Last updated 30 September 2026
Filmset holds two very different kinds of information: the accounts of the studios who pay us, and the weddings those studios deliver through us. We answer for the first. For the second we only do what the studio tells us. This policy keeps them apart, because the difference decides who you ask when you want something changed.
| Whose data | Our role | Who decides |
|---|---|---|
| The studio's account name, email, billing, how they use the app |
We are responsible for it | Us. Ask us directly. |
| The wedding films, photographs, couple names, client email addresses |
We only store and deliver it, on the studio's instruction | The studio. Ask them, and we will act on what they tell us. |
In legal terms we are the controller of the first and a processor for the second. In practical terms: if you are a couple who wants your gallery taken down, write to your photographer — they can do it in seconds, and we will do it at their request.
This is the wedding itself, and it is there because a studio put it there:
We do not look through this material, and we do not use it to train anything. We access it only to run the service, to fix a fault, or where the law requires.
If you have been sent a gallery, here is everything that happens:
We do not build a profile of you, we do not track you across other websites, and we do not sell anything about you to anyone.
Galleries and the studio app set no advertising cookies and run no third-party analytics or tracking scripts. Every cookie they set does a job you asked for:
| Cookie | What it does |
|---|---|
| fs_session | Keeps a studio signed in |
| fs_studio | Remembers which studio you are working in |
| fs_pending | Holds the two-step sign-in briefly, mid-login |
| fsg_… | Remembers that a visitor entered a gallery's password |
| fs_v | An anonymous id so a visitor's favourites are theirs |
Your browser also stores a few preferences locally — light or dark, where you had reached in a film — which never leave your device and never reach us.
Our own marketing pages are the one exception. On filmset.co’s home page, the
comparison pages and the invitation form, we use the Meta Pixel to measure our
advertising. It tells Meta (Facebook and Instagram) that your browser opened one of those
pages, and whether it asked for an invitation, so we can see which of our ads work and show
them to people likely to be interested. Meta may connect that to a Meta account you are
signed in to, under Meta’s own privacy
policy. It sets Meta’s _fbp cookie, and our own fs_mid: a random
number that lets the pages a browser opens and its request be recognised as one visitor. Meta only
ever receives it scrambled (hashed), never the number itself.
Our server also tells Meta about those page views and requests directly, so they are counted even if your browser blocked the pixel. It sends the same facts the pixel would, your browser’s IP address and type, and your email address in hashed form (scrambled so it cannot be read back), which Meta uses only to match the request to the ad you saw.
It never runs in a gallery, for a signed-in studio, on a studio’s own domain, for visitors in the EU, EEA, UK or Switzerland, or in a browser that sends the Global Privacy Control signal. You can also switch it off for this browser.
For studios: because we need it to provide the service you have contracted us for, to take payment, and to meet our legal obligations. Where we rely on a legitimate interest — keeping the service secure, preventing fraud — we have weighed it against your interests.
For gallery content: because the studio instructed us to hold it. The studio is responsible for having the consents and releases required from the people who appear in it, and they promise us they do.
We use a small number of providers to run Filmset. Each is bound to protect what it handles and to use it only for us:
| What for | What they hold |
|---|---|
| Hosting, file storage and the database | Everything the service stores |
| Video encoding and streaming | Films, and the streams delivered from them |
| Sending email | Recipient addresses and message contents |
| Payments | Studio billing details and card data |
| Our own business email | Anything you write to us |
| Measuring our advertising (Meta) | That a browser opened our marketing pages or asked for an invitation, with a hashed email address for a request |
The current list of providers is available on request at support@filmset.co.
We do not sell personal information. The only information shared for advertising is what the Meta Pixel sends from our marketing pages, described above, and you can stop it. We will disclose information if the law compels us, or to protect someone's safety — and where we are permitted to tell the affected studio, we will.
Files are stored in the United States. Video for streaming is encoded and held in Germany and the United States, and delivered from edge locations worldwide so a gallery loads quickly wherever it is opened.
That means information may be transferred outside the country you live in, including to the United States. Where the law requires a safeguard for that transfer, we rely on our providers' standard contractual clauses.
No service can promise perfect security. If a breach affects your information we will tell you and the relevant authority as quickly as the law requires and as clearly as we can.
Wherever you live, you may ask us to give you a copy of the personal information we hold about you, correct it, delete it, or stop a particular use of it. Depending on where you live — including the EU and UK under the GDPR, and California, Texas and other US states under their own privacy laws — you may also have the right to portability, to object to processing, and to complain to a regulator. We do not sell personal information. Under some US state laws the Meta Pixel on our marketing pages counts as sharing for targeted advertising; you can opt out of it as described in the next section. We will not treat you differently for exercising any of these rights.
Write to support@filmset.co. We will answer within 30 days, and we may need to verify who you are first.
If you are a couple or a gallery visitor, the material in the gallery belongs to your photographer's account. Ask them first — it is faster, and they can act immediately. If you cannot reach them, write to us and we will pass it on and help.
You can stop our marketing pages from sharing anything with Meta from this browser. We will remember it for two years. Turning on Global Privacy Control in your browser does the same everywhere, and we honour it automatically.
Filmset accounts are for adults; the service is not directed at children and we do not knowingly collect information from them. Galleries very often contain photographs of children, uploaded by a studio who is responsible for having the permission to do so. If you believe a child's information is on Filmset without proper consent, write to support@filmset.co and we will act.
Email from Filmset comes in two kinds. Transactional messages are the ones you asked for or need — a gallery link, a password, a receipt, and a studio's warning that files are about to be deleted. They carry no unsubscribe link because switching them off would break the thing you are paying for.
Reminders sent to a couple before a deadline carry an unsubscribe link and we honour it immediately.
If a message hard-bounces or is reported as spam, we stop writing to that address for good, whatever kind of message it is. That is not a preference anyone can override.
We will update this policy as Filmset changes. If a change is material we will email the studios on our list before it takes effect, and the date at the top always says when it last changed.
Write to us about anything in this document at support@filmset.co.