Privacy Policy
How Lenso handles personal information across studio accounts, project requests, client review, payments, optional analytics, and AI Brief Assist.
Effective: August 19, 2026
Last updated: August 19, 2026
This Privacy Policy explains how Lenso, doing business as Lenso ("Lenso," "we," "us," or "our"), collects, uses, discloses, and retains personal information when you visit lenso.io, create or use a studio account, submit a request to a studio, open a client link, contact us, or otherwise use Lenso.
Studios use Lenso to keep a client job together from first request to final files. A studio generally decides why and how it uses the client and job information placed in its workspace. Lenso processes that information to provide and protect the service. Lenso is separately responsible for information it uses for account administration, billing, security, support, website operations, optional analytics, and its own business communications.
This policy is not a substitute for a studio's own privacy notice. Contact the studio if you have questions about why it requested information, how it uses job information, or who it invited to a job.
At a glance
The studio controls its client jobs.
Studio owners and authorized team members decide which clients are invited, what job information is collected, and which job files are shared through the client area.
Lenso provides and protects the service.
Lenso uses account, technical, security, support, and job information to authenticate users, operate requests and client links, store files, send service messages, prevent abuse, and keep the service reliable.
Card details are handled by Stripe.
Stripe processes card, bank, and payment details for Lenso subscriptions and optional studio-connected client payments. Lenso receives the transaction and subscription information needed to operate billing, but does not need to store full card numbers.
AI Brief Assist is optional.
When you choose AI Brief Assist, relevant text and form context are sent to Lenso's configured AI provider to draft suggestions. Nothing is applied to a job until a person reviews and chooses it.
Optional analytics stays off until you allow it.
Essential browser storage keeps accounts, client links, and preferences working. Google Analytics and Ahrefs Web Analytics load only after you allow analytics on approved public pages.
You can ask questions or make a privacy request.
Email [email protected]. We may need to verify your identity before giving access to or changing personal information.
Who this policy covers
This policy applies to personal information Lenso handles about:
- visitors to lenso.io;
- studio owners, administrators, and team members;
- people invited to a studio workspace;
- clients who receive a project-specific client link;
- people who submit a project request to a studio;
- people who contact Lenso for support, sales, onboarding, or another question;
- people whose business contact details Lenso uses for relevant business outreach;
- people who interact with Lenso's public content, videos, or booking links.
In this policy, "personal information" includes information that identifies a person, relates to an identifiable person, or is treated as personal data or a similar term under applicable law.
Who is responsible for information
Lenso's own purposes
Lenso is responsible for personal information it uses for its own purposes, including:
- creating and administering Lenso accounts;
- managing subscriptions and billing;
- securing and monitoring the service;
- responding to support, sales, and privacy requests;
- operating lenso.io;
- measuring public-page use when analytics is allowed;
- communicating product or business information where permitted;
- meeting legal and contractual obligations.
Studio-controlled job information
A studio generally decides why it collects and uses the client, request, and job information in its workspace. This can include brief answers, product and SKU details, references, files, comments, revisions, approvals, invoices, and final files.
Lenso processes that information to provide the studio's request form, workspace, client area, file storage, email delivery, review, approval, invoicing, and delivery features. Lenso also uses limited technical and security information from those interactions to prevent abuse, investigate errors, protect accounts, comply with law, and provide support.
If your question is about information a studio asked you to provide or how a studio uses your job information, contact the studio first. Lenso will support the studio's response and will respond directly where applicable law requires it.
Studio responsibilities
Studios are responsible for:
- collecting only information they have a valid reason and authority to use;
- giving their clients any studio-specific notice required by law;
- inviting the correct people;
- setting appropriate team access;
- deciding what is shared in the client area;
- responding to privacy requests about their own client relationships;
- avoiding unnecessary sensitive personal information in briefs, files, messages, and AI prompts.
Information Lenso collects
Information you provide directly
Depending on how you use Lenso, you may provide:
- name, email address, phone number, account credentials, and verification details;
- studio name, website, logo, profile, address, timezone, and workspace settings;
- team-member and invitation details;
- support, sales, onboarding, or privacy messages;
- marketing preferences;
- client name, email, phone number, company, billing details, shipping details, and tax details;
- project requests, brief answers, products, SKUs, shot requirements, shot lists, references, deadlines, and notes;
- job files, proofs, versions, comments, messages, revisions, approvals, final files, and delivery information;
- invoice, subscription, payment, refund, and transaction information;
- text you choose to submit to AI Brief Assist;
- any other information you intentionally place in a Lenso form, workspace, client area, or message.
Information collected automatically
When you use Lenso, we may collect:
- IP address;
- browser and device information;
- user-agent string;
- operating system;
- language and approximate location derived by a provider from an IP address;
- date, time, route, and interaction information;
- login, access, security, and error events;
- file metadata such as filename, file type, size, checksum, and upload time;
- request-form, template, job, workspace, and event identifiers;
- referral hostname (not a full URL) and approved campaign parameters;
- cookie, local-storage, and session-storage values needed for authentication, client access, preferences, and allowed analytics.
Public request forms record IP address and browser information to protect the form, investigate abuse, and maintain an audit trail.
Information from other sources
We may receive information from:
- a studio that invites you or creates a client record;
- Google when you choose Google sign-in;
- Stripe when you create a subscription, connect a Stripe account, receive an invoice, or complete a payment;
- Google Places when you choose address autocomplete;
- a referring website or approved campaign link;
- a referral or business introduction;
- a public business website or professional profile;
- an approved business-contact provider, where using the information for relevant business outreach is permitted.
When Lenso uses business contact information from another source, it should keep the source, collection date, country, role relevance, and opt-out state needed to manage that use responsibly.
Sensitive information
Lenso is designed for commercial studio work, not for medical, financial-account, government-identity, or similarly sensitive records. Do not upload sensitive personal information unless it is genuinely necessary for a job, the studio has authority to use it, and appropriate safeguards are in place.
How Lenso uses personal information
Lenso uses personal information to:
- create, verify, authenticate, and administer accounts;
- create and manage studio workspaces and team access;
- receive, verify, and route project requests;
- let a studio review a request before it becomes a job;
- invite a client to a project-specific client area;
- collect and maintain briefs, products, SKUs, shot lists, references, files, comments, revisions, approvals, invoices, and final files;
- store, process, and deliver job files;
- send account, verification, invitation, review, billing, security, and support messages;
- process Lenso subscriptions and optional studio-connected client payments through Stripe;
- provide AI Brief Assist when a person chooses it;
- prevent spam, fraud, unauthorized access, and misuse;
- troubleshoot errors and maintain service reliability;
- enforce contracts and protect legal rights;
- create workspace exports and process account deletion;
- understand public-page use when analytics is allowed;
- evaluate campaign sources using privacy-minimized attribution;
- improve product usability, reliability, and support;
- answer questions and provide onboarding;
- send product updates or relevant business outreach where permitted;
- maintain opt-out and suppression records;
- comply with law, legal process, and regulatory obligations.
Legal grounds where required
Where applicable law requires a legal ground, Lenso relies on one or more of the following:
- performance of a contract or steps requested before a contract;
- legitimate interests in providing, securing, supporting, measuring, and promoting a business service;
- consent for optional analytics, marketing, or another use where consent is required;
- compliance with legal obligations;
- establishment, exercise, or defense of legal claims.
A legal reviewer must confirm this paragraph before publication.
Automated decisions
Lenso does not use AI Brief Assist or public-page analytics to make decisions that produce legal or similarly significant effects about a person. AI Brief Assist drafts suggestions for human review. It does not approve a request, create a job, change a price, send an invoice, or approve work by itself.
How job information is shared
Inside a studio workspace
Job information is available to authorized studio members according to their workspace role and assigned access.
A studio can invite a client to a project-specific client area. The invited client can see and use the information made available for that job, such as the brief, selected files, comments, revision actions, approval actions, invoices, and final files.
A client link is tied to a particular job and client identity. It is not a universal account containing every job or every studio.
Public requests
A public project request is sent to the studio named on the form. The requester must confirm the email address before the request is ready for normal studio review. The studio decides whether to convert the request into a job and whether to invite the requester.
Submitting a request is not a booking and does not require the studio to accept the work.
Service providers
Lenso shares limited information with service providers that host, secure, monitor, email, analyze, or process parts of the service. The service-provider table below explains the main current providers and when information is sent.
Legal and business disclosures
Lenso may disclose information:
- when required by law, court order, subpoena, or valid legal process;
- to investigate fraud, abuse, security incidents, or violations of terms;
- to protect Lenso, a studio, a client, or another person's rights and safety;
- to professional advisers under confidentiality obligations;
- as part of a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards and notice where required.
Lenso does not exchange personal information for money.
Service providers and integrations
The providers below support the current service. A provider receives information only when the related feature is active or used. Provider configuration can change, so Lenso reviews this list when the service changes.
| Provider | Purpose | Information involved and when |
|---|---|---|
| Amazon Web Services | Application infrastructure, private object storage, and transactional email through Amazon SES | Account, workspace, job, file, message, and email-delivery information needed to host or send the service |
| Stripe | Lenso subscriptions, billing portal, connected-account onboarding, invoices, payments, refunds, and fraud controls | Account, business, customer, transaction, payment, billing, and verification information when a Stripe feature is used |
| Cloudflare Turnstile | Bot and abuse protection on selected forms | Browser and security signals needed to determine whether a form interaction appears human; the Turnstile script should load only on protected forms |
| Google sign-in, optional address autocomplete, and Google Analytics when configured and allowed | Basic Google profile information for sign-in; address search text for Places; public-page device and interaction data for Analytics after consent | |
| Ahrefs Web Analytics | Aggregate public-page measurement when configured and allowed | Page URL without sensitive query values, referrer hostname, device and browser information, approximate location, language, and interaction events after consent |
| OpenAI | AI Brief Assist, if OpenAI is the verified production provider | Text a person chooses to submit, relevant current brief values, and the form field structure needed to draft suggestions |
| Sentry | Error and performance monitoring when enabled | Technical error, route, environment, and diagnostic context after Lenso's scrubbing rules; do not intentionally send job content or credentials |
| Sanity | Delivery of public editorial content | Public-content requests and normal delivery metadata |
| YouTube | Optional product video playback after a person chooses to load or play a video | Browser, device, network, and playback information sent to YouTube when the embed loads |
| External booking provider | Scheduling when the booking link points to an external service | Information a person chooses to provide on the provider's site |
Service providers may process information in Canada, the United States, or other countries where they or their service providers operate. Their own terms and privacy notices also apply to the services they provide directly.
Lenso does not publish a provider certification, region, retention period, or no-training statement until current production configuration and the applicable agreement support it.
OpenAI states that API business data is not used to train its models by default. OpenAI may retain API inputs and outputs for up to 30 days for service delivery and abuse monitoring unless an approved different retention setting applies. Lenso verifies its production account and current terms before relying on this statement.
AI Brief Assist
AI Brief Assist is optional.
When you choose it, Lenso sends the text you enter, the relevant form field structure, and relevant existing brief values to the configured AI provider. The provider returns suggested field values, follow-up questions, and notes.
The suggestions are a draft. Nothing is applied to the form or job until a person reviews and chooses to apply it. A person can edit or reject every suggestion before submitting the request or brief.
Lenso's normal AI audit events are designed to record technical information such as request status, model, latency, token use, text length, and suggestion counts without including the raw pasted text or full provider response. The AI provider may process or retain inputs under its own terms and Lenso's account settings.
Do not paste confidential or sensitive personal information that is not needed for the request.
Lenso does not use customer job content to train a Lenso-owned model without explicit permission.
Learn more about AI Brief Assist and privacy
Cookies and browser storage
Essential storage
Lenso uses essential cookies and similar browser storage to:
- keep account sessions working;
- protect authentication and requests;
- maintain temporary client-link access during a browser session;
- remember billing or signup state;
- preserve interface and privacy preferences;
- prevent duplicate or unsafe actions.
Essential storage is required for the related feature and cannot be disabled through Lenso's analytics control. A browser can still block or clear it, but parts of the service may stop working.
Optional analytics
With your permission, Lenso uses Google Analytics and Ahrefs Web Analytics on approved public pages to understand page use, traffic sources, and broad interaction patterns.
Optional analytics:
- stays off until you allow it;
- is not intended to run on authentication, credential recovery, client access, team invitation, billing, private application, request-form, or embedded-request routes;
- does not receive names, email addresses, phone numbers, job titles, filenames, SKUs, free text, card details, client-link tokens, request tokens, or internal job identifiers;
- receives pathname only, not a raw query string;
- stops collecting future activity when you withdraw permission.
Signup attribution
When you arrive on an approved public page with approved campaign parameters, Lenso may store a short privacy-minimized attribution record in your browser for up to 90 days or until signup, whichever occurs first. The record may include approved campaign values and an external referrer hostname. It does not store email addresses, credentials, tokens, full external URLs, or the full document referrer.
Privacy choices
Use the control in the footer or on this page to allow or decline optional analytics.
Withdrawing permission stops future optional analytics. It does not undo information already processed before the change. Lenso removes its own first-party analytics cookies where practical and tells Google Analytics to stop collection.
Browser controls
You can also clear cookies and browser storage through your browser. Clearing session storage can sign you out of a client area or require a new client link. Clearing account cookies can sign you out of Lenso.
Marketing and business outreach
Account marketing
Lenso sends product news, guides, or offers to account users who choose to receive them, or where another lawful basis permits the message. Marketing consent is separate from accepting the Terms or creating an account.
Every marketing message provides a practical way to unsubscribe.
Relevant business outreach
Lenso may use a business email address, business role, company name, public business website, professional profile, referral, or approved business-contact source to send relevant business outreach where permitted by law.
Lenso's outreach should be limited to people whose role is relevant to product photography studio operations. Lenso records the source, date, country, role relevance, campaign, and opt-out state needed to manage that outreach.
Lenso does not treat a publicly visible Canadian email address as automatically available for automated outreach. The required consent or other documented basis must exist before sending.
Opt-out and suppression
You can opt out through the link in a message or by emailing [email protected].
After an opt-out, Lenso keeps a minimal suppression record so the preference can be honored. The suppression record should contain only what is reasonably needed to prevent another message and document the request.
Service messages
Unsubscribing from marketing does not stop necessary account, security, billing, request-verification, client-invitation, job, or support messages.
Retention and deletion
Lenso keeps personal information only as long as reasonably needed for the purpose described in this policy, a studio's instructions, legal obligations, security, billing, disputes, or enforcement.
The following schedule applies after it has been approved, implemented, and verified in production.
| Information | General retention |
|---|---|
| Active studio account and job information | While the workspace is active and as needed to provide the service |
| User-requested account deletion | A 30-day grace period during which the request can be canceled, followed by deletion or anonymization unless an unresolved obligation or legal requirement blocks it |
| Trial account that does not convert | Scheduled for deletion or anonymization 60 days after the trial ends, subject to notice, export access, blockers, and legal requirements |
| Paid workspace after cancellation | Scheduled for deletion or anonymization 90 days after cancellation, subject to notice, export access, blockers, and legal requirements |
| Generated workspace export | Available for 7 days, then the export file is removed |
| Unverified public request | 30 days after creation |
| Verified request not converted into a job | 12 months after the last activity |
| General contact inquiry | 12 months after the last activity |
| Outbound business prospect record | 24 months after the last meaningful interaction, unless a shorter period is required |
| Marketing opt-out or suppression record | As long as reasonably needed to honor the opt-out and demonstrate compliance |
| Signup attribution | Up to 90 days or until signup, whichever occurs first |
| Local operational and security logs | Generally 30 to 90 days depending on log type and production configuration |
| Billing, tax, fraud, dispute, and legal records | As long as required by applicable law or reasonably needed to resolve the obligation |
| Backups | Until replaced through the normal protected backup cycle, unless a longer period is required for recovery, security, or law |
Converted requests
When a studio converts a request into a job, the request becomes part of the job record and follows the workspace and job retention rules.
Deletion limits
Deletion can be delayed when an account has:
- an active subscription;
- an active job;
- an open invoice;
- an unresolved payment, refund, dispute, or payout;
- a legal hold or other legal obligation.
Lenso explains the blocker and available next step. Deletion does not mean every provider or protected backup erases the information at the same moment. Residual copies are removed or overwritten through normal provider and backup cycles unless they must be retained.
Anonymized information
Lenso may retain information that has been anonymized so it can no longer reasonably identify a person, including aggregate product, reliability, security, and business metrics.
Security
Lenso uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure.
Safeguards include account and role controls, private file storage, time-limited file links, request verification, form-abuse protection, encrypted network connections, audit events, and deletion guardrails. Some controls depend on current production configuration.
No service can guarantee perfect security. Keep account credentials and client links private, invite only the intended people, and contact Lenso promptly if you suspect unauthorized access.
Read How Lenso protects studio and client work for a practical explanation of current safeguards and current product limits.
Privacy choices and rights
Available choices
Depending on where you live and how Lenso handles your information, you may have the right to:
- ask whether Lenso has personal information about you;
- request access to that information;
- ask how it has been used and disclosed;
- correct inaccurate or incomplete information;
- request a portable copy where available;
- request deletion or anonymization;
- withdraw consent for optional analytics or marketing;
- object to or restrict certain uses;
- complain to a privacy regulator;
- appeal a decision where applicable law provides that right.
How to make a request
Email [email protected] with:
- your name;
- the email address connected to the information;
- whether you are a studio user, client, requester, website visitor, or business contact;
- the studio or job involved, if applicable;
- the request you want Lenso to address.
Do not send a password, client-link token, full payment-card number, or unnecessary identity document by email.
Lenso may ask for enough additional information to verify identity and authority. Lenso responds within the time required by applicable law. Some information may be withheld or retained where law permits or requires it.
Studio-controlled information
If the request concerns job information controlled by a studio, contact the studio first when practical. Lenso will help the studio respond and will handle a direct request where required.
Analytics
Use to change optional analytics at any time.
Marketing
Use the unsubscribe link in a marketing message or email [email protected].
Complaint
You may also contact the privacy regulator in your province, state, country, or other jurisdiction. Lenso asks that you contact its Privacy Officer first so it has an opportunity to address the concern.
International processing
Lenso and its service providers may process personal information in Canada, the United States, and other countries where they operate.
Privacy laws in another country may differ from the laws where you live. Courts, law-enforcement agencies, regulators, or security authorities in that country may be able to access information under local law.
Lenso uses contractual, technical, and organizational measures appropriate to the service and provider relationship. Lenso does not promise a customer-selected data-residency region unless that capability is formally offered and documented.
Children
Lenso is a business service for studios and their commercial clients. It is not directed to children.
If you believe a child provided personal information to Lenso without appropriate authority, contact [email protected] so the situation can be reviewed.
Changes to this policy
Lenso may update this policy when the service, providers, legal requirements, or information practices change.
The updated policy will show a new effective and last-updated date. If a change is material, Lenso will provide additional notice where appropriate, such as an account message, email, or prominent website notice.
Lenso does not use a policy update to introduce a materially different optional use without providing the choice or consent required by law.
Contact
Lenso Privacy Officer
Lenso
Email: [email protected]
Contact the studio directly for questions about why the studio collected client or job information.
Related policies
- Security - how Lenso protects studio and client work
- Terms of Service - terms for accounts, subscriptions, client links, and acceptable use
- Refunds and disputes - subscription and payment-dispute policy
- Status - current service-status information when configured