Privacy policy

Last updated:

1. What we collect

From the studio: name, e-mail, password (stored hashed) and the brand settings it configures. From the material: the photos and videos uploaded, processed only to provide the service. From the end client: no signup at all, they open a link without an account. When a client favorites or reviews a delivery, those records attach to the gallery, not to a profile.

2. Where the data lives

Material is stored in cloud object storage (Backblaze B2) and streaming is served by dedicated video infrastructure. Transactional e-mail goes out through Resend. Payments are processed by Stripe, and Momentz never sees or stores card data. Support chat runs on Crisp. Usage metrics and error monitoring use PostHog and Sentry.

3. Connected cloud accounts

Momentz connects to Google Drive and Dropbox in two directions, and each one is authorized by the person who owns the account being used. Files are never moved between two accounts, and no connection is ever made on somebody else's behalf.

Delivering to a client. When the person receiving a gallery chooses to have it sent to their own cloud, Momentz asks that account for write access only: it can put that gallery's files into a new folder and nothing else. It cannot read, list or alter anything already there. The authorization is used for that one transfer and is destroyed the moment it ends, whether it succeeded or failed.

Importing a studio's own material. A studio may connect its own cloud account to bring its own footage in. Momentz lists that account's folders so the studio can choose what to import, and reads only the files it selects. Because the connection is meant to be reused, the credential is kept — encrypted at rest, on our servers, never exposed by any page or API response — until the studio disconnects the account, which deletes it.

4. Your rights (LGPD)

Under Brazil's General Data Protection Law (LGPD), a data subject may request access to, correction of, or deletion of their data, as well as information about how it is processed. Requests can be made through the support chat inside the platform.

5. Cookies

The public site uses no tracking cookies. Inside the platform, cookies and local storage exist to keep the session and the studio's preferences.