Albums and orders
Track gallery orders through payment and production
Product documentation · Reviewed
The gallery shop separates digital downloads, printed products, albums and paid access extensions. Each order freezes the selected files, quantities, crop or approved album revision and current prices before checkout opens.
Buy a selected digital package
A studio can offer a fixed number of selected files at a set price, with either web-size or full-resolution delivery. Choose exactly the number shown before checkout. The server validates the selection, resolution and saved price. A later catalog price change or archived package does not rewrite an existing checkout or paid receipt. A web-size receipt cannot unlock full-resolution files.
Review the actual order
For example, choose a photograph for an 8 × 10 print, adjust its crop and inspect the result before opening checkout. Low-resolution originals are rejected at the selected size. An album order uses an approved design at the product’s dimensions; one album design can have multiple copies.
The current studio catalog is configured through exact product mappings and retail prices. Physical products remain unavailable until the lab mapping’s fingerprint is certified and fulfillment is enabled. The storefront browses the studio’s certified print, wall-art, card and keepsake categories. The catalog does not imply support for every lab SKU.
The payment provider collects the delivery address and calculates applicable configured tax. The paid receipt must match the connected studio account, frozen order, currency and final amount. Repeating the same checkout request keeps the original order; changing the cart requires a new request.
Payment is one milestone
A paid physical order becomes queued for production. Private production files are prepared, a lab quote is checked against the order’s revenue, and the workspace needs an approved fulfillment spending allowance before submission. The system holds requests that exceed that allowance or cannot be verified.
The order page distinguishes payment status from imported, submitted, accepted and shipped production states. Multiple shipment updates are merged so a later package does not replace an earlier tracking number. Shipped does not establish delivery to the customer.
If a lab request loses its response, use Reconcile with the existing confirmation rather than retrying production blindly. Provider simulator tests exercise these paths; real payment, lab certification and live webhook rehearsal are activation requirements.
Handle a refund deliberately
The studio can request a refund and review the verified payment-provider result. A refund stops unsubmitted production where possible and revokes purchased download access. It does not cancel an order the lab may already be producing. Contact the lab separately when the order has reached that stage, and reconcile uncertain requests before creating replacements. Verified gallery payments append immutable cash entries for the accounting report. Refund observations append only the newly confirmed amount: duplicate receipts and older cumulative totals do not add a second deduction. Entries use the studio’s private workspace and a fixed reporting period. Processing fees and the tax portion of a refund stay unknown until verified; they are not assumed to be zero. These entries record actual confirmed cash, not an estimate of production profit.
Included albums and cover choices
The album workspace can grant an allowance to a specific recipient email. The recipient must verify that email in the gallery before seeing or spending the allowance; entering an email at checkout alone is not proof. Each grant records its package reference and original amount. Revoking an allowance stops new use and retains any open checkout or authorized order commitment.
A prepaid credit must come from verified principal on a settled USD invoice for the same wedding. Tips and historical paid flags without a recorded payment cannot fund it. The source invoice and earlier grants are checked again when reserving an order and before production. An invoice refund or unresolved source funding issue can hold an included order. A studio package discount is different: it reduces merchandise before tax and does not represent prepaid cash.
Customers select an approved album, certified product/cover option, quantity, and US delivery address. Where the exact lab mapping supports a photo cover, the customer chooses a photograph and reviews its crop at that template’s certified production dimensions. The selected source checksum, crop, cover description, upgrade price, album revision and interior files are frozen in the order. Production renders the photo cover as a 300-DPI JPEG. Available materials and templates are the studio’s certified products, not a claim that every lab SKU is supported.
Included orders require a Stripe Tax calculation for the frozen address, discounted merchandise and configured delivery amount. Prepaid credit applies after that calculation. A remaining balance opens a card checkout for exactly that total; tax is not calculated a second time. If the verified package covers the entire amount, the customer explicitly confirms the included order. Its status becomes package authorized, not a fabricated paid card transaction. Neither path marks the album shipped or fulfilled.
The tax record is a separate durable step before the lab queue. A lost response retries the same recording key within the safe window. After that window, production stays held for review. The gallery’s order controls can retrieve the original Stripe Tax transaction and verify its account, order reference, frozen hash and amounts before resuming. An active tax attempt cannot be overlapped by manual reconciliation.
Cash reports include only an actual additional card receipt, not previously received prepaid funds. Mixed prepaid/card orders retain their complete order tax but leave the cash-entry tax allocation unknown rather than guessing. A refund does not automatically restore prepaid credit or cancel production. Included-order cash refunds require a separate reviewed tax-reversal and package-allocation decision. The return controls implement that decision with a durable provider request and receipt; they never restore prepaid credit merely because a card refund was requested.
Tax registrations, connected-account behavior, certified lab mappings and real provider orders are activation checks deferred until coordinated setup. Local tests exercise the adapters with provider simulators; they do not certify tax treatment or lab output.
Partial refunds and reviewed package returns
Open Review a return or partial refund on an order. Enter the exact card amount and a reason, then acknowledge that you reviewed the independent lab status. Pending requests reserve the refundable card balance, including across simultaneous tabs. The original request identity and provider key survive retries. Verified cumulative charge receipts append only new cash-refund deltas to the ledger.
A partial digital goodwill refund retains the purchased files after settlement. A full refund revokes purchase access. A refund of printed goods stops an order that has not been submitted; when it may already have reached the lab, its physical status is retained for separate cancellation or return handling.
For an included album, the next step lets you allocate already confirmed card refunds and choose how much original prepaid credit to restore. Their combined gross amount is frozen with your reason, the original order hash, and the production status you reviewed. The tax provider reverses that exact gross against the recorded original tax transaction. Its actual returned tax is stored with the receipt; the app does not invent a tax split or issue another card refund in this step.
Prepaid availability increases only after that receipt is verified. Replayed callbacks and retries cannot restore it twice. A revoked allowance remains revoked; Reopen funded allowance rechecks the original source invoice before making its remaining balance available again. Returning package credit does not itself refund the source invoice. The source invoice retains its own payment history and refund controls, and active or spent package commitments continue to protect its funds.
A fully covered order canceled in full before any tax-recording attempt can restore its credit without creating and reversing an unnecessary tax transaction. A partial adjustment, or an order with an uncertain recording attempt, must first record or reconcile its original tax transaction. The controls provide both paths.
Lost card-refund or tax-reversal responses retain their reservations and retry the original provider identity inside the safe window. After the safe window, the controls accept the original provider receipt ID and verify its order, account, immutable decision, and amount before completing it. A definitive provider rejection releases the pending reservation; it keeps the rejected request in history and requires a new reviewed request. A failed follow-up lookup after an accepted refund is treated as uncertain, not as a rejection.
Build a physical cart and review every printed face
The print storefront retains up to 20 cart items in the current browser session. Add different certified products, review each image crop, change quantities, or reopen an item’s crop controls. A refresh keeps the local selection. Prices and availability are always validated on the server; a browser cart cannot alter retail prices. A changed checkout selection receives a new request identity, while retries of the unchanged selection recover its original order. Clear the cart explicitly when you want to start again.
A certified product can have one to eight image surfaces. For a two-sided card, choose front and back artwork separately and review both crops at the lab’s exact dimensions including template bleed. Typography belongs in prepared artwork supplied by the studio. Each face freezes its source checksum, crop and matching lab image-node ID. Production renders individual 300-DPI files; the lab request preserves their order and quantity. Original single-image orders retain their original snapshot hashes and filenames.
The studio can calculate retail prices from lab cost using a reviewed markup, or enter fixed prices. Surface dimensions and node mappings form part of the existing catalog certification fingerprint. Products requiring different order-level shipping or packaging attributes must use separate checkouts; incompatible combinations are rejected before payment. The cart shows the configured US shipping amount before tax, and secure checkout shows final tax and discounts before authorization.
For gifts, enter the recipient’s name and delivery address at checkout and your own receipt email. Albums retain their separate approved-design checkout and may include several copies of the same design. Support replacement reviews display every frozen printed face, so a replacement never silently substitutes a new photograph or crop. Real catalog certification, lab pricing, shipping, physical output, callbacks and fulfillment recovery remain coordinated activation checks.
Reusable physical price lists
Create a reusable list under Galleries → Physical products → Price lists, or use Price lists, offers & storefront inside a gallery. Select the products, enter retail prices and optional cover upgrades, or calculate them from product cost and a reviewed markup. A markup calculation is a draft suggestion until you approve the list.
Applying a list to a gallery freezes that exact list revision. Only its currently active, certified products appear for new orders; later edits to the reusable list do not change an assigned gallery until you explicitly apply its newer revision. Archive a list to stop new assignments while preserving existing assignments and order history. Return to the default catalog to use all currently active certified studio products.
For albums, an assigned product-list price replaces the design's base price. Reviewed extra-spread charges and the selected cover upgrade are added separately. Without an assigned list, the existing album base-price behavior is retained. Checkout freezes product, list revision, copies, crop, source files and monetary terms. A later catalog change never rewrites an existing checkout or paid production record.
Offer codes have reviewed percentages, expiry, active state and use limits. Concurrent checkouts reserve remaining uses. Changing offer terms requires the current saved version, and disabling a code stops new reservations. Earlier checkout discounts stay frozen. Linked unsent promotional campaigns stop when their reviewed offer terms change.
Send a gift funded by the studio
Open Studio-funded client gifts from the gallery. Choose original photographs and certified products, review every crop and printed face, and enter the recipient's US delivery address. The studio note stays private; it is not a printed enclosure. Canvas and framed products are available only when the studio has configured their exact certified lab mappings.
The first step previews the frozen gift and its catalog cost estimate. The workspace owner then approves the exact content, address and maximum studio production cost. Changing those inputs requires another preview. This creates a separate studio authorized order with zero customer charge; it does not create a Stripe checkout, customer payment or gallery sales ledger entry.
The normal production worker prepares private files and obtains the real lab quote. That quote must fit the retained owner-approved ceiling, and the studio must have explicitly enrolled fulfillment spending with enough remaining capacity. No automatic overage enrollment occurs. An over-budget quote is held before submission. The retained authorizer must still be the workspace owner when production dispatches; an ownership change requires reviewing outstanding gifts.
Before submission, eligible gifts can be cancelled from their controls. A held gift can retry its original content and confirmation; an uncertain import or submission requires lab reconciliation. After submission, use the same shipment tracking and production-support workflow as other physical orders. A replacement requires its own reviewed studio cost approval. The original gift, approval and production history stay intact.
The lab's confirmed charge is recorded in the fulfillment usage ledger, separately from customer sales. This does not file taxes or automatically classify the gift in an accountant's expense categories. Private storage, exact catalog certification, lab tax/shipping settings, spending enrollment and real order/recovery tests remain part of coordinated activation.
Recover your purchase history
Open Your gallery purchases while signed in to find receipts associated with a currently verified email on your account. The desk includes confirmed purchases, refunds, payment-processing records and authorized/returned included packages. It excludes unpaid carts. Filter by verified receipt email, gallery and UTC date, then page through earlier purchases or export up to 5,000 matching records as CSV.
Each card keeps payment, cash refund, included-credit and production status separate. Currency totals include confirmed cash payments and recorded cash refunds only; prepaid credits are shown separately. Open the original receipt to use the existing download entitlement, track individual shipments, review replacement/support progress or contact the studio through that order.
A typed email, shared wedding invitation or business contact address cannot reveal somebody else’s purchases. The desk uses the signed-in account’s current provider-verified emails. It refreshes those verified addresses at the web/API boundary, checks them again when recovering a receipt, and projects only customer-facing records. Studio costs, margins, internal notes, provider credentials and other customers’ orders remain private. The named API /api/v1/gallery-purchases requires an account session, not a workspace integration key.
Financial history remains available after gallery expiration or archive. Opening a receipt does not extend the gallery, remove its password, revive a refunded download or restore deleted originals. A private receipt link is still a bearer invitation; protect it as you would the original order confirmation.
Portrait and monogram purchases use the separate Keepsake orders page. This desk does not combine a studio’s business bookkeeping with a customer’s personal purchase record.
Keep a support request in one conversation
Each physical-order case now has a conversation on the private customer receipt and in the studio's production support page. A customer can add details, answer a question, or ask for an update without opening another case. The studio can post a customer-visible update beside its existing decision tools. Refresh loads new replies and the current case status.
Messages in this conversation are visible to anyone who holds the private order receipt link. Studio-only notes stay in the private decision form and never appear in the conversation feed. Posting here saves the update on the receipt and the studio case; it does not claim that an email or text was delivered.
A reply checks the case revision so a concurrent studio decision is not silently ignored. If the case changed, refresh, review its latest state, and submit again. An unchanged retry after an interrupted response uses the same request identity and recovers the original saved message. Draft reply text stays on screen after an error.
Resolved cases require an explicit Reopen this resolved case with my message confirmation. Reopening changes only the support case. It does not authorize a replacement, cancel a lab order, issue a refund, restore package funds, or change an approved purchase snapshot. The order still allows at most ten open cases at once.
The page shows recent conversation history, up to 50 replies per case from the order's most recent 1,000 replies. Earlier records remain retained. Studio integrations can page the complete case history through GET /api/v1/galleries/{id}/production-cases/{caseId}/messages with after and limit; POST uses the same reply service as the studio UI. Reading requires assets:read, writing requires assets:write, or the account must have full private workspace access. Scoped credentials and current workspace membership are rechecked even when recovering an earlier reply receipt.
Continue a canceled or expired checkout
If you leave the payment page, your receipt now offers Check & resume checkout. This retrieves the original provider session on the studio's original connected account. An open, verified session returns you to that same checkout. A completed payment updates the receipt; a processing payment stays separate from a confirmed purchase. Checking never creates a new order, payment or refund.
An uncertain checkout creation is recovered using its original provider reference. If the provider cannot confirm what happened, the receipt asks you to retry or contact the studio. A network error or a locally expired timer does not create a second checkout. Frozen prices and reviewed contents must still verify; an included-package payment also needs its retained tax quote and funded allowance.
After confirmed expiration, Review a new order in the gallery opens the current shop. Review products, photographs, every printed crop, quantity, delivery and current prices again before approving a new purchase. The earlier order remains unchanged. The receipt does not silently rebuild an expired cart or promise its earlier discount. Archived galleries need studio help before new purchases.
An album-only purchase offers Review current album options when its retained invitation is still current. This opens the existing album review and approval flow, subject to its password and current production readiness. It never reveals the full gallery. Older receipts without invitation provenance, rotated invitations and expired proofs ask you to use the original invitation or contact your photographer.
Integrations can use POST /api/v1/gallery-orders/{token}/checkout-recovery with the receipt's expectedSnapshotHash. The private receipt token is the authority; keep it private. The API invokes the same recovery service as the receipt. Repeated checks use the same recorded provider session and idempotent reconciliation receipts. Real Stripe/Connect activation and sandbox end-to-end checkout reconciliation remain part of coordinated setup.