What I collect, why I collect it, and what I will never do with it.
Last updated 21 July 2026
anjafio photography is one person. I am Andrew Fiore, a photographer working in Worcester County, Massachusetts, operating as a sole proprietor. There is no marketing department and no data team. Your information is handled by me.
The short version: I collect what I need to photograph you, deliver your photographs, and get paid. I do not sell your information, I do not share it for advertising, and I do not use your photographs to train artificial intelligence models.
On this page
The contact form asks for your name, your email address, a subject, and your message. That is all it sends.
Booking collects the information needed to plan and deliver a session:
Payment card numbers never reach me or this website. Card details are entered on Stripe and stay with Stripe. What comes back to me is whether a payment succeeded, an amount, and a reference number.
Ordering prints adds one more thing: Stripe collects your shipping address and passes it back to me so I can send the prints. It appears on your receipt.
Decisions about photographing children, and about whether anyone's photographs may be shown publicly, are not made at booking. They are made when the photo release is signed. See Your photographs and Children.
An optional account lets you come back to your client area without a link. It stores your email address and a securely hashed version of your password. Your password is never stored in a form anyone can read, including me.
If you accept the analytics choice, the site records basic activity so I can see which pages people find useful and whether the booking flow is working. If you decline, it records nothing. See Cookies and analytics for exactly what that means.
Every field above exists because a session needs it. Contact details let me reach you about your booking. The date, location, and notes let me plan and show up in the right place. Consent flags exist so I can prove you agreed before I ever text you or show your photographs. Payment references let me match a deposit to a booking and issue a refund if one is owed.
I do not build advertising profiles, and I do not buy or sell personal information.
Your photographs are the most personal thing here and they get the strongest treatment.
Film sessions produce physical negatives. I keep those negatives, as photographers normally do. The same choices about public use apply to scans from them.
I use a small number of outside services to run the business: taking payments, serving the site, delivering email, storing data, and alerting me when a booking request arrives. Each one sees only the minimum it needs to do its job, and none of them may use your information for purposes of their own.
Where your photographs are stored. The live site runs on a server in the United States. Every night, photographs and an encrypted copy of client records are copied to a backup store in the European Union. That means your information crosses a border. It is not used there for anything, it is storage.
I do not list these providers by name. A published map of the systems behind a site full of client photographs would do more for an attacker than for you. If you have a legitimate reason to need the list, write to me and ask.
Beyond these, I share information only when a person legitimately needs it to complete your order, such as a print or film lab, or when the law requires it.
The first time you visit, a small bar at the bottom of the screen asks whether you accept optional analytics and advertising measurement. You can accept or decline, and you can change your mind later using the Cookie choices link in the site footer.
This site sets one cookie, and only after you answer that question. It is named anjafio_consent and it stores nothing but your answer, so the site does not ask again on every page.
A few other things are kept in your browser rather than sent to me. They stay on your device:
If you decline, nothing is stored on your device and no visitor identifier is ever created. The site keeps working exactly the same way.
Two things still happen, and I would rather say so plainly than claim more than is true. My own server keeps a short arrival record, described just below. And the advertising measurement tag loads in its most restricted setting, where it may send an anonymous signal that carries no cookie and no identifier. Neither one can recognize you, follow you between visits, or connect two pages you looked at.
Separately from the choice above, my own server keeps one line for each page it serves: the time, which page, the site you followed a link from if there was one, and any campaign tags that were already in the address you clicked. This is the only way I can tell whether an advertisement brought anyone here at all.
It holds no cookie, no identifier, and no IP address, and there is nothing in it that can connect two page views to the same person. It is a count of arrivals, not a record of people. Requests from search engines and other automated visitors are left out of it entirely.
The site records page views and key steps such as starting a booking, so I can tell whether the site is working. Each record holds the page, the referring link, your browser's user agent, a random visitor identifier, and how you first arrived, such as a campaign link.
That log does not record your IP address. Because of how the site is served, what reaches the log is the delivery network's address rather than yours, so visitor addresses are not retained there.
One thing worth being plain about: submitting a booking is itself recorded as an event, so the activity log ends up holding a copy of what you submitted, including your name, email, phone, and notes. It is not an anonymous statistics file, and I treat it as client data.
Separately from any of this, the delivery network in front of the site sees incoming requests the same way any host would, whatever you choose here.
To be straightforward with you: the site contains the wiring for advertising measurement services, including Google and Meta, because I may advertise this business in future. None of those services are currently loaded on this site, no advertising tag runs today, and the wiring is switched off entirely unless you accept. If you decline, it stays off. If that changes, this section changes with it.
The delivery network also provides basic visitor counting, which does not use cookies.
Your finished photographs are delivered through a gallery of your own, reached by a link I send you. A gallery can also be set private and protected with a password, and repeated wrong guesses are throttled so a password cannot be worked out by brute force.
Where a gallery is not password protected, the link itself is the protection, so anyone you forward it to can open it. That is deliberate, so you can share with family without them needing an account. Treat the link accordingly, and ask me if you would rather have a password on it.
Galleries are asked not to appear in search engines. Example albums shown publicly on the site are only ever from clients who chose Yes to public use, and public viewing does not hand out the full resolution originals.
One exception worth naming: the sneak peek of a few favorites sent within 48 hours is served from a plain link with no password on it. It is a handful of images, and it is unguessable, but anyone holding that link can open it.
Your gallery stays online for at least a year after delivery. Please save your photographs somewhere safe while it is up. If you want a gallery taken down sooner, or its link changed, ask me.
There are two different kinds of message and they follow different rules.
Unsubscribing stops promotional mail. It does not stop a receipt or a message telling you your gallery is ready, because those are the service you booked.
I do not send text messages to clients. Not marketing texts, not reminders. If that ever changes it will be something you opt into, and this page will say so first.
When you write to me through the contact form, I keep a copy of your message alongside the email, so a note does not get lost in a mailbox.
I photograph families, so children are often in front of my camera. That is different from children using this website. This site is not directed at children and I do not knowingly collect information from anyone under 13.
When children are photographed, a parent, legal guardian, or other authorized representative signs the photo release and makes one choice, Yes or No, covering every child in their care at that session. What I store from that is the name of the adult who decided, their relationship to the child, their signature, and optionally the child's name, so the release records who it covers. The child's name is not required and you can leave it out.
If you believe a child has sent me information directly through this site, tell me and I will delete it.
Straight answer: by default I keep things indefinitely. There is no automatic clock that deletes your booking record, your correspondence, or your photographs after a set period.
That is a deliberate choice rather than an oversight. Clients come back years later wanting a reprint of a photograph they did not order the first time, and tax and accounting records have to be kept for years regardless. Photographs and negatives are kept so that reordering stays possible.
Two things to know about what that means in practice:
Backups are the practical limit on immediate erasure. Deleted material can persist in encrypted nightly backups for a period after I remove it from the live system.
Some of these you can do yourself. Unsubscribing from promotional email is one click in any such email. Changing your analytics choice is the Cookie choices link in the footer. Deleting your account is in your client area, and as noted above that removes the login rather than the session record.
Everything else is a request to a person, because it needs a person. Email me and I will do it by hand. There is no automated erasure button for photographs, and I would rather tell you that than pretend otherwise. Write to hello@anjafio.com to ask me to:
I do not require you to prove residency in a particular state to ask. If you are a Massachusetts resident, a California resident, or covered by another privacy law, you are welcome to the same choices either way. I will confirm your identity before acting on a request about someone else's photographs, for obvious reasons.
The site runs over an encrypted connection, payment card numbers never touch it, gallery links cannot be guessed, and the administrative side of the site is separately protected. No system is perfect, and I will tell you promptly if something happens that affects your information.
If you have found a security problem, there is a disclosure address at security.txt.
If this policy changes in a way that matters, I will update the date at the top, and I will tell clients with an active booking directly rather than quietly editing the page.
Questions about any of this go to hello@anjafio.com. A real person reads it.
See also the Terms of Service, which cover booking, payment, cancellation, and delivery.