Skip to content
FotoFit
Legal centre

Privacy Policy

How FotoFit collects, uses, stores, and deletes information when you use our websites, dashboard, integrations, and generation services.

Effective August 18, 2026Last updated August 20, 2026

In plain language

  • We use account, workspace, template, recipient, and submission data to provide the features you ask us to run.
  • We do not sell personal data or use Google Workspace data for advertising or to train generalized AI models.
  • Temporary output files expire on the schedule shown for your plan. Managed credential records and files are retained until you delete them or request account deletion.
  • Dodo Payments is the merchant of record for paid purchases and handles payment details on its hosted checkout.

Who this policy covers

This policy applies to FotoFit services at fotofit.in, app.fotofit.in, our public campaign and Smart Form pages, and our API. In this policy, “you” includes account holders, workspace members, form respondents, credential recipients, and visitors where the context requires.

An organization using FotoFit decides what recipient or respondent data to collect and why. For that data, the organization is normally the controller or data fiduciary and FotoFit processes the data on its instructions. Our Data Processing Terms explain that relationship.

Information we collect

  • Account and workspace data, such as your name, email address, login credentials, workspace membership, invitations, role, and preferences.
  • Content and configuration you provide, such as templates, frames, fonts, spreadsheet rows, field mappings, dynamic image URLs or uploads, API requests, webhook settings, and delivery instructions.
  • Recipient and Smart Form data, which may include names, email addresses, identifiers, submitted field values, and generated credentials. FotoFit does not currently collect phone numbers through Twibbon campaigns.
  • Google Sheets data you explicitly select, including spreadsheet and worksheet identifiers, names, columns, and selected row values used for imports or CSV Lookup forms.
  • Billing metadata such as your plan, subscription status, payment identifier, invoice details, currency, and amounts. FotoFit does not receive or store full card or bank-account details.
  • Technical and security data such as IP address, browser and device details, request identifiers, authentication sessions, API-key fingerprints, timestamps, logs, usage counts, failures, and abuse signals.

How we use information

We process information to perform our agreement with you, follow your instructions, operate our legitimate security and service interests, obtain consent where required, and comply with law. The precise legal basis depends on your location and relationship with FotoFit.

  • Authenticate users, manage workspaces and permissions, and keep accounts secure.
  • Create Twibbons, templates, bulk outputs, managed credentials, Smart Form results, and API renders requested by you.
  • Import selected spreadsheet data, deliver requested emails, operate webhooks, and provide verification pages.
  • Administer subscriptions, credits, invoices, fraud controls, support, and service communications.
  • Monitor reliability, troubleshoot failures, prevent abuse, enforce limits, and improve the product using aggregated or service-usage information.
  • Meet legal obligations and protect users, FotoFit, and the public.

Google Sheets and Drive data

Connecting Google Sheets is optional. FotoFit requests the Google Drive drive.file permission so you can choose a spreadsheet through Google Picker and let FotoFit read the selected spreadsheet and worksheet. We use the selected values only for the bulk job or CSV Lookup form you configure. FotoFit does not browse unrelated Drive files, edit or delete your files, or use Google data for advertising.

We store an encrypted OAuth refresh token while the connection is active, along with the connection and selected file references needed to operate the feature. Imported rows may be stored with the bulk job or Smart Form configuration so the requested workflow can run. You can disconnect Google Sheets in FotoFit or revoke access in your Google Account. Disconnecting deletes FotoFit's stored connection secret and stops future access; imported values already used in FotoFit remain subject to the normal product retention and deletion rules.

FotoFit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data is not sold, used for personalized advertising, or used to train generalized AI or machine-learning models. Human access is limited to circumstances you authorize, security and abuse investigation, legal compliance, or support needed to provide the feature.

Uploads and generated files

Dynamic images supplied for a generation job may be downloaded from the URL you provide or uploaded to temporary private storage and normalized for rendering. Job source uploads are deleted after job finalization. For a managed record, FotoFit may retain the original source URL and any replacement image you later upload so that an edit or regeneration can work. If the saved URL is no longer available, FotoFit asks you to provide a new URL or upload.

Temporary jobs create downloadable output files but no durable recipient record. Their files expire after completion according to the plan shown at the time of the job: currently 10 minutes on Free, 1 hour on Pro, and 24 hours on Growth. Deletion is handled asynchronously, so an expired object may remain briefly inaccessible while cleanup completes.

Managed credential records, current files, and limited regeneration history are retained while the record exists, including after a subscription is cancelled or downgraded. You can permanently delete an individual managed record or job in the dashboard. A permanent deletion removes the associated stored files, subject to backup, security, dispute, and legal-retention exceptions.

When information is shared

We share information only as needed to provide the service, follow your instructions, complete a purchase, protect the service, or comply with law. Providers receive only the information relevant to their role and are subject to contractual or legal obligations appropriate to that role.

  • Cloudflare provides object storage, content delivery, DNS, and security services.
  • Google provides the optional Sheets and Drive integration and, where configured, cloud task or rendering infrastructure.
  • Resend or a configured SMTP provider delivers transactional and recipient emails.
  • Dodo Payments acts as merchant of record for checkout, payment processing, invoices, tax, fraud, disputes, and refunds. Dodo handles payment data under its own buyer terms and privacy policy.
  • Professional advisers, authorities, or transaction counterparties may receive information when reasonably necessary for legal compliance, safety, claims, or a corporate transaction.

Cookies and local storage

FotoFit uses essential HttpOnly cookies for access and refresh sessions. In production they are sent only over HTTPS and are shared across FotoFit subdomains so sign-in can work between the website and dashboard. We store your light, dark, or system theme preference in local storage. When optional analytics is configured, a shared FotoFit consent cookie carries your choice between the public website and dashboard; Google Analytics or Plausible loads only after you accept. Advertising storage and personalized advertising remain disabled.

Retention

We retain account, workspace, billing, and product data for as long as needed to provide the service and maintain legitimate business, security, tax, dispute, and legal records. Retention differs by data type rather than using one blanket period.

  • Temporary render files follow the plan-specific expiry displayed for the job.
  • Managed credential files and records remain available while the record exists; cancelling a subscription does not delete an issued credential.
  • Google OAuth secrets remain until you disconnect, revoke access, or delete the relevant account, unless a short security or backup period is required.
  • Operational logs, invoices, payment identifiers, abuse records, and backups may be retained for the period reasonably required by security, accounting, dispute, and legal obligations.

Your choices and rights

Depending on applicable law, you may have rights to know about, access, correct, export, restrict, object to, or delete personal data, withdraw consent, and complain to a regulator. Workspace owners can manage much of their content directly. Form respondents and credential recipients should usually contact the organization that collected their data first; we will assist that organization where required.

Send requests from your registered email address to hello@fotofit.in. We may verify your identity and authority before acting. We will respond within the period required by applicable law.

Security and international processing

We use safeguards designed for the nature of the data, including HTTPS, password hashing, HttpOnly authentication cookies, encrypted integration secrets, private object storage with time-limited access, role and workspace checks, API-key hashing, rate limits, and operational logging. No online service can promise absolute security.

FotoFit and its providers may process information in countries other than yours. Where law requires a transfer mechanism or additional safeguards, we use contractual and technical measures appropriate to the transfer.

Children and school use

FotoFit is a business and creator tool, not a service directed to children. Schools and other organizations that submit information about minors are responsible for having the authority, notices, consents, and safeguards required by applicable law. They should collect only the data needed for the credential or form workflow.

Changes and contact

We may update this policy when the service, providers, or law changes. We will post the revised date and provide additional notice where a change materially affects your rights or our use of personal data.

For privacy questions, rights requests, or Google Sheets disconnection help, email hello@fotofit.in. FotoFit is operated from Kerala, India.

Questions about this policy?

hello@fotofit.in