Summer Camp PhotosBook a conversation

Summer Camp Photos · Consent-first · Private per-child proofing · Early access · 2026

Camp photos with consent built in, not bolted on — parents see only their child, camps get an audit-ready record

Summer Camp Photos bundles consent intake, private per-child proofing, and transparent print fulfillment into one workflow. A parent grants permission by email, then immediately sees only their child’s photos and can order prints. Manual photographer tagging is the matching method — face-assisted matching is off by default and not used in this camp flow. No cloud storage library, no subscription fees to families. The camp gets an audit-ready consent record for every child — without managing a second compliance system. Early access — no pricing commitment, no signup, no live payments today.

Consent firstper-child, per-use, per-season, revocable — audit log included
One family, one galleryparents see only their child’s photos — no other child visible
Manual taggingphotographer tags each proof to the roster — face-assisted matching off by default, not used in this flow
90-day proofing windowproofs expire unless ordered — no long-term storage, no cloud library

The differentiator — consent as the engine of the ordering flow

A parent grants permission and immediately sees their child’s photos — consent and ordering are one flow, not two

Most camps handle consent as a separate step: a paper form collected at drop-off, or a checkbox on a registration form that no one checks after the fact. Photos end up on a shared drive, emailed in bulk, or posted to a platform where any parent can see any child. The camp has no record of what was consented, no way to enforce it photo by photo, and no audit trail if a parent asks what happened to their child’s image.

Summer Camp Photos treats consent as the mechanism that makes the ordering flow work. A parent receives a per-child consent request by email before the season begins. They grant or decline, and the platform records the exact grant — date, what was consented, which uses were permitted. After the shoot, that parent sees exactly one private gallery: their child’s photos, nothing else. The photographer uploaded tagged proofs; the tag matched to the consent record; and the gallery went live only for the consenting family. No other parent can navigate to it, see it, or order from it.

The camp director gets an audit log for free — built in, not added on. Every row shows the child name, the date consent was granted, and what was granted. If a parent revokes consent, the child’s proofs come down immediately and the revocation is logged. The camp ends the season with a consent record it can export, read, and keep, regardless of whether it continues with the platform the following year.

How it works

The camp photo season in four stages

Summer Camp Photos runs on a simple four-stage workflow: consent before the shoot, photographer upload after the shoot, the parent ordering window, and a clean season close. Every stage is described as it is built today.

Step 1 · Before the shoot — roster upload and consent collection

The camp director uploads the season roster: child names and parent email addresses. The consent engine sends a per-child permission request to each parent before the photographer arrives. Parents grant or decline consent for their child to be photographed, for the family to order prints, and for the camp to use low-resolution previews of consented images. The photographer sees a real-time consent roster before the shoot begins — an unconsented child is flagged at the name level, not discovered in post-processing. Consent intake is built and production-ready. Email delivery requires a configured provider key.

Step 2 · After the shoot — photographer uploads tagged proofs

After the shoot, the photographer uploads proofs tagged by child name or activity group. The platform matches each proof to the correct family’s private gallery — only the parents of the child in a photo can see that photo. No other family sees it. Manual tagging is the only matching method in this flow: each proof is matched to the roster by the photographer’s tag, and face-assisted matching is off by default and not used here. Unmatched photos are flagged in the photographer’s upload queue before the ordering window opens. Proofs are stored on our own systems, encrypted in transit, never shared with advertisers.

Step 3 · The ordering window — private proofing and parent print orders

Each family is notified when their child’s proofs are ready. They access a private gallery showing only their child’s images — download-disabled, order-enabled. A parent selects items, sizes, and quantities. Orders fulfil directly to the parent’s address. Proofs remain available for approximately 90 days from upload; proofs not ordered within that window expire and are removed. There are no subscriptions, no digital-library upsells, and no recurring fees to parents. The fulfillment engine is built; the charge rail is honest-off today.

Step 4 · Season close — records export, proofs expire, data handled cleanly

At season close, the director exports the full consent and order record: which children were consented, which proofs were uploaded, which families ordered, what the camp earned per activity group. This record is the camp’s, portable and readable without the platform. Proofs that were not ordered expire on schedule and are removed. A camp that does not continue takes its data with it. Consent can be withdrawn by a parent at any time; a revocation removes the child’s proofs from the active gallery immediately.

The full platform

Five engines — honest about what is built and what is coming

Every feature is labelled honestly: Built means the underlying engine is production-ready. In development means the surface, wire-up, or carrier integration is in active build. We do not claim otherwise.

Photographer proof upload & private parent proofing — one child, one family

After the shoot, the photographer uploads proofs tagged by child name or camp activity group. The platform matches each upload to the roster and makes it visible to exactly one family: the parents of the child in that photo. No family sees another child’s images. Downloads are disabled on the proofing interface — a parent sees a proof, taps to order, and the original file never moves to their device. Proofs are stored on our own systems, encrypted in transit, and never shared with advertising networks or data brokers. Manual photographer tagging is the only matching method in this product — each proof is matched to the roster by the photographer’s tag, not by a face scan. Face-assisted matching is off by default and is not used in this camp flow. Unmatched photos are flagged for the photographer to resolve before the ordering window opens. Proofs auto-expire approximately 90 days after upload unless the family has ordered from them. The proof upload and parent proofing engine are built and production-ready.

Proof upload and proofing engine built · manual tagging, no face scan in this flow

Print order fulfillment — per-print split, ships direct to parent

A parent orders prints from the private proofing interface. The order goes to the fulfillment engine: item type, size, quantity, and parent address. Prints ship directly to the parent — the camp never handles physical order fulfillment. Pricing is transparent per camp: the per-print cost and the camp’s revenue share are shown to the director before the season opens. The split is applied at the item level in the fulfillment engine — the camp’s share is calculated per order, not estimated at settlement. There are no subscription fees charged to parents, no digital-library upsell, and no auto-renewal. The camp earns a share of each print order; there are no upfront or per-child fees. The fulfillment engine is built and production-ready. The charge rail that accepts payment from a parent is honest-off — present in the platform, not enabled for live transactions today.

Fulfillment engine built · charge rail honest-off

Camp dashboard — roster, consent status, upload tracker, season records

The camp director sees the season in one view: roster rows with consent status (consented — pending — declined), the photographer’s proof upload progress per child, order counts per activity group, and an export of the full consent and order record for the camp’s own files. The consent audit log is always present: each row shows the child name, the date consent was granted, exactly what was granted, and any subsequent updates or revocations. An end-of-season export delivers the full record in a portable format the camp keeps regardless of whether they continue with the platform. The core consent and order records are built; the camp dashboard UI surfaces and the export flows are in active development.

Records built · dashboard UI and exports in development

White-label camp branding — camp name, logo, and email sender on every surface

Parents receive a consent request, a proof-ready notification, and an order confirmation that carry the camp’s own name and logo — not the platform’s. The proofing interface shows the camp name in the header. Fulfilment confirmation emails are sent under the camp’s configured name. The platform’s consent and payment rails run underneath; the family experience is the camp’s brand. The branding layer — logo, camp name, email sender configuration — is built and production-ready. Custom domain routing for the proofing interface is in active development.

Brand layer built · custom domain routing in development

Who uses it

Built for directors, photographers, and parents — three distinct workflows on one platform

For camp directors

A director uploads the roster and the consent engine handles the rest before the season opens. On picture day, the photographer’s roster shows which children are consented and which are not. After the shoot, the director sees proof upload progress per child in the dashboard. At season close, a full consent and order export goes to the camp’s own files. There is no second system to manage for consent and no spreadsheet to reconcile after the season. The pricing and camp revenue share are shown before the season opens — no surprises at settlement.

For photographers

A photographer sees which children are consented before arriving on site. After the shoot, bulk upload and tag-by-name-or-group handles large activity sessions. Unmatched photos are flagged in the upload queue before the ordering window opens — the photographer resolves them, not the camp admin. Manual tagging is the method — face-assisted matching is off by default and not used in this flow, so there is no biometric tooling to navigate: manual tagging is the method, and the platform is built around it. The photographer is notified when a family places an order.

For parents

A parent receives a consent request by email before the season begins. They decide, per child, what they are granting: family ordering only, or also camp use of low-resolution previews. After the shoot, they receive a notification and access a private gallery showing only their child’s photos. Download is disabled; ordering is the action. Prints ship directly to the parent’s address. Consent can be withdrawn at any time — revocation removes the child’s proofs from the gallery immediately. No subscription, no recurring fee, no account that persists beyond the ordering window.

What is built and what is coming — plainly

The engines are built. The charge rail is not live yet.

Built and production-ready today: the consent intake engine (roster upload, per-child permission request, real-time consent status, audit log); the proof upload and parent proofing engine (per-child private gallery, download-disabled, order-enabled, manual photographer tagging, unmatched-photo flagging, 90-day expiry); the print fulfillment engine (order intake, item-level split calculation, direct-to-parent shipment); and the white-label camp branding layer (logo, camp name, email sender configuration).

Not yet enabled for live use: the charge rail (the part that accepts payment from parents), the camp dashboard UI and season-export flows, and custom domain routing for the proofing interface. These are honest-off — present in the platform, not yet enabled. There is no live checkout here. No billing. No subscription. Camp directors deserve to know what is production-ready and what is still being built.

Connected to the platform

Camp photos are one part of the full camp and school-photo ecosystem.

Summer Camp Photos handles the photo capture and fulfillment season for camps. campmanager.software is the full camp operations platform: registration, rosters, billing, check-in and attendance, parent communications, health and safety, and the same consent substrate that governs who sees what and when. For school picture day, pictureday.software runs the same consent-first workflow on the school-year schedule. For homeschool co-ops and microschools wanting a keepsake, homeschool.photos brings the same group-aware portrait and yearbook engine to small programs. The publishing and yearbook platform for K–12 schools is at homeroom.software.

Early access · Camp directors and school-program coordinators

Book a conversation to see the current state honestly

Summer Camp Photos is in active development. We do conversations that show the current state honestly: how the consent engine sends a per-child permission request from a roster upload, how the photographer upload and private proofing experience works, how the fulfillment engine calculates the camp’s revenue share per order, and what the charge-rail timeline looks like. There is no pricing commitment and no signup. If it looks right for your camp season, we discuss what early access looks like.

To book: email [email protected].

FAQ

Common questions

What happens if a parent doesn’t consent?

The child’s name is flagged in the photographer’s roster before the shoot. The photographer knows not to include that child in the proofing batch. No photos of an unconsented child are uploaded into the system. The camp sees a real-time count of unconsented children per activity group before the shoot, so the photographer can plan accordingly. If a parent who initially declined later grants consent, the flag clears and they join the eligible roster. Consent can be updated at any time before the ordering window closes.

Can the camp use photos for its own marketing or website?

Only for consented children, and only when the parent specifically granted that use during intake. The consent form distinguishes between three permissions: photographed for family ordering only; photographed and available for camp use in low-resolution previews; and photographed and available for the camp’s public-facing marketing. A camp can only download and use a low-resolution preview if the parent’s consent record grants that specific use. If a parent said “family ordering only,” the camp receives nothing for that child. The consent record governs every downstream use — the platform enforces it, not a policy document.

How long are photos stored? What happens when proofs expire?

Proofs are available for approximately 90 days from upload. If a family orders during that window, the original proof is used to fulfil the order and is removed after fulfilment. If no order is placed within the 90-day window, the proof expires and the file is removed from our systems. There is no long-term photo archive, no cloud library, and no subscription that keeps a family’s photos alive indefinitely. Parents are sent a reminder before expiry. This is intentional: the platform is an order fulfilment service with a bounded proofing window, not a photo storage service. While a proof is live, it is stored on our own systems, encrypted in transit, and never sold or shared with outside companies or advertisers.

Is this COPPA-compliant? What about FERPA?

The platform is built with a COPPA-aware architecture: consent is collected per child from a parent or guardian before any photos are processed; photos are not accessible to any party other than the consenting family and the camp director; no child’s image is visible to other families or to the public; no behavioural tracking, face recognition, or advertising is applied. We do not claim a COPPA certification badge — that is not how COPPA works. We describe the architecture honestly: designed to comply. Summer camps that are school-run programs operate under FERPA’s directory information rules; the consent framework is designed to be compatible with those requirements. A camp with specific regulatory questions should review the consent architecture with its own counsel.

How does pricing work? What does the camp earn per print?

The per-print price, the camp’s revenue share, and the platform fee are shown to the director transparently before the season opens — not after the first order arrives. There are no hidden processing fees. No upfront costs, no subscription required to run a season, no per-child enrollment fee. The camp earns a share of each print order, calculated at the item level. The charge rail that accepts payment from parents is honest-off today — the fulfilment engine is built, but live payment is not yet enabled. Pricing detail is discussed in a conversation rather than published as a fixed public rate card, because camp seasons, group sizes, and item mixes vary.

Do you use face detection, smile detection, or AI auto-tagging?

In this camp product, matching runs on manual photographer tagging — the photographer tags each upload with the child’s name or activity group from the roster, and that tag drives which family sees which proof. Face-assisted matching is off by default and is not used in this flow. Biometric processing of minors’ images is a legally sensitive area — COPPA at the federal level and a growing body of state biometric privacy laws — so any face lane the wider platform offers is opt-in, off by default, permission-checked, kept only inside our own private system, and retention-bounded. Withdrawing consent stops the matching and marks the template due for destruction — and the step that actually destroys it is not finished, so we are not going to tell you a deletion has run when we cannot show it to you. Here, manual tagging is the method; it takes more photographer time and we think that trade-off is correct.

What can a camp actually use right now?

The platform is in active development. In a conversation we walk through the current state honestly: the consent intake engine (roster upload, per-child permission request, real-time consent status view for the director and the photographer); the proof upload and private proofing experience (per-child private gallery, download-disabled, order-enabled, manual tagging); and the fulfilment engine (print order, item-level split calculation, direct-to-parent shipment). None of those workflows involve live payments today. The camp dashboard and reporting surfaces are in active build. A conversation is the honest next step.

How does a photographer upload proofs?

After the shoot, the photographer logs in and uploads photos for the camp season. Each upload is tagged with the child’s name or activity group as it appears on the roster — a dropdown or a free-text match against the roster import. Bulk upload for large-group shoots is supported. The platform matches each tagged upload to the correct family gallery. Unmatched photos — where the tag does not resolve to a roster name — are flagged in the upload queue before proofs go live. The photographer resolves unmatched photos before the ordering window opens. The proof upload engine is built and production-ready.

What happens when a parent revokes consent?

Consent can be withdrawn by a parent at any time. A revocation removes the child’s proofs from the active family gallery immediately — the family can no longer see or order from those proofs. The camp director sees the revocation in the consent audit log with a time stamp. If an order was already placed before the revocation, the director is notified and must make a fulfilment decision. Revocation records are stored in the consent audit export alongside the original grant. Consent revocation is a real, working feature — not a policy statement.

When will the platform be available for live seasons?

The platform is in active development. The consent intake engine, proof upload and parent proofing, the fulfilment engine, and the white-label branding layer are built and production-ready. The camp dashboard and the charge rail that accepts payments are in active build. The charge rail is honest-off — present in the platform, not yet enabled for live transactions. There is no live checkout here, no billing, and no subscription commitment to make. The best next step is a conversation where we show the current state honestly and discuss what a pilot season looks like for your camp.