Mobile App Data & Permissions
What the Signature Album Android app may process and why each device permission is used.
Examples: name, studio/business name, email, phone number, profile photo and account identifiers.
Purpose: account creation, authentication, client identification, service communication and support.
Examples: user-selected photos, album files, proofs, correction markings, thumbnails, final-delivery files and attachments.
Purpose: album design, proofing, corrections, printing (where ordered) and final delivery.
Examples: message text, attachments and user-initiated voice notes.
Purpose: communication between the client, authorised team members and administrators about a project.
Examples: order details, service type, amounts, discounts, invoice records, payment status and transaction references.
Purpose: billing, payment verification, account balance, refunds/cancellations where applicable and financial recordkeeping.
Examples: device model, operating system/app version, session/login records, security logs and push-notification token.
Purpose: sign-in security, device/session management, fraud/abuse prevention, troubleshooting and delivery of notifications.
Where the app asks for photo/video access, it is for selecting or uploading media needed for profile or project features. The app should use the minimum permission scope appropriate to the feature and Android version. Occasional user selection should use Android’s system picker when feasible rather than unnecessary broad media-library access.
Microphone access is used only when you deliberately start a voice-message or audio-recording feature. The app should not record audio in the background for unrelated purposes.
Notification permission is used for relevant account, order, message, proof/correction, payment, workflow and delivery updates. Users can manage notification permission in Android settings, subject to platform rules.
The normal Signature Album workflow should not require continuous precise location, contacts, SMS or call-log access. If a future feature genuinely needs a new sensitive permission, the app, privacy policy and Play Console disclosures should be updated before that permission is used.
Data may be processed by infrastructure and service providers necessary to deliver the requested feature, such as hosting/cloud storage, Google Drive where used, Razorpay or another payment processor, email/SMS/push-notification services, authorised design/print partners and couriers where applicable. We do not sell personal data.
This public notice does not replace the Google Play Data safety form. The Data safety form must accurately match the app’s actual code, SDKs, permissions, data collection, sharing, encryption and deletion behavior for the released version.

