Skip to content

Legal

Privacy Policy

Soldello handles real information about real people: the agents in a photographer’s client list, the homeowners whose houses are photographed, and the buyers who sign in at an open house. This policy says what we collect, who we hand it to, and how long we keep it. It describes what the product actually does today, not what it might do later.

Last updated 2 October 2026

Contents
01

Who we are

Soldello is operated by Digilux HD LLC, a Florida limited liability company. “Soldello” is a fictitious name (a DBA) under which Digilux HD LLC does business. In this policy, “we”, “us” and “our” mean Digilux HD LLC.

You can reach us about anything in this policy at support@soldello.com. That address reaches a person, and it is the only one we ask you to use — we do not run separate privacy or legal mailboxes.

By post: Digilux HD LLC, 407 Lincoln Rd, Suite 6H PMB 1141, Miami Beach, FL 33139.

02

Who this policy covers

Four kinds of people have information in Soldello, and they arrive by different routes. This policy covers all of them.

  • Photographers and studios. The subscriber — the person or business that holds the account, uploads the photographs and runs the workspace.
  • Agents and other clients. The people a photographer shoots for. They receive galleries, listing websites and marketing material, and some of them also hold their own login to the listing portal.
  • Sellers. Homeowners who receive a performance report about their own listing through a private link.
  • Members of the public. Anyone who opens a public listing page, uses the buyer chat, or signs in at an open house.

For most of what sits inside a photographer’s workspace — their client list, their orders, their photographs — the photographer decides what goes in and what is done with it, and we hold and process it on their behalf. If you are an agent or a seller and you want a record changed or removed, the fastest route is usually the photographer who created it. Write to us if that does not work.

03

What we collect

Account information

Your name, email address, phone number, profile photo, and the details of your studio or brokerage. Sign-in is handled by Supabase Auth: your password is stored there as a hash, and we never see or store the password itself.

Client and contact records

First and last name, email address, phone number, brokerage or company, profile photo, and any notes the photographer or agent writes. Agents using the listing portal also build contact records for buyers and sellers, including how they were first met.

Order and property information

The street address of the property, appointment dates and times, the services ordered and their prices, shot lists, listing facts such as bed and bath counts, and any notes attached to the job.

Photographs, video and floor plans

The original files a photographer uploads, every version generated from them, floor plans, and videos. Photographs of a home show the inside of somebody’s house, which is why Section 5 describes separately how they are stored and who can reach them.

Payment information

We never receive or store a full card number. Card details are entered directly into Square’s payment form in your browser and exchanged with Square for a token. What we keep is the card brand, the last four digits, and Square’s own customer and card identifiers — enough to show you which card is on file and to charge it again when you have asked us to.

Usage and delivery records

  • Page views. A count of gallery and listing-page opens against the order they belong to. We record which order and when, not who was looking.
  • Downloads. When a gallery’s files are downloaded, and what was downloaded.
  • Email events. For each message we send: the recipient address, the type of message, and its lifecycle — sent, delivered, opened, clicked, bounced or marked as spam — as our email provider reports it back to us.
  • Audit events. Significant actions taken in the product: who did it, what they did, what it was done to, the IP address and browser user agent it came from, and what the content was at the time. This is how a dispute about who approved or published something gets settled.

Open house sign-ins

When an agent runs an open house through Soldello, a visitor may leave their name, email address, phone number, whether they already have an agent, whether they are pre-approved, and a note. There is also a marketing consent box. It is unticked by default and it is never inferred. Signing a sheet to be let into a house is not agreement to a marketing sequence, and we do not treat it as one.

Connected-account credentials

When you connect an outside account (Section 11), we store the access and refresh tokens that let us act on your instruction. Social publishing tokens are encrypted at rest with AES-256-GCM, under a key held separately from the database.

04

Public records we look up

Some of the information in Soldello was never typed in by you. It comes from public records, and it is there so that facts already on file do not have to be retyped on every order.

The Florida real estate licensee register

We hold a copy of the Florida Department of Business and Professional Regulation’s monthly export of licensed real estate professionals — 298,254 licensees. For each one it holds the name, licence number and rank, licence dates, email address, phone number, city, county and ZIP code, and the firm they are attached to. All of it is public record published by the state.

Public record is not the same as freely browsable, and we treat it that way. The table has row-level security switched on with no access policy for signed-in accounts at all. No photographer and no agent using Soldello can search it, list it, or export it. It is reachable only by our own administrators, through an internal tool, and it is used to resolve a name or a brokerage to a licence record and to understand the market we operate in.

If you are a Florida licensee and you would rather not be in our copy, write to support@soldello.com and we will remove your record. We cannot remove you from the state’s own published register — that is a matter for the DBPR.

Property records

To fill in the facts about a property — beds, baths, square footage, lot size, year built, and in some counties the recorded owner name — we query county property appraiser websites and their public mapping services, the US Census Bureau geocoder, and two licensed property-data providers. These lookups are keyed on a property address, not on a person.

05

How photographs move through the platform

A photographer uploads their originals. From each one we generate three versions: a watermarked preview, an MLS-sized copy, and the full-resolution file. Room tagging (Section 9) may also run at this point.

The client gallery sits behind a payment gate. Until the order is released, every image on the page — the hero included — is the watermarked preview, and the clean files are not sent to the browser at all rather than merely hidden in it. Once the order is released, the clean MLS-sized and full-resolution files become available to view and download.

Galleries and seller reports are reached through a long random link rather than a login. Those pages are marked noindex so search engines do not list them, and the file links themselves are signed and stop working after fifteen minutes. Treat the link as private: anyone who has it can open the gallery.

06

Why we use it

  • To run the service: bookings, uploads, galleries, listing websites, marketing material and reports.
  • To take payment, keep a card on file when you have asked us to, and charge it on delivery.
  • To send the messages the work itself requires — a booking confirmation, a delivery notice, a password reset.
  • To show a photographer how their business is doing, and an agent how their listing is performing.
  • To keep the platform secure and accountable, which is what the audit log in Section 3 is for.
  • To answer support requests, and to meet our legal, tax and accounting obligations.

We do not sell personal information, and we do not share it with advertisers. We do not run behavioural advertising, and we do not build profiles for anyone outside the account the information belongs to.

07

Payments

Payments run through Square. A photographer may connect their own Square account, in which case their clients’ payments settle directly with them; otherwise payments run through our Square account. Either way card numbers are captured by Square in your browser and never reach our servers, and a payment only releases an order after Square’s signed webhook confirms it and the amount matches. Square’s handling of your payment details is governed by Square’s own privacy notice.

08

Email and text messages

Transactional email is sent through Resend. We record when each message is delivered, opened, clicked, bounced or reported as spam, so a photographer can tell whether a delivery notice actually arrived. Text messages are sent through Twilio, from a real phone number provisioned for the workspace.

Agents can switch off the non-essential mail — the “more photos were added” notice, listing activity nudges, and the automated seller report — from their portal settings. Messages that are the transaction itself, such as a delivery email, an appointment confirmation, a portal invitation or a password reset, cannot be switched off while the account is in use.

Marketing mail to a contact captured at an open house is sent only where that contact ticked the consent box. Our outgoing mail does not currently carry a one-click unsubscribe link. To stop receiving mail from us, write to support@soldello.com and we will action it by hand.

09

Artificial intelligence

Three AI providers are used, each for a specific job, and only when a feature that needs them is used.

  • Anthropic writes listing copy, MLS remarks, social captions, marketing email, seller updates, image alt text and buyer-chat replies. What is sent is the listing facts and the instructions for the piece being written.
  • Google Gemini tags photographs by room type so a shoot can be sorted into walkthrough order. Photographs are sent for this.
  • Decor8AI performs virtual staging, object removal, sky replacement, enhancement and upscaling. Photographs are sent for this.

Nothing is sent to a provider beyond what the requested feature needs, and no AI feature runs on your content unless it is asked for. What each provider does with what it receives is governed by that provider’s own terms, which we do not control.

10

Service providers

These are the companies that process information on our behalf, and what each one is for. We do not put a provider on this list until it is genuinely in use.

CloudflareHosting, image delivery, object storage for photographs, and domain registration when an agent buys a listing domain through us.
SupabaseThe database and the sign-in system.
Amazon Web ServicesCold storage. Older shoots move to S3 Glacier and then Deep Archive, which is why an archived gallery takes minutes or hours to come back.
ResendSending email, and reporting what happened to it.
SquareCard payments, cards on file, and subscription billing.
GoogleCalendar, when you connect one. Maps Places for address autocomplete. Gemini for photo room tagging.
DropboxImporting photographs and creating delivery folders, when you connect an account.
AnthropicWritten marketing copy, and the buyer chat.
Decor8AIVirtual staging and AI photo editing.
TwilioText messages, and the phone number they are sent from.
MuxHosting and transcoding property video.
4overPrinting and shipping physical marketing material, which means the delivery address goes to them.
RentCast and RapidAPIProperty facts looked up from public record by address.
Meta and XPublishing posts to a Facebook Page, Instagram Business account or X account you have connected, reading how those posts did, and receiving the leads from a connected Facebook Page's lead forms.

A few more are reached only on your explicit instruction. Aryeo, HDPhotoHub and Rela are called by the migration tool at /export, using an API key you paste in; that tool runs entirely in your own browser and writes to your own disk, so neither the key nor the files pass through our servers. And a county property appraiser receives a property address when a lookup is run against it.

We may also disclose information where the law requires it, to enforce our terms, or as part of a merger or sale of the business — in which case this policy travels with it.

11

Accounts you connect

Google Calendar, Dropbox, Square, Facebook, Instagram and X are connected by you, one at a time, and each connection belongs to the person who made it rather than to the workspace as a whole. Nothing is connected by default.

You can disconnect any of them from your settings, and you can also revoke our access from the provider’s own security page, which works whether or not you still have a Soldello account. Disconnecting stops future access; it does not retroactively delete what was already imported or created.

12

Google user data

If you connect a Google account, Soldello requests a single scope: https://www.googleapis.com/auth/calendar.events.

We use it for one thing: to put your confirmed shoots on your own calendar, and to keep them up to date when a booking moves or is cancelled. We do not read your calendar for any other purpose, we do not use it to build a profile of you, and we do not use it to train any model.

Soldello’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to others except as necessary to provide or improve this feature, to comply with applicable law, or as part of a merger or acquisition. We do not sell it, and we do not use it for advertising.

You can revoke our access at any time from your Google account permissions page, or by disconnecting the calendar in your Soldello settings.

13

Facebook and Instagram data

If you connect a Facebook Page, Soldello asks Meta for these permissions, and uses each one only for what is listed here:

  • pages_show_list to list the Pages you manage, so you can choose which one to connect.
  • pages_manage_posts to publish the posts you approve to that Page, and to change or delete one of those posts when you ask.
  • pages_read_engagement to read the Page’s name and, for posts we published, the post as it is on the Page and how many reactions, comments and shares it has.
  • instagram_basic to find the Instagram professional account linked to the Page, read its username, and, for posts we published, read the post as it is on Instagram and its like and comment counts.
  • instagram_content_publish to publish the posts you approve to that Instagram account.
  • leads_retrieval and pages_manage_ads to read the Page’s lead forms and the answers people give on them, so each new lead arrives in your contacts.
  • read_insights and instagram_manage_insights to read how many times the posts we published were seen and by how many people, and, on Instagram, how many times they were saved and shared, which we show you in your reports.

What we keep

The Page’s ID and name, the Instagram account’s ID and username, an access token for the Page (encrypted with AES-256-GCM), the IDs and links of the posts we published, and their counts: reactions, comments, shares, saves, views and reach. We keep counts, not who reacted, commented or saw a post. From a lead form we keep what the person entered, usually a name, email address and phone number plus the form’s own questions, and the form’s name, as a contact in your account. We do not read your personal profile, your friends or your messages.

How we use it

Only to provide these features to you. Nothing is posted unless you, or someone on your team, approves it. Filling in a lead form is treated as asking to be contacted about it, not as agreeing to marketing email. We do not sell any of this, use it for advertising, or use it to train AI models, and our use of information from Meta follows Meta’s Platform Terms.

How long we keep it

The connection and its token are kept until you disconnect. Posts already published stay on Facebook and Instagram unless you delete them, and our record of them stays with the campaign. Leads become contacts in your account and are kept like any other record (Section 15).

How to delete it

  • Disconnect. In Soldello, open Settings, then Connections, and press Disconnect on Facebook and Instagram. The stored token and the connection are deleted straight away.
  • Remove us on Facebook too. In Facebook, open Settings and privacy, then Settings, then Business integrations, and remove Soldello. This works whether or not you still have an account with us.
  • Delete everything we received from Meta. Email support@soldello.com from your account’s address and name the Page. That includes leads filed from its forms and our record of its published posts. A person handles it, and we will write back when it is done.

If you filled in an agent’s lead form and want your details removed, ask the agent, or write to us at the same address.

14

Cookies

Soldello sets only the cookies it needs to work, and there is nothing to consent to because there is nothing optional.

  • A session cookie that keeps you signed in.
  • Short-lived cookies holding the state value during a connection to an outside account, so the round trip cannot be forged.
  • A cookie recording that one of our administrators is viewing a workspace for support, which expires after four hours.

There are no third-party advertising, analytics or session-recording trackers anywhere on this site. No Google Analytics, no tag manager, no advertising pixels. The view and download counts a photographer sees are counted by us, on our own servers, and are tied to the order rather than to a person.

15

How long we keep it

By default, files are never deleted. Cloud retention is off until a photographer chooses a period, and the setting itself says so: “Never delete — files stay in the cloud indefinitely.”

A photographer may instead set a retention period of 1, 2, 3, 5 or 7 years. That clock measures inactivity, not age, and it restarts on the latest of: delivery, the property selling, the last time the gallery or listing page was viewed, and the last time anything was downloaded. A shoot from six years ago that somebody opened last week is not old.

Once an order passes its window, nothing is deleted on the first pass. A warning email goes out and a further 30 days must elapse before the files are deleted. That is a full month in which to download a copy or mark the order “keep forever”, which overrides the policy for that order regardless of the setting. Deletion at the end of it is permanent.

Separately, and regardless of the retention setting, delivered shoots move to colder storage to keep costs down — to Glacier around 30 days after delivery, and to Deep Archive after about twelve months. Nothing is lost. An archived gallery simply takes from a few minutes to around twelve hours to become downloadable again, and the gallery says so while it waits.

Records that are not files — accounts, client records, orders, audit and email events — are kept while the account is open, and afterwards for as long as we need them for tax, accounting and dispute purposes.

16

How we protect it

  • Every workspace is isolated at the database level by row-level security, so one photographer’s query cannot return another photographer’s rows.
  • Photograph links are signed and expire after fifteen minutes.
  • Social publishing tokens are encrypted with AES-256-GCM before they are stored.
  • Payment webhooks are rejected unless the signature verifies and the amount matches.
  • When one of our administrators views a workspace to help with a support request, it is recorded in the audit log against their own name, and the session expires after four hours.
17

Your choices and requests

Write to support@soldello.com to ask for a copy of the information we hold about you, to have it corrected, or to have it deleted. There is no self-service delete button today; these requests are handled by a person, and we will tell you what we can and cannot remove and why. Some records — a paid invoice, an audit entry — have to survive a deletion request for tax and accountability reasons.

Photographers can export their own data at any time, including a local backup of every file in a shoot.

We are a Florida business serving customers in the United States, and information is stored in the United States. Where a privacy law gives you rights we are subject to, we will honour them. If you believe we have got something wrong, tell us first and we will try to fix it.

18

Children

Soldello is a business tool and is not directed at children. We do not knowingly collect information from anyone under 13. If you believe a child has given us information, write to support@soldello.com and we will delete it.

19

Changes to this policy

When this policy changes we will update the date at the top of the page. If a change materially affects how we handle your information — a new category of data, a new purpose, a new provider — we will tell account holders by email before it takes effect.

20

Contact

Digilux HD LLC, d/b/a Soldello — Florida, United States. support@soldello.com