Privacy Policy
Privacy Policy.
1. Who we are
Lighting Lab is an off-camera flash simulator published by Nathaniel Rohr, an individual photographer and educator ("we", "us"). It runs at lightinglab.nathanielrohr.com. This policy explains what information the lab handles, why, and the choices you have. We do not sell personal information and we do not show advertising.
2. What we collect
Using the free lab, with no account
You can use the free lab without telling us anything. Your lighting setups, kit colours and an uploaded team logo stay in your own browser (see section 5). Our hosting provider records standard server logs, described in section 4.
Buying Lighting Lab Pro
Payment is handled by Stripe on Stripe's own pages. We never see or store your card number. Stripe tells us your email address, the plan you bought, and payment status so we can create your account and switch Pro on. If you ask Stripe for a receipt or portal access, Stripe may collect your name and billing address under its own privacy policy.
Having an account
An account holds your email address, a hashed password (we cannot read it), the date it was created, and your plan status. If you save setups to the cloud, we store the setups you save: a name, an optional description and tags, and the setup itself (light positions, modifiers, gels, subject and scene settings). You can delete any of them at any time.
Using the Shoot Planner (Pro)
If you type a place name into the Shoot Planner, that place name and the date you choose are sent to Open-Meteo, a weather service, to look up coordinates, sunrise and sunset times and a forecast. No account information is sent with it. We do not ask for or use your device's location.
Writing to us
If you email us, we receive what you send and your email address, and we keep the exchange for as long as it is useful to help you.
What we do not collect
- No analytics or tracking scripts, no advertising identifiers, no social media pixels.
- No cookies set by the lab itself. Stripe sets its own cookies on its checkout pages.
- No images of you. The subject in the lab is a built-in figure; a team logo you upload stays in your browser unless you choose to save a setup that uses it.
3. Why we use it
| What | Why | Basis |
|---|---|---|
| Email, plan, payment status | To create your account, switch Pro on and off, send receipts and the activation email | Performing our contract with you |
| Saved setups | To store and return what you asked us to keep | Performing our contract with you |
| Server logs | To keep the service running, detect abuse and fix faults | Our legitimate interest in a working, secure service |
| Billing records | Tax and accounting | Legal obligation |
| Your emails to us | To answer you | Our legitimate interest in supporting customers |
We send transactional email only: receipts, the account activation link, password resets, and replies to you. We do not send marketing email from the lab.
4. Services we rely on
| Service | Role | What it handles |
|---|---|---|
| Netlify | Hosting and serverless functions | Serves the pages; keeps standard access logs (IP address, browser type, pages requested, timestamps) for a limited time |
| Supabase | Accounts and database (United States, Ohio region) | Email, hashed password, plan status, saved setups, billing mirror |
| Stripe | Payments | Card details, billing details, receipts, subscription management. We receive email, plan and payment status. |
| Open-Meteo | Weather and geocoding for the Shoot Planner | The place name and date you type; your IP address as part of the request |
| Google Fonts | Typeface | Your browser requests the font file from Google, which sees your IP address |
Each of these providers publishes its own privacy policy. We share only what each one needs to do its job, and nothing for their own marketing.
5. Data stored in your browser
The lab uses your browser's local storage, which stays on your device and is not sent to us unless you take an action that needs it (signing in, saving to the cloud). It holds:
- your current sign-in session and plan status, so you stay signed in;
- interface preferences, such as which panels are open;
- an uploaded team logo and locally saved setups, if you use those features.
Clearing site data in your browser removes all of it. Signing out removes the session and plan status.
6. How long we keep data
- Account and saved setups: for as long as you have an account. When you request deletion from the account page, the account enters a 7-day window in which you can change your mind, then account data and saved setups are deleted.
- Billing records: as long as tax and accounting law requires, typically seven years, held by Stripe and in our billing mirror.
- Server logs: retained by Netlify for its standard period, then discarded.
- Email to us: as long as it is useful to help you, then deleted.
7. Your choices and rights
Wherever you live, you can:
- See and change your email and plan on the account page, and manage billing through Stripe's portal from there.
- Delete saved setups from inside the lab, and your whole account from the account page.
- Ask us for a copy of the personal information we hold about you, for a correction, or for deletion, by emailing nrohr@nathanielrohr.com. We answer within 30 days.
If you are in the European Economic Area, the United Kingdom, California or another place with a data protection law, you may have additional rights, including to object to or restrict processing, to data portability, and to complain to your local authority. Email us and we will help. We do not sell or share personal information for cross-context advertising, and we treat a request to opt out as granted by default.
8. Children and schools
The free lab collects no personal information, so students of any age can use it in a classroom. Accounts and purchases are for people aged 16 or over; a teacher or parent should hold the account for younger students. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, email us and we will delete it.
9. Security
All traffic uses HTTPS. Passwords are stored only as salted hashes by Supabase. Card data never reaches our servers. Access to the account database is limited to the serverless functions that need it and to the publisher. No system is perfectly secure; if we learn of a breach affecting your information we will tell you without undue delay.
10. Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and, for account holders, say so by email or on the account page before the change takes effect.
11. Contact
Nathaniel Rohr, publisher of Lighting Lab. Email: nrohr@nathanielrohr.com.