Consent collection and roster-driven capture — QR/barcode matching, red-flag detection
Before picture day opens, every parent on the school roster receives a consent request. The photographer receives a session-day consent list: who has opted in, who has opted out, and who has not yet responded. A student who has not consented is excluded from the shared gallery and yearbook export at the data layer — not by a reminder email, by code. On picture day, each student is matched to their portrait via a QR code or barcode on their session card. The match is recorded against the roster entry, not inferred by face. No facial recognition and no face match is used in this matching workflow — portrait-to-student matching is a QR/barcode read at capture, not a face comparison. Any face-processing capability is off by default and would run only under a separate, explicit per-family opt-in. Red-flag detection surfaces unmatched photos (a shot with no corresponding roster match) and missing students (a roster entry with no captured shot) before the session closes — so the photographer resolves both before leaving the school. The consent gate, roster-driven capture, QR/barcode matching, and red-flag detection are built and production-ready.
Built · production-ready · no face scan
Private parent proof galleries and ordering — gallery built, payment honest-off
After session upload, each consented student’s proofs are available to their family in a private gallery accessible by roster name. There is no public gallery, no browsable feed of student portraits, and no face-based search: a family navigates to their child’s proofs using the name registered on the school roster. Unconsented students appear in no gallery. The ordering interface presents the photographer’s package options — print packages, digital downloads, and any add-ons configured for the session. The proof gallery is built and production-ready, as is the ordering interface, on the platform’s commerce substrate. The payment rail is honest-off: it accepts no live family transactions today — present in the platform, not enabled for live payments. There is no live checkout and no billing active on the platform right now.
Gallery built · ordering interface built · payment honest-off
Photographer earnings and school fundraising leg — exact-cent split engine, charge rail honest-off
Every picture-day session on the platform carries three financial legs: the photographer’s earnings leg (the larger share), a school fundraising leg (a defined share of net proceeds flowing directly to the school), and the platform’s own take — the residual left after those legs, computed last, earned on the same orders, not skimmed off the top. The split engine divides proceeds with exact-cent precision: processing and lab costs come off gross proceeds first — the real, external costs of the sale — before any split is calculated. The photographer and school legs are each a share of the net that remains; the platform’s residual is simply what is left after those legs. A largest-remainder reconciliation pass ensures the total distributes to the exact cent, with no penny rounded silently in the platform’s favour and every leg — including the platform’s residual — visible in the breakdown. The photographer sees the projected distribution before the charge rail runs. The split engine is built and production-ready. The charge rail that moves money is honest-off: it exists in the platform but is not enabled for live transactions today.
Split engine built · charge rail honest-off
Yearbook export — PSPA/SPOA format, consent-audited, bulk metadata
At session close, the yearbook export produces every consented portrait in PSPA/SPOA format — the industry-standard delivery specification used by yearbook production vendors — alongside a bulk metadata file that maps each portrait to its roster entry: student name, grade, teacher, and class. Only students with a completed consent record appear in the export. The school or yearbook adviser receives an irrefutable consent audit log alongside the image files, so the yearbook goes to print with documented proof of consent for every student portrait included. The export also generates the red-flag summary: unmatched shots and missing students, so the yearbook adviser knows what to schedule for retakes. The export, consent-audit log, bulk metadata, and retake flag are built and production-ready. PNG-alpha cutout delivery alongside PSPA JPG is available where the school-choosable backgrounds engine is configured.
Built · PSPA/SPOA format · consent-audited
Print fulfillment — order substrate built, outside-lab routing in active development
The fulfillment substrate manages the order handoff from a family’s purchase to print production: order line-items, package configuration, print-size specs per item, and order status tracking per student. The order model and package configuration layer are built and production-ready on the platform’s commerce substrate. Outside-lab routing is in development: directing orders to a photographer’s preferred third-party print lab uses the PhotoLabProvider seam, which defines the interface, and active wire-up to named outside labs is in development. On-platform fulfillment routing is in active development alongside the payment rail. No live print orders are being routed today.
Order substrate built · lab routing in development