Last updated: 16 March 2026
York Headshots respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how I collect, use, store, and protect your personal data when you visit this website, make an enquiry, book a session, or interact with an online gallery.
1. Who I am
York Headshots is a specialist headshot service from Sam Chipman Photography.
Website: https://yorkheadshots.co.uk/
Email: info@yorkheadshots.co.uk
For the purposes of UK data protection law, Sam Chipman Photography is the data controller responsible for personal data collected through York Headshots.
2. What personal data I collect
I may collect, store, and use the following personal data:
- name
- email address
- phone number
- postal address
- business name
- social media handles
- session details
- information you submit through enquiry forms
- information you provide by email, phone, questionnaire, consultation, or social media
- payment and invoicing information where relevant
- website usage data, such as IP address, browser type, device information, and pages visited
- marketing preferences
- gallery activity, favourites, selections, and purchase information where you use an online gallery
- photographs created during your session
I do not intentionally collect personal data from children without the involvement of a parent or legal guardian where required.
3. How I collect your data
I collect personal data when:
- you fill out a form on my website
- you get in touch by email, phone, or social media
- you enquire about or book a session
- you sign a contract or complete a questionnaire
- you make a payment
- you use an online gallery
- you place an order for prints or products
- you browse my website
- you leave a comment on the website
Some data is collected directly from you. Some is collected automatically through cookies and website technologies.
4. How I use your personal data
I use your personal data to:
- respond to enquiries
- provide headshot photography and related services
- send quotes, contracts, invoices, guides, and client communications
- manage bookings and consultations
- deliver galleries and digital files
- process print and product orders
- improve my website, services, and client experience
- keep business records
- comply with legal, tax, and accounting obligations
- send marketing communications where you have consented or where I am otherwise permitted to do so by law
5. Lawful bases for processing
Under UK GDPR, I rely on one or more of the following lawful bases:
- contract
Where I need your data to provide services you have requested or booked. - legitimate interests
Where I use your data in ways you would reasonably expect in order to run and improve my business. - legal obligation
Where I must process or retain data for tax, accounting, or legal reasons. - consent
Where consent is required, such as for certain marketing communications, image use permissions, or optional cookies.
6. Website forms, comments, and enquiries
If you submit an enquiry through my website, I will use the information you provide to respond to you and discuss the services you are interested in.
If you leave a comment on the website, I may collect the data shown in the comments form, along with your IP address and browser user agent string to help with spam detection.
I may retain enquiry information for administrative, record-keeping, and follow-up purposes, even if you do not go on to book.
7. Client data
If you book a session, I will collect and use the personal data needed to manage and deliver your booking.
This may include names, contact details, addresses, timings, business details, brand information, questionnaire responses, invoicing details, and other information you choose to provide.
I use this information to communicate with you, plan your session, fulfil my contractual obligations, and deliver your final images.
8. Photography and image use
Photographs in which you can be identified are treated as personal data.
I may use images from your session on my website, social media, printed materials, portfolio, or other marketing only where you have given permission for that use.
If you do not want your images used publicly, that is absolutely fine. Your session can still go ahead and your images can still be delivered privately.
If you previously gave permission and later wish to withdraw it, contact me and I will stop using your images in future marketing where reasonably possible.
Where services are provided for anyone under 18, personal data and image use permissions must be provided by or with the consent of a parent or legal guardian.
9. Online galleries and Pic-Time
I use Pic-Time as a third-party service provider to host online galleries, deliver digital images, allow favourites and selections, and where applicable, offer print and product ordering.
When you interact with a gallery hosted through Pic-Time, personal data may be processed by Pic-Time on my behalf. This may include:
- your name
- your email address
- your IP address
- browsing activity within the gallery
- favourites and selections
- purchase activity
- information needed to provide gallery access and related services
Pic-Time may also use cookies and similar technologies to operate its platform and improve user experience.
For more information, please refer to Pic-Time’s own policies:
Pic-Time Terms of Service: https://www.pic-time.com/#TermsOfService
Pic-Time Privacy Policy: https://www.pic-time.com/#PrivacyPolicy
10. Print orders and fulfilment
If you order prints or other products through an online gallery or through me directly, I may need to share relevant information with trusted print labs, fulfilment partners, or suppliers in order to process and deliver your order.
This will usually include only the information necessary to complete the order.
11. Marketing
If you opt in to receive marketing emails, updates, or offers from me, I may use your contact details to send you those communications.
You can unsubscribe at any time by clicking the unsubscribe link in the email or by contacting me directly.
I do not sell your personal data.
12. Sharing your data
I may share your personal data with trusted third-party providers where necessary to operate my business and deliver my services.
These may include:
- website hosting providers
- email providers
- CRM and workflow systems
- online gallery platforms such as Pic-Time
- payment processors
- print labs and fulfilment partners
- cloud storage providers
- accountants, legal advisers, or insurers where necessary
- analytics and website performance tools
- spam detection or website security tools
I only share data where it is genuinely needed and take reasonable steps to work with providers who handle personal data appropriately.
13. International transfers
Some third-party providers I use may store or process data outside the UK.
Where this happens, I take reasonable steps to ensure that appropriate safeguards are in place so that your personal data remains protected in line with applicable data protection law.
14. How long I keep your data
I keep personal data only for as long as necessary for the purposes set out in this policy, including legal, tax, accounting, and record-keeping requirements.
As a guide:
- enquiry data may be retained for administrative and follow-up purposes
- client records may be retained for up to six years for legal, contractual, and tax reasons
- invoices and financial records may be kept as required by law
- delivered image files and gallery information may be retained for archive, backup, and service purposes
Clients are encouraged to download and back up their images promptly after delivery.
15. Cookies and website tracking
This website may use cookies and similar technologies to help the site function properly, understand how visitors use the site, and improve performance.
Some cookies are essential for the running of the website. Others, such as analytics cookies, may only be used where appropriate consent has been given.
You can usually control cookies through your browser settings and any cookie banner shown on the website.
16. Embedded content and third-party services
Pages on this website may include embedded content or features from third-party platforms such as social media, video hosting services, maps, or other plugins.
These third-party services may collect data about you, use cookies, and monitor your interaction with that content, especially if you are logged into their platform.
I am not responsible for the privacy practices of third-party websites or services. You should review their own privacy policies where relevant.
17. Data security
I take reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, alteration, or disclosure.
However, no website or online system can ever be guaranteed completely secure.
18. Your rights
Under UK data protection law, you may have the right to:
- request access to your personal data
- request correction of inaccurate or incomplete data
- request erasure of your data in certain circumstances
- request restriction of processing
- object to certain processing
- request transfer of your data where applicable
- withdraw consent where processing is based on consent
If you would like to exercise any of these rights, please contact me at info@yorkheadshots.co.uk.
19. Complaints
If you have concerns about how your personal data is handled, please contact me first and I will do my best to resolve the issue.
You also have the right to complain to the Information Commissioner’s Office in the UK.
20. Changes to this Privacy Policy
I may update this Privacy Policy from time to time.
Any changes will be posted on this page with the revised date shown at the top.
21. Contact
If you have any questions about this Privacy Policy or how I handle your data, please contact:
York Headshots
info@yorkheadshots.co.uk
