Kelsick Photography
DashboardPrivacy policy
Effective 29 September 2026
This policy covers the Kelsick Photography admin dashboard at admin.kelsickphotography.com (the “dashboard”). The dashboard is an internal tool used only by Kelsick Photography’s own staff to run the business. It is operated by Kelsick Photography, a Utah real estate media company owned through Kelsick Media Company. It does not cover our public website or the delivery of photos and video to clients.
What the dashboard holds
Staff accounts. For each person with a dashboard account: name, work email address, role (admin or sales rep), a one-way hash of their password (bcrypt), an encrypted two-factor authentication secret and hashed recovery codes, their active sign-in sessions, and the time they last signed in. Once Sign in with Google is live, the dashboard also records the Google account identifier for the person’s @kelsickphotography.com Workspace account, and a log of security events such as sign-ins, role changes and access reviews. Accounts are by invitation only; there is no public sign-up.
Business records. The sales pipeline and client book: names, brokerages, phone numbers, email addresses and notes about the real estate agents we work with or would like to, and public listing information about their properties. A copy of our orders from Aryeo, our booking and billing system: customer names and contact details, property addresses, appointments, what was ordered, prices, discounts, tax and payments.
The company’s own bank and card data. The two owners use Plaid to connect Kelsick Photography’s own business bank and credit card accounts so the dashboard can report expenses and profit. For those accounts the dashboard stores the account name, type and last four digits, and each transaction’s date, amount, description, merchant name and category, plus categories and notes the owners add. Bank sign-in details are entered into Plaid’s own window and go only to Plaid and the bank: the dashboard never sees or stores bank usernames or passwords. What it keeps is a Plaid access token, stored encrypted, that lets it read transactions from those accounts.
Cookies. The dashboard sets only the cookies it needs to keep you signed in: kp_session (your session) and kp_mfa (a ten-minute cookie while you enter a two-factor code). There are no advertising or analytics cookies and no tracking scripts. Pages load their fonts from Google Fonts, so your browser requests those files from Google.
Why
To run Kelsick Photography: to manage the sales pipeline and client relationships, pay commission, and report the company’s revenue, expenses and profit to its owners. We do not sell any of this information, use it for advertising, or share it with anyone except the service providers listed below, who handle it only to provide their service to us.
Who can see it
- Admins (the two owners, Ethan Galland and Isaiah Galland) can see everything, including Financials and all bank data.
- Sales reps see the sales pipeline, client book and their own commission. They cannot see Financials, bank connections or bank transactions.
- Photographers and editors are contractors and have no dashboard access.
- Every page and action checks your account and role on the server before it shows or changes anything.
How long we keep it
| Data | How long |
|---|---|
| Staff accounts | While the person works with us. Switched off the day they leave; deleted on request or at the next quarterly access review once no longer needed. |
| Sign-in sessions | Up to 30 days, or until you sign out. Expired sessions are deleted automatically.* |
| Two-factor sign-in attempts | Ten minutes. Stale attempts are deleted automatically.* |
| Leads, clients and Aryeo orders | For as long as we have a business relationship and need the records for accounting and tax (up to seven years), or until deleted on request where the law allows. |
| Bank and card transactions | Only from 1 January 2026 onward; nothing earlier is requested from Plaid or kept.* Kept while the account is connected, for up to seven years for the company’s financial records. Disconnecting an account deletes its transactions from the dashboard and removes the connection at Plaid. |
| Sync logs | 180 days, then deleted automatically.* |
| Security event log | At least one year, as evidence for access reviews.* |
* These automatic deletions and limits are being added to the dashboard in pending updates (bank data encryption and retention; Google sign-in and access reviews). Until they are live, the owners apply them by hand.
The database is hosted by Railway, and Railway’s backups of it (if enabled) keep their own copies for up to 89 days before they expire.
Third parties
- Plaid — connecting the company’s bank and card accounts and reading their transactions. Plaid End User Privacy Policy
- Railway — hosting the dashboard and its database. Railway Privacy Policy
- Google (Workspace) — staff email, and signing in to the dashboard. Google Privacy Policy
- Aryeo — our booking and billing system, the source of order data. Aryeo Privacy Policy
- GitHub — stores the dashboard’s source code (no customer or bank data). GitHub Privacy Statement
How it is protected
- The dashboard is served only over HTTPS; old TLS versions (1.0 and 1.1) are refused.
- Accounts are invitation-only. Admins must use two-factor authentication.
- Passwords are stored only as bcrypt hashes. Session tokens are long random values held in secure, HTTP-only cookies and checked against the database on every request.
- Plaid access tokens and two-factor secrets are encrypted with AES-256-GCM before they are stored. Bank transaction details are being moved to the same encryption (pending update).
- Messages from Plaid are accepted only when Plaid’s signature checks out.
- Passwords and keys for our services are kept in our hosting provider’s encrypted settings, never in the code.
- Dependencies are scanned for known vulnerabilities and the code for leaked secrets on every change.
Your choices
If you are a member of staff, a client or a lead and want to know what the dashboard holds about you, have it corrected, or have it deleted, email hello@kelsickphotography.com. We will answer within 30 days. We may need to keep some records, such as orders and payments, where the law requires it for accounting or tax; if so we will tell you what we kept and why.
The only people whose bank data the dashboard holds are the company itself, through accounts the owners connected. Either owner can disconnect an account at any time from Financials > Bank connections, which deletes its data here and removes the connection at Plaid. Plaid’s own handling of that data is covered by its End User Privacy Policy, and Plaid offers its own tools at my.plaid.com.
Changes
We will update this page, and its effective date, when the dashboard’s handling of data changes.
Contact
Kelsick Photography — hello@kelsickphotography.com
Ethan Galland, CEO — ethan@kelsickphotography.com
Isaiah Galland, COO — isaiah@kelsickphotography.com