Vignette release notes September 25, 2026
Sneak-peek gallery releases, customizable client emails, team earnings, smarter gallery downloads, and stronger protection for contracts, payments, and accounts.
New this week
Share a sneak peek without building a second gallery
A gallery can now begin as a Sneak Peek gallery. The first upload is selected automatically when that option is enabled, while every later upload stays private until the photographer deliberately adds it. Choose any gallery photo as an independent sneak-peek cover, preview the flat client presentation, and send a curated first look without exposing albums or unfinished work. Sending freezes the cover, selected photos, order, gallery copy, and watermark into an immutable release, so later editing cannot change what the client sees. Continue uploading, organizing albums, and refining the same gallery, then release the full gallery to the same client link when it is ready. Turning Sneak Peek mode off hides its authoring tools without deleting the selection or breaking an already-shared release.
Learn howPreview and personalize client invitation emails
Regular bookings, galleries, appointments, and meeting requests now share one responsive email composer. Edit the generated subject, add an optional personal message, and review the resolved sender, recipient, branding, workflow details, questionnaire note, and client link in the exact server-rendered email before it is sent. Gallery sneak peeks and full-gallery releases keep separate copy. Draft changes update the preview without saving; Save changes is the explicit commit point, and Reset to default restores the current generated subject and clears the note. Previewing never sends an email, creates access, or advances the workflow.
Learn howSort every part of a gallery
Gallery Photos and every album now have their own keyboard-accessible Sort menu. Order images by natural filename, date taken, file size, or a fresh random sequence, with clear direction choices such as A to Z and Z to A. Date taken uses the original EXIF capture time when available and falls back to upload time for stripped or older files. The grid updates immediately, saves through the established reorder workflow, and restores the previous sequence with a notification if persistence fails.
Learn howClients can focus on—and download—their favorites
After a client marks at least one favorite, the gallery gains a Show Favorites view plus a dedicated Favorites ZIP. The filter follows favorites across the cover, Gallery Photos, albums, album cards, counts, and navigation while leaving the photographer’s saved organization untouched. Empty album sections disappear from the filtered view, and removing the final favorite returns safely to Show All. Clients can also download a complete album from its card or section heading. Prepared files now identify the choice in the filename with Favorites or the album name, while Download All, limits, and active-release access continue to work as before.
Learn howTeam earnings arrive in Finance automatically
When a contractor payment settles, the receiving studio now sees the compensation in a dedicated Finance → Team earnings roster with year-to-date and all-time totals. Search and filter by date, sort by payment date, amount, event, or hiring photographer, and review the source booking, team role, event date, confirmed hours, rate, and compensation. Settled team earnings also flow into revenue charts, category and session reporting, tax planning, and the tax packet. Pending or failed attempts and the hiring photographer’s separate Stripe fee never count as recipient income.
Learn howPeople brings client work and money together
Person details now show Paid all time, the combined Outstanding balance across active full sessions and that client’s own mini-session slots, and the earliest Next payment with either its real date or honest workflow timing. Canceled work is excluded from what is still owed, while settled history remains part of the lifetime total. The same drawer also adds recent questionnaires from bookings, appointments, and meeting requests alongside contracts, galleries, and bookings, with compact context that opens the owning workflow without exposing answers in the summary. Long message histories begin with the latest three entries and offer an explicit View all messages action.
Learn howEmail delivery failures become actionable
Booking, contract, gallery, payment-receipt, and refund emails now enter a durable delivery queue with separate queued, provider-accepted, delivered, and failed states. Temporary transport problems retry instead of disappearing as successful sends, and photographer or studio names containing accents or other non-ASCII characters are encoded correctly for delivery. When a terminal delivery failure can be tied to a photographer, Vignette sends a platform-branded notification with a plain-language reason and a link back to the affected workflow, while keeping raw mail-server diagnostics private. The underlying booking, payment, or other completed action remains successful even when its notification email does not arrive.
Learn howFixes and refinements
Gallery sharing explains what clients can see
The gallery header now keeps Share, Preview, and Add images usable from phones through wide desktops, while the editor navigation switches between a compact mobile drawer and a full icon-led rail. Gallery settings are reorganized into Gallery details, Sneak Peeks, Sharing & delivery, Client access, Downloads, Watermark, and Delete gallery. Release choices and action labels now say Sneak peek or Full gallery in context, show which release clients are viewing, and make unpublished changes easier to recognize without turning settings saves into accidental emails.
Learn howBooking times respect the whole calendar
After a session date is chosen, the booking form now disables start times whose complete session window overlaps another booking or appointment. Editing excludes the current booking, canceled appointments remain available, and storefront availability is correctly treated as open time rather than a conflict. New mini sessions begin with four 20-minute spots and no gap so their full event window can be checked immediately, then recalculate whenever the geometry changes. A failed availability check keeps uncertain times disabled, the server rechecks before saving, and a new appointment now opens directly into its details drawer after creation.
Learn howBooking guidance points to the actual problem
Server validation now returns errors to the matching booking fields for the client, package, category, title, price, retainer, date, time, duration, location, deliverables, notes, and contract template instead of leaving a generic message at the bottom of the form. Invalid negative amounts, inconsistent retainers, and malformed currency values are rejected consistently. Booking labels also distinguish Awaiting payment, Payment past due, Payments up to date, and Confirmed, and a payment tied to confirmation becomes due at the same moment for owner and client views when no contract step exists.
Learn howGallery passwords and watermarks protect every path
Password-protected galleries now require the same verified access for gallery details, favorites, single-photo downloads, ZIP creation, and export polling—not only the first viewer page. A successful password creates a short recipient-bound grant that expires and is invalidated when the password changes. Client image responses no longer expose storage keys, use short-lived media links, and serve the protected derivative whenever watermarking is active so the original cannot be recovered from page data. Cover photos, watermark files, linked bookings, and package contract templates are also validated against the owning studio before they can be saved.
Learn howPayment history resists replays and double collection
Partial refunds now remain part of the paid balance and Finance totals when provider events are replayed. An open Stripe checkout blocks competing manual payments, waivers, plan archival, or mini-session release actions that could collect twice, and mini-session status changes must use the cancellation and refund workflow. Out-of-order subscription, invoice, booking-payment, and contractor-payment events can no longer move newer state backward; uncertain mini-session checkouts recover against the correct client link, and one failed recovery no longer stops other payments or refunds from being reconciled. Public checkout and status endpoints also have link-aware rate limits without placing bearer tokens in cache keys.
Contracts sign once and stay private
Contract signing now locks and rechecks the current contract, preventing double submissions, duplicate PDFs or emails, and signatures on canceled or superseded versions. A recipient’s signed-PDF download requires a short-lived credential tied to that signing cycle instead of an exposed contract identifier, whether the agreement belongs to a client or team member. Contract PDF rendering also blocks external resource requests, and a package or event can no longer attach a contract template owned by another studio.
Learn howAccount identity and deletion close the remaining gaps
The verified account email can no longer be overwritten through ordinary profile edits, and Google sign-in links only to an enabled, confirmed account whose matching email is verified. Public client pages use the studio’s business contact instead of falling back to the owner’s login address. After the deletion grace period, a resumable worker now removes authentication, galleries, planning, calendar, storefront, notification, contact, logo, RAW Exchange, and other owned data; required payment records remain only as anonymized accounting history for the retention period. Finance CSV exports also neutralize spreadsheet formulas before download.
Learn howPreviews and long-running work fail safely
Booking, gallery, and appointment client previews now open in the current tab with a shared Back control. Parent mini-session previews are fully read-only: time choices, client details, resume actions, and reservation submission cannot mutate real availability, while owner preview continues to hide recipient favorite and download controls. Email previews grow to the full rendered document height so the page—not an iframe—owns scrolling. Behind the scenes, leased background jobs are fenced against duplicate completion, gallery deletion keeps its lock through storage cleanup, and mini-session resume sends the existing secure link by email without ever returning its bearer token in the response.
Learn how