Consent intake at enrollment — COPPA-aware, per-child, audit-ready
Before the photographer arrives, the consent engine sends a per-child permission request to the parent email on the camp roster. The request is clear: it names the camp, the season, and what the parent is granting — whether photos may be taken for family ordering, whether the family wants to order prints, and whether the camp may use low-resolution previews of consented images for its own communications. One consent record per child per season, stored with a time-stamped audit trail the camp director can export. An unconsented child is flagged in the photographer’s roster before the shoot begins — not discovered in post-processing. Consent is affirmative, granular, per-use, and revocable. A parent who declines can update their answer; a parent who granted consent can revoke it at any time, and revocation removes the child’s proofs from the active gallery immediately. The consent intake engine is built and production-ready. The email delivery carrier is key-gated; delivery confirmation is honest-off without a configured provider key.
Consent engine built · email delivery carrier key-gated
Photographer proof upload & private parent proofing — one child, one family
After the shoot, the photographer uploads proofs tagged by child name or camp activity group. The platform matches each upload to the roster and makes it visible to exactly one family: the parents of the child in that photo. No family sees another child’s images. Downloads are disabled on the proofing interface — a parent sees a proof, taps to order, and the original file never moves to their device. Proofs are stored on our own systems, encrypted in transit, and never shared with advertising networks or data brokers. Manual photographer tagging is the only matching method in this product — each proof is matched to the roster by the photographer’s tag, not by a face scan. Face-assisted matching is off by default and is not used in this camp flow. Unmatched photos are flagged for the photographer to resolve before the ordering window opens. Proofs auto-expire approximately 90 days after upload unless the family has ordered from them. The proof upload and parent proofing engine are built and production-ready.
Proof upload and proofing engine built · manual tagging, no face scan in this flow
Print order fulfillment — per-print split, ships direct to parent
A parent orders prints from the private proofing interface. The order goes to the fulfillment engine: item type, size, quantity, and parent address. Prints ship directly to the parent — the camp never handles physical order fulfillment. Pricing is transparent per camp: the per-print cost and the camp’s revenue share are shown to the director before the season opens. The split is applied at the item level in the fulfillment engine — the camp’s share is calculated per order, not estimated at settlement. There are no subscription fees charged to parents, no digital-library upsell, and no auto-renewal. The camp earns a share of each print order; there are no upfront or per-child fees. The fulfillment engine is built and production-ready. The charge rail that accepts payment from a parent is honest-off — present in the platform, not enabled for live transactions today.
Fulfillment engine built · charge rail honest-off
Camp dashboard — roster, consent status, upload tracker, season records
The camp director sees the season in one view: roster rows with consent status (consented — pending — declined), the photographer’s proof upload progress per child, order counts per activity group, and an export of the full consent and order record for the camp’s own files. The consent audit log is always present: each row shows the child name, the date consent was granted, exactly what was granted, and any subsequent updates or revocations. An end-of-season export delivers the full record in a portable format the camp keeps regardless of whether they continue with the platform. The core consent and order records are built; the camp dashboard UI surfaces and the export flows are in active development.
Records built · dashboard UI and exports in development
White-label camp branding — camp name, logo, and email sender on every surface
Parents receive a consent request, a proof-ready notification, and an order confirmation that carry the camp’s own name and logo — not the platform’s. The proofing interface shows the camp name in the header. Fulfilment confirmation emails are sent under the camp’s configured name. The platform’s consent and payment rails run underneath; the family experience is the camp’s brand. The branding layer — logo, camp name, email sender configuration — is built and production-ready. Custom domain routing for the proofing interface is in active development.
Brand layer built · custom domain routing in development