Privacy Policy
Shotly Ltd Company Number: 16974198
Effective date: 25th May 2026 Last updated: 3rd June 2026
1. Introduction
Shotly Ltd ("Shotly", "we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, how we protect it and what rights you have in relation to it.
Shotly Ltd is registered with the Information Commissioner's Office (ICO) in the United Kingdom as a data controller. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy applies to all users of the Shotly platform accessible at shotly.io and within the Shotly application (the "Platform").
By creating an account and using the Platform you confirm that you have read and understood this Privacy Policy.
2. Who we are
Shotly Ltd Company Number: 16974198 Registered in England and Wales Contact: support@shotly.io
For all data protection enquiries or to exercise your rights under UK GDPR please contact us at support@shotly.io.
3. What data we collect
3.1 Account information When you create an account we collect:
Your full name
Your email address
Your password (stored in encrypted form, never in plain text)
Your account type and plan information
The date and time your account was created
3.2 Payment information All payment processing is handled by our third party payment provider Stripe. Shotly does not store your card details, bank account information or any other payment credentials directly. Stripe's privacy policy governs the handling of your payment data and is available at stripe.com/privacy.
We do retain records of:
Your subscription plan and billing cycle
Payment history and transaction dates
Invoice records
3.3 Production content When you use the Platform you may create, upload or store:
Scripts and written content
Shot lists, storyboards and mood boards
Schedules, call sheets and breakdowns
Budgets and invoices
Contacts, locations and production documents
Files uploaded to the Asset Vault
Voice notes and messages sent via Team Chat
This content belongs entirely to you. See Section 7 for full details of how we handle your production content.
3.4 Usage data We may collect technical data about how you use the Platform including:
Pages and features accessed
Time and duration of sessions
Device type, browser type and operating system
IP address
Error logs and performance data
This data is used to maintain, improve and secure the Platform and is not used to profile you for advertising purposes.
3.5 Communications If you contact us for support or any other reason we will retain a record of that communication including your name, email address and the content of your message.
3.6 Google Workspace data If you choose to connect your Google Workspace account we may access data from your Google account in accordance with the permissions you grant. See Section 9 for full details of how we handle Google Workspace data.
4. How we use your data
We use your personal data for the following purposes and on the following legal bases under UK GDPR:
4.1 To provide the Platform Legal basis: Performance of a contract
Creating and managing your account
Processing your subscription and payments
Enabling you to create and manage your production projects
Providing AI features within your project
Enabling team collaboration on Studio plans
4.2 To communicate with you Legal basis: Performance of a contract and legitimate interests
Sending account verification codes
Sending subscription confirmation and renewal notifications
Responding to support requests
Notifying you of material changes to our Terms of Use or Privacy Policy
4.3 To maintain and improve the Platform Legal basis: Legitimate interests
Monitoring Platform performance and uptime
Identifying and fixing bugs and errors
Developing new features and improvements
Ensuring the security of the Platform
4.4 To comply with legal obligations Legal basis: Legal obligation
Maintaining financial records as required by law
Responding to lawful requests from regulatory or law enforcement authorities
5. What we never do with your data
We want to be completely clear about how we do not use your data:
We never sell your personal data to any third party
We never share your production content with other users without your explicit action
We never use your Content to train AI models
We never use your data for targeted advertising
We never share your data with advertisers
We never access your Content except where strictly necessary to provide technical support you have explicitly requested
6. Who we share your data with
Shotly does not sell or rent your personal data. We share limited data with the following trusted third party service providers solely for the purpose of operating the Platform:
Stripe — payment processing. Your payment data is handled directly by Stripe in accordance with their privacy policy.
Cloud infrastructure providers — secure storage and hosting of Platform data. All data is stored on cloud based infrastructure with appropriate security measures in place.
Rewardful — affiliate and partner programme tracking for approved partners only. Partner tracking data is limited to referral link clicks and subscription conversions and does not include your production content.
All third party providers are carefully selected and are required to handle your data securely and in accordance with applicable data protection law.
7. Your production content
7.1 You own your content All scripts, budgets, shot lists, call sheets, schedules, mood boards, storyboards, contacts, locations, files and any other material you create or upload within the Platform belongs entirely to you. Shotly claims no ownership over your Content.
7.2 How we process your content Your Content is processed solely to provide the Platform to you. This includes storing your Content securely, displaying it to you and your invited collaborators and enabling the AI features within your project.
7.3 Confidential productions Shotly recognises that your Content may include commercially sensitive, confidential or legally protected material. Your Content is never shared with other users, disclosed to third parties or accessed by Shotly staff except where you have explicitly requested technical support.
7.4 AI and your content All AI features within the Platform operate exclusively within your individual project. Your Content is never used to train AI models and no information from your project is shared with other users or third parties through AI processing.
7.5 Studio plan data arrangements Studio plan customers who require bespoke contractual data protection arrangements — for example in connection with large scale commercial productions or enterprise client requirements — may contact us at support@shotly.io to discuss their requirements.
8. Data retention
8.1 Active accounts We retain your personal data and Content for as long as your account remains active.
8.2 Account deletion When you request account deletion your account and all associated Content will be permanently deleted within a few hours of your request. This includes all scripts, budgets, shot lists, call sheets, schedules, mood boards, storyboards, contacts, locations, files and any other Content associated with your account. This action is irreversible and cannot be undone.
8.3 Financial records Certain financial records including payment history and invoice data may be retained for up to six years following the end of your subscription in accordance with our legal obligations under UK tax and accounting law.
8.4 Support communications Records of support communications may be retained for up to two years following the resolution of your support request.
9. Google Workspace integration
9.1 Optional and consent based The Google Workspace integration is entirely optional. You are under no obligation to connect your Google account and your use of the Platform is not conditional on doing so.
9.2 What we access When you connect your Google Workspace account and grant permissions Shotly may access the following Google services depending on the permissions you choose to grant:
Gmail — to send call sheets, production updates and emails directly from Shotly
Google Drive — to access, import and export production files
Google Docs — to import scripts and production documents into Shotly
Google Sheets — to import and export budgets and schedules
Google Tasks — to sync tasks with your Shotly task board
9.3 You control your permissions You choose exactly which Google services Shotly has access to. You can grant or revoke individual permissions at any time from your integrations settings within the Platform.
9.4 How we use Google data Data accessed through your Google Workspace integration is used solely to provide the integration features within the Platform. It is not shared with third parties, used for advertising or used to train AI models.
9.5 Disconnecting You may disconnect your Google Workspace integration at any time from your integrations settings. Upon disconnection Shotly's access to your Google account is revoked immediately. Shotly may delete previously synced Google Workspace data following disconnection, subject to operational, legal, backup and security requirements.
9.6 Google's privacy policy Your use of Google Workspace services is also governed by Google's Privacy Policy available at policies.google.com/privacy. Shotly is not responsible for Google's data handling practices.
9.7 Availability Google Workspace integration is available on Pro and Studio plans only.
10. Security
10.1 Encryption All connections to the Platform are protected by SSL encryption. Data transmitted between your device and the Platform is encrypted at all times.
10.2 Storage security Your data is stored on secure cloud based infrastructure with appropriate technical and organisational security measures in place to protect against unauthorised access, loss or disclosure.
10.3 Access controls Access to your Content within Shotly is strictly limited to you and the collaborators you explicitly invite to your projects. Shotly staff do not access your Content except where strictly necessary to provide technical support you have explicitly requested.
10.4 Payment security All payment data is handled directly by Stripe and is never stored on Shotly's systems. Stripe is PCI DSS compliant.
10.5 Breach notification In the event of a personal data breach that is likely to result in a risk to your rights and freedoms we will notify you and the ICO in accordance with our obligations under UK GDPR.
11. Your rights under UK GDPR
As a data subject under UK GDPR you have the following rights in relation to your personal data:
11.1 Right of access You have the right to request a copy of the personal data we hold about you.
11.2 Right to rectification You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
11.3 Right to erasure You have the right to request that we delete your personal data. You can exercise this right by deleting your account from within the Platform or by contacting us at support@shotly.io.
11.4 Right to restriction of processing You have the right to request that we restrict the processing of your personal data in certain circumstances.
11.5 Right to data portability You have the right to receive your personal data in a structured, commonly used and machine readable format and to transmit that data to another controller where technically feasible.
11.6 Right to object You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis.
11.7 Rights related to automated decision making You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you.
11.8 How to exercise your rights To exercise any of your rights please contact us at support@shotly.io. We will respond to your request within one month in accordance with UK GDPR requirements. We may need to verify your identity before processing your request.
11.9 Right to complain If you are unhappy with how we have handled your personal data you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.
12. Cookies
The Platform uses cookies and similar technologies to maintain your session, remember your preferences and analyse usage patterns. A full breakdown of the cookies we use is available in our Cookie Policy at shotly.io/cookies.
You can manage your cookie preferences through your browser settings at any time.
13. Children's privacy
The Platform is not intended for use by children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has created an account please contact us at support@shotly.io and we will delete the account and associated data promptly.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email to the address associated with your account or by a prominent notice within the Platform. The updated policy will include a revised effective date. Your continued use of the Platform following notification of changes constitutes your acceptance of the updated policy.
15. Contact and data controller details
If you have any questions about this Privacy Policy or wish to exercise your data protection rights please contact us at:
Shotly Ltd Company Number: 16974198 ICO Registered support@shotly.io