photographer.softwareBook a conversation

photographer.software · Studio-tier school photography platform · Early access · 2026

The platform a studio runs school picture day on at scale — with a consent story it can prove to any district

photographer.software is the operating platform for studios that shoot school picture day at scale: multi-school branded parent stores (your name, not ours), a per-school commission ledger with rep assignment and projected splits, roster-driven capture with consent state at the student level, and a PSPA/lab fulfillment seam that closes the job. The consent substrate is the lead: every student photo carries its parental consent state, revocation is immediate, and the studio can show a district the consent audit log in seconds. Early access — no pricing commitment, no signup, no live payments today.

Consent-firstevery photo carries consent state — revocation is immediate, not batch-cleared
Commission ledgerper-school rep assignment, projected split, studio leg vs. school fundraising leg
Studio-branded storesyour name on every parent store — not the platform’s
Honest-offlive checkout and payouts exist in the platform; not enabled for live transactions today

How it works

The picture-day season in four stages

photographer.software runs on the real picture-day workflow: school setup and consent collection before the day, roster-driven capture on the day, proof delivery and parent ordering after, and lab fulfillment with yearbook export to close. Every stage is described as it is built today.

Step 1 · Before picture day — school setup and consent collection

The studio configures each school in the platform: roster upload, photographer assignment, session date, and the consent collection window. Consent outreach goes to families before picture day: each family receives a consent form tied to their student’s record covering depiction (which uses of the photo they permit) and marketing opt-in (whether the family wants to receive the digital proof and ordering information). A student whose family has not consented is flagged before the photographer arrives. No consent, no photo that enters the delivery chain. The studio sees consent coverage by school before the day begins. The platform owns the roster-to-consent linkage; the studio does not manage this in a spreadsheet.

Step 2 · Picture day — roster-driven capture and real-time matching

On picture day, the photographer works from the roster. QR-code or barcode matching ties each photo to a student record at the moment of capture: the photographer scans the student’s ID, takes the photo, and the match is recorded. Unmatched photos surface immediately as a red-flag list; the photographer resolves them before the session ends. Students flagged as opted-out are visible in the roster so the photographer knows before the student walks in, not after a post-shoot cull. The session is complete when every photo is matched and every unmatched photo is resolved or noted.

Step 3 · Proof delivery and parent ordering

After the shoot, proofs are uploaded to the studio account and routed to each student’s family portal. A family sees only their child’s photo — not the class gallery, not a grid of every student’s face. EXIF and device metadata are stripped before any photo reaches the parent portal. The parent can view the proof, select a product from the studio’s catalog (wallets, portrait packages, digital downloads), and place an order. The parent store carries the studio’s brand. The ordering flow and proof delivery are built and production-ready. The checkout that accepts live payment is honest-off today.

Step 4 · Lab fulfillment and yearbook export

Orders route to the lab through the PhotoLabProvider fulfillment seam: ship-to-photographer or direct-to-family. PSPA/SPOA export produces the delivery file labs and school systems expect. The yearbook export delivers consent-confirmed photos in the format the yearbook workflow requires: only photos with yearbook-use consent included, captioned correctly, with the consent audit record attached. The commission ledger updates as orders ship: the studio leg, the school fundraising leg, and the platform’s residual are visible to the studio owner and the assigned rep. Lab fulfillment and yearbook export are built and production-ready.

The full platform

Five engines — honest about what is built and what is coming

Every feature is labelled honestly: Built means the underlying engine is production-ready. In development means the surface, wire-up, or payment rail is in active build. We do not claim otherwise.

Per-school commission ledger — rep assignment, projected split, studio earnings

A studio that runs dozens or hundreds of schools needs a real commission ledger, not a spreadsheet reconciled at year-end. The commission ledger tracks each school as a separate record: which rep is assigned to it, what the agreed commission structure is, what the projected split looks like before orders ship, and what the studio’s net looks like after the school fundraising leg is separated. A rep assigned to a school can see their pipeline for that school. A studio owner can see the full portfolio. The split engine applies three rules in order: processing and lab costs come off the gross first; the studio leg and the school fundraising leg are each a share of the net that remains; and the platform’s take is the residual left after those legs — earned on the same orders, computed last, not skimmed off the top. The studio leg and the school fundraising leg are maintained as separate ledger entries, never commingled. The commission ledger and split engine are built and production-ready. The charge rail that moves money — the live payout to the studio — is honest-off: present in the platform, not enabled for live transactions today.

Ledger + split engine built · live payouts honest-off

Multi-school branded parent stores — the studio’s name, not ours

Each school gets a parent store branded as the studio — the studio’s name, the studio’s color, the studio’s product catalog. A parent ordering prints from Lincoln Elementary sees the studio’s brand; they do not see the platform. The product catalog is studio-configured: wallets, portrait packages, digital downloads, and the options the studio actually offers, not a generic template list. The parent store substrate and catalog management are built and production-ready. The checkout interface is honest-off — it accepts no live payment from families today; present in the platform, not enabled for live transactions. There is no live storefront checkout in operation right now; we say so directly because studio owners need to know the difference between what is built and what is live.

Store substrate built · live checkout honest-off

Roster-driven capture, PSPA export, and lab fulfillment — the full workflow

The shoot workflow starts with the school roster: students are pre-loaded before picture day so the photographer matches a photo to a student record at the moment of capture, not in post. QR-code and barcode matching tie the photo to the correct student on the spot; unmatched photos surface as a red-flag list for the photographer to resolve before proof delivery. After the shoot, PSPA/SPOA export produces the delivery format labs and school systems expect. The PhotoLabProvider fulfillment seam handles order routing to the print lab: ship-to-photographer or direct-to-family. Retake management is built into the workflow: retake flags carry forward from the original session, and the studio sees which students are scheduled for a retake before the second day arrives. Roster-driven capture, PSPA export, retake management, and the PhotoLabProvider fulfillment seam are all built and production-ready.

Roster capture + PSPA export + fulfillment seam built

School admin portal — consent dashboard, delivery status, fundraising leg

The school admin portal gives a principal or yearbook coordinator a real-time picture of the session: consent coverage by homeroom (what percentage of students have a consent decision on file), delivery status (which photos are in proof, which are ordered, which are shipped), and the school’s fundraising leg from the split engine. A consent audit export is available for FERPA-aware record-keeping: a log of which student photos carry what consent state, when consent was recorded, and when any change occurred. The platform does not claim FERPA compliance as a certified badge — it says FERPA-aware architecture: every photo access is logged, consent state is tied to the student record, and the export is available on request. The admin portal and consent audit export are built and production-ready.

Admin portal + consent audit export built

Who uses it

Built for studios, transparent to schools, private for families

For studios

A studio that shoots dozens of schools needs more than a file-upload tool. photographer.software gives the studio a real operating platform: per-school configuration (roster, session date, photographer assignment, consent window), a commission ledger with rep assignment and projected split per school, a multi-school branded parent store where every store carries the studio’s name, and a PSPA/lab fulfillment seam that closes the job without a manual export step. The studio sees the full portfolio in one account. A rep sees their assigned schools. The commission ledger tracks the studio leg and the school fundraising leg separately.

For schools

A principal or yearbook coordinator gets a school admin portal with a real picture of the session: consent coverage by homeroom before picture day, delivery status as orders move from proof to ordered to shipped, the school’s fundraising leg from the split engine, and the consent audit export for FERPA-aware record-keeping. The school does not need to ask the studio for a consent summary — it is in the portal, tied to the session record. The platform does not claim FERPA compliance as a certified badge; it says FERPA-aware architecture: access is logged, consent is tied to the student record.

For families

A parent sees only their child’s photo — not a class gallery, not a grid of every student. The parent store carries the studio’s brand, not the platform’s. A family can view the proof, select products from the studio’s catalog, and place an order. EXIF and device metadata are stripped before any photo reaches the parent portal. Consent is affirmative: a family consents to specific uses, not to everything at once. A family can revoke consent at any time; the photo is removed immediately. No ad network, no behavioral tracking, no data broker integration. The family’s data is never sold.

The split-payment model — studio leg, school fundraising leg, transparent family cost

No markup games. The math is visible to the studio, the school, and the family — in the same system.

The split engine applies three rules in order. First, processing and lab costs come off the gross — the real, external costs of the sale, not a platform charge. Second, the studio leg and the school fundraising leg are each a share of the net that remains: a share of what is left after those costs, not a share of the gross. Third, the studio leg and the school fundraising leg are maintained as separate ledger entries: they are never commingled, and each party sees their own number. The platform’s own take is the residual left after those legs — earned on the same orders, computed last, not a fee skimmed off the top.

The family sees the exact per-item price at the parent store. The studio sees the projected split before orders ship and the actual split as they do. The school sees the fundraising leg in the admin portal in real time. The studio and school each see their own leg to the cent; the platform’s residual is simply what remains after those legs on the same orders. The split engine is built and production-ready. The charge rail that moves the money is honest-off: not enabled for live transactions today.

Privacy and data posture — what we do and what we do not do

Student photos in our own private system. No ad networks. No data brokers. No behavioral tracking.

Student photos run in our own private infrastructure, encrypted in transit and at rest. Photos are never sold or shared with outside companies for profit. Photos are never used in platform marketing or advertising without explicit per-family opt-in. EXIF and device metadata are stripped before any photo reaches the parent portal. A parent can request deletion of their child’s photos and that request is honored: photos removed from proof delivery, the parent portal, and pending lab exports. Unconsented student photos do not enter the delivery chain.

Face-matching is off by default. It requires opt-in at the studio level and at the school level before it runs for any session. When it runs, the system produces a suggested roster match for the photographer to confirm; what the studio keeps is the confirmed roster link to the student record. We do not say “no face data ever” — the optional match assist processes image data to produce the suggestion. We say what is true and controllable: it is off by default, requires opt-in at both the studio and school level, and no face-match runs for any session without both.

No ad network integration. No data broker integration. No behavioral tracking of families or students. The platform is not a social platform and does not build searchable minor profiles.

What is built and what is coming — plainly

The engines are built. The charge rail is not live yet.

Built and production-ready today: the consent substrate (per-student consent state, revocation, audit log, affirmative per-use); roster-driven capture (QR/barcode matching, unmatched-photo red flags, consent state at the student level); PSPA/SPOA export; the PhotoLabProvider fulfillment seam (ship-to-photographer or direct-to-family); retake management; the commission ledger and split engine (per-school rep assignment, costs-off-gross-first, studio leg / school fundraising leg as a share of the net, platform residual computed last, separate ledger entries); the parent store substrate and catalog management (studio-branded, studio-configured products); and the school admin portal with consent audit export.

Not yet enabled for live use: the payment rail (the part that moves money), live storefront checkout for families, live payouts to studios and reps, and live carrier delivery for communications. These are honest-off — present in the platform, not enabled for live transactions. There is no live checkout here. No billing. No active subscription. We say so directly because studio owners deserve to know what is production-ready and what is still being enabled.

Connected to the school platform

The studio runs the shoot. The school publishes the yearbook. Every student deserves to be in it.

photographer.software handles the studio side: consent collection, roster-driven capture, branded parent stores, commission ledger, PSPA export, and lab fulfillment. homeroom.software is the school publishing platform: the multi-surface editor for yearbook, newspaper, newsletter, and playbill. The yearbook export from photographer.software delivers consent-confirmed photos in the format the homeroom.software editor expects. photog.software is the solo photographer tier: the same engine scoped to a single photographer who shoots a handful of schools and wants the whole job in one tool. pictureday.software is the school admin tier: the platform for admins and PTA coordinators running their own picture day workflow, with photographer check-in, retakes, and the same consent substrate. studentphoto.id is the student photo identity layer: the consent dashboard and granular per-use family controls.

Early access · Studio owners, studio managers, lead photographers

Book a conversation to see the current state honestly

photographer.software is in active development. We do conversations that show the current state honestly: the consent substrate (consent state at the student level, revocation, audit log), the commission ledger (rep assignment, projected split per school, studio leg vs. school fundraising leg), the branded parent store configuration, the PSPA export, and the PhotoLabProvider fulfillment seam. None of those involve live payments today. There is no pricing commitment and no signup. If it looks right for your studio, we discuss what early access looks like.

To book: email [email protected].

FAQ

Common questions

What does “consent-first, not compliance-after” mean in practice?

Most picture-day platforms treat parental consent as a legal checkbox: a permission slip collected at enrollment that nobody checks when an order ships. This platform treats consent as a data-layer rule: every photo carries its consent state, and the engine reads that state before a photo is displayed, included in a proof, exported to a lab, or included in a yearbook. A family that revokes consent gets an immediate result — the photo disappears from every surface, including pending lab exports — not a result that clears in the next batch run. A studio can produce the consent audit log for any session in seconds. Consent is affirmative and per-use: a family that consented to yearbook use has not consented to digital downloads or event gallery sharing. Silence is never treated as consent.

Is the live payment checkout available? Can families order and pay now?

Not yet. The parent store substrate, the product catalog management, the order management system, and the split-payment engine are built and production-ready — the ordering workflow, the consent checks, and the ledger math are all there. The checkout interface that accepts live payment from families is honest-off: it exists in the platform but is not enabled for live transactions today. There is no live billing and no active subscription. When the charge rail is enabled (a founder-gated decision), studios will be notified. The CTA here is “book a conversation,” not “sign up and pay.”

How does the commission ledger work for a multi-school studio?

Each school is a separate ledger record: the assigned rep, the commission structure for that school, the projected split before orders ship, and the actual split as orders are fulfilled. The split engine applies three rules: processing and lab costs come off the gross first, the studio leg and the school fundraising leg are each a share of the net that remains (never a share of the gross, which would overstate every leg), and the platform’s take is the residual left after those legs — earned on the same orders, computed last. The studio leg and the school fundraising leg are recorded as separate entries, never commingled. A rep sees their pipeline per school. The studio owner sees the full portfolio. The commission ledger and split engine are built. The live payout to the studio is honest-off while the charge rail is being enabled.

What is the school fundraising leg? How does the school earn from picture day?

Picture day can include a fundraising component for the school: a defined share of each order’s net proceeds — the net after processing and lab costs come off the gross — goes to the school’s account. The platform’s own take is the residual left after the studio and school legs, earned on the same orders, not a fee skimmed off the top. The split is configured per school, not a flat platform default. The school admin portal shows the fundraising leg in real time as orders come in. The studio leg and the school fundraising leg are separate entries in the ledger from the first order. A principal or PTA coordinator does not need to trust the studio’s end-of-year report — the split is visible to both parties in the same system. The split engine is built. The charge rail that moves the money is honest-off.

How is face-matching used? Is there a face database?

Face-matching (matching a captured photo to a student in the roster by face similarity) is an optional assist, off by default for every school. A studio enables it per school, and the school enables it per session. No face-match feature runs without both. When it runs, the system produces a suggested roster match for the photographer to confirm; what the studio keeps after confirmation is the confirmed roster link to the student record. Photos are stored in our own private system, encrypted in transit, and never sold or shared with third parties for profit. We do not claim “no face data ever” because the optional match assist processes image data to produce the suggestion. We do say what is true and controllable: it is off by default, opt-in at both the studio and school level, and no face-match runs for any session without both.

How does the multi-school branded store work? Will parents see the platform’s name?

No. Each school’s parent store is branded as the studio: the studio’s name, color, and product catalog. A parent ordering from Lincoln Elementary sees the studio, not the platform. The store substrate and catalog management are built on the platform’s commerce layer. The studio configures what products appear — wallets, portrait packages, digital downloads, the combinations the studio actually offers — not a generic template list. The storefront checkout that accepts live payment is honest-off today. The white-label posture (studio brand, not platform brand) is a design constraint, not an add-on feature.

What does the school admin see? What can a principal or yearbook coordinator access?

The school admin portal shows consent coverage by homeroom (the percentage of students with a consent decision on file before the session), delivery status as orders move from proof to ordered to shipped, the school’s fundraising leg from the split engine, and the consent audit export for FERPA-aware record-keeping. A principal does not need to ask the studio for a consent summary — it is in the portal, tied to the session record. The consent audit export is a log of which student photos carry what consent state, when consent was recorded, and when any change was made. The platform does not claim FERPA compliance as a certified badge; it says FERPA-aware architecture: access is logged, consent is tied to the student record, and the export is available on request.

What is the photog.software sibling? Is this the same product?

photographer.software is the studio-tier product: multi-school operations, rep assignment, commission ledger, a full portfolio of schools under one studio account. photog.software is the solo or small-shop tier: the same engine scoped to a single photographer who shoots a handful of schools and wants the whole job in one tool without a rep ledger or multi-brand store configuration. The consent substrate, roster capture, PSPA export, and fulfillment seam are the same across both. The studio tier adds the commission ledger, the multi-school branded store configuration, and the rep management layer.

How is minor student data handled? What is the privacy posture?

Student photos run in our own private infrastructure, encrypted in transit and at rest. Photos are never sold or shared with outside companies for profit. Photos are never used in marketing or advertising without explicit per-family opt-in. A parent can request deletion of their child’s photos and that request is honored — photos removed from proof delivery, parent portal, and pending lab exports. Unconsented student photos do not enter the delivery chain: no consent, no proof, no order. EXIF and device metadata are stripped before any photo reaches the parent portal. No behavioral tracking, no ad network, no data broker integrations. The platform is not a social platform or a searchable minor profile directory.

What can a studio actually use right now?

The platform is in active development. In a conversation we walk through the current state honestly: the roster-driven capture workflow (student matching, unmatched-photo red flags, consent state at the student level), the school admin portal (consent coverage by homeroom, delivery status), the commission ledger (rep assignment, projected split per school, studio leg vs. school fundraising leg), the PSPA export, and the PhotoLabProvider fulfillment seam. None of those involve live payments today. A conversation is the honest next step — we show what is built, what the charge-rail timeline looks like, and what early access means for a studio.

When will the platform be available for live use?

The consent substrate, roster-driven capture, PSPA export, PhotoLabProvider fulfillment seam, commission ledger, split engine, school admin portal, and consent audit export are built and production-ready. The payment rail (the part that moves money), live storefront checkout, and live payouts are honest-off — present in the platform, not yet enabled for live use. There is no active billing and no subscription today. We say so directly because studio owners deserve to know what is production-ready and what is still being enabled. The best next step is a conversation where we show the current state honestly and discuss what early access looks like for your studio.