Privacy Policy

What we collect, how we use it, and your rights.

Last updated: June 8, 2026

This page explains what data we collect, how we use it, who we share it with, and your rights over it. Plain language. No tricks.

Who we are

Collin Stark Headshots is operated by Stark Method LLC. You can reach us at info@collinstarkheadshots.com for any privacy question.

What we collect

We collect three categories of information:

  1. Information you give us — name, email, phone, acting agency, headshot preferences, and anything you write in a booking form or send us by email. Provided voluntarily when you contact us or book a session.
  2. Information we collect automatically — pages visited, links clicked, emails opened, IP address, device, browser. Collected through standard analytics, cookies, and email tracking pixels.
  3. Information from third parties — when an agent, manager, or referral introduces you, we receive the basic profile data they share.

How we use it

  • To deliver the headshot services you've requested
  • To send emails you've subscribed to (booking confirmations, refresh reminders, you can unsubscribe anytime)
  • To improve our work, content, and offers
  • To coordinate with your acting agent or manager when you've authorized us to
  • To comply with legal obligations (tax records, model releases, fraud prevention)

We do not sell your data. We do not share it with advertisers. We do not use it to profile you for purposes you didn't agree to.

Who we share with

We use these service providers to run our business. They receive only the data needed to do their job:

  • Klaviyo — email delivery and analytics
  • Cloudflare — content delivery and DDoS protection
  • Vercel — website hosting
  • Supabase — database and authentication
  • Google (Gmail, Drive, Calendar) — email, file storage, scheduling
  • Stripe / PayPal — payment processing

Each provider has its own privacy policy. We've reviewed and signed Data Processing Agreements where required.

How long we keep it

  • Active clients: for the duration of our working relationship
  • Past clients: up to 7 years for tax/legal records, then deleted
  • Inquiry forms / leads: up to 2 years if no engagement, then deleted
  • Headshot files and footage: kept indefinitely as part of our archive, subject to your model release terms
  • Analytics / behavior data: up to 24 months in identifiable form, then aggregated

Your rights

You can:

  • Access — request a copy of every piece of data we hold on you
  • Correct — fix anything that's wrong
  • Delete — ask us to wipe your data entirely (subject to legal retention windows and existing model releases)
  • Port — get your data in a machine-readable format to take elsewhere
  • Object — tell us to stop processing for specific purposes
  • Unsubscribe — every email has an unsubscribe link; works one-click

Email info@collinstarkheadshots.com with the subject "Privacy request" and we'll respond within 30 days.

Cookies and tracking

We use a small number of cookies and tracking pixels:

  • Essential cookies — let the site work (login, language)
  • Analytics cookies — let us see which pages get read and which links get clicked
  • Email tracking pixels — let us see open and click rates on emails you've subscribed to

We don't use third-party advertising trackers. We don't sell cookie data.

Image rights

Headshots produced during your session are governed by the model release and contract you signed before the shoot. Within those terms, we retain creative ownership of the work and may use it for portfolio and case-study purposes consistent with your release.

Our galleries are monitored for unauthorized access and image theft. By accessing any gallery you consent to that monitoring. Reproducing, downloading, or redistributing imagery outside the terms of your release may result in legal action and licensing fees.

Security

We protect your data with:

  • HTTPS / TLS encryption in transit
  • Encryption at rest on all databases
  • Row-level access controls on every table holding personal data
  • Daily encrypted backups
  • Rotated keys and limited access roles
  • Incident response plan with 24-hour notification window

We can't promise breaches are impossible. We can promise we've put the right defenses in place and that we'll tell you fast if something goes wrong.

Children

Our services are not directed at anyone under 16 without a parent or guardian's consent. If you believe we've collected data from a child without that consent, email info@collinstarkheadshots.com and we'll delete it.

Changes to this policy

We may update this policy as the business evolves. Material changes will be flagged at the top of the page and emailed to anyone on our list. The "Last updated" date always reflects the current version.

Contact

Questions, complaints, requests — all to: info@collinstarkheadshots.com