tracking technologies:

Essential Cookies: Session and authentication cookies required for the Service to function (Auth.js).

Product Analytics: We use PostHog to understand how users interact with our Service and improve the user experience.

Web Analytics: We use Google Analytics (GA4) to measure website traffic and conversion performance.

Error Monitoring: Sentry sets cookies to track application errors and performance, helping us maintain service reliability.

Payment: Stripe sets cookies necessary for secure payment processing.


5. Data Retention Policy

All uploaded selfies and generated photos are retained as long as your account exists. You may request account deletion at any time by contacting us using the details in Section 9. Upon receiving your request, all your data will be permanently deleted within 30 days.


6. Marketing Communications

When you create an account, complete checkout, or sign in for the first time, we may enroll you in tenant-specific marketing email preferences for the brand you are using. Marketing emails may include practical tips, examples, product updates, and occasional offers related to our services.

Opt-Out: You can object to and unsubscribe from direct marketing at any time by clicking the unsubscribe link included in every marketing email, changing your email preferences in your account profile, or contacting us using the details in Section 9. Once you object or unsubscribe, we will stop processing your personal data for direct marketing for that brand.

Service Emails: Transactional and service-related emails (such as one-time login codes, purchase receipts, team invite notifications, onboarding reminders for an active invite, and account security messages) are separate from marketing emails and may continue as needed to provide the Service.

Legal Basis: We rely on legitimate interests for service communications and, where permitted, for marketing about our related products and services. Where local law requires consent for marketing, we will use consent as the legal basis.


7. Your Rights

Under GDPR and FADP, you have the following rights regarding your personal data:

  • Access & Export: Request a copy of your photos and personal data we hold about you.
  • Rectification: Update or correct inaccurate account information.
  • Erasure (“Right to be Forgotten”): Request deletion of your account and all associated data.
  • Restriction: Request that we limit how we process your data in certain circumstances.
  • Data Portability: Receive your data in a structured, commonly used, machine-readable format.
  • Objection: Object to processing of your personal data in certain circumstances.
  • Direct Marketing Objection: Object to direct marketing at any time. This right is unconditional, and we will stop processing your personal data for direct marketing after you object.
  • Withdraw Consent: Withdraw your consent for biometric data processing at any time by deleting your account.

How to Exercise Your Rights: Contact us using the details in Section 9. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.


8. Security

We employ enterprise-grade security measures including:

  • Encryption in Transit: All data transmitted to and from our servers is protected using SSL/TLS encryption.
  • Encryption at Rest: Stored data is encrypted using industry-standard AES-256 encryption.
  • Access Controls: Strict role-based access controls limit who can access your data.
  • Secure Infrastructure: Our hosting provider (Hetzner) maintains ISO 27001 certification.

While we strive for maximum security, no internet transmission is completely invulnerable. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by law.


9. Contact

For privacy concerns, please contact us at: