Last updated September 21, 2026
This explains what we collect, why, and what you can ask us to do about it. It is written to be read rather than to
be impressive.
What we collect, and why
- When you enquire: your name, email, phone number, event type, date, venue, guest count, budget
range and whatever you write in the message box. We need these to answer you with a real price and honest
availability. - If you book: the above plus your signature, the email address you sign with, your IP address, your
browser’s user-agent string and the exact text of the agreement as it appeared to you. That is what makes an electronic
signature provable, and we are required to keep it. - Your event brief: the running order, the people who matter to you, and anything you tell us to
handle carefully. This can include health or accessibility information if you choose to share it — you do not have
to. - Payments: handled by Stripe. We receive a confirmation and the last four digits. We never
see or store your full card number. - Your photographs: stored in our private delivery system and on Amazon S3.
- This website: standard server logs (IP, page, time, browser) kept for security and
troubleshooting.
What we do not do
We do not sell your data. We do not share it with advertisers. We do not run advertising trackers or profile you
across other websites.
Who else touches it
- Stripe — card payments.
- Amazon Web Services (S3) — encrypted storage of delivered photographs.
- Twilio — text messages, only if you opted in.
- Our photographers — the ones working your event get your name, contact details and your brief, and
are contractually required to keep them confidential and delete them afterwards.
How long we keep things
- Your online gallery: 60 days from delivery, then the image files are permanently deleted.
- Signed agreements and their audit records: seven years. These are legal and tax records and we
cannot delete them on request. - Enquiries that never became bookings: two years, then deleted.
- Your event brief: deleted with the gallery.
Your rights
Wherever you live, you can ask us to show you what we hold, correct it, delete it, or stop emailing and texting you.
If you are in California, the CCPA gives you those rights explicitly and the right not to be discriminated against for
using them. If you are in the UK or EU, the UK GDPR and GDPR do the same.
Ask at hello@zenithshots.com and we will respond within 30 days. We will not charge you and we will
not make it difficult.
Two honest limits: we cannot delete a signed contract or its audit record while we are legally required to keep it,
and we cannot recover a gallery once its 60 days have passed.
Texts and emails
Reply STOP to any text. Every marketing email has an unsubscribe link. Emails about a booking you have made are
service messages and will keep coming until the work is finished.
Children
We photograph children at family events with their parents’ consent, and we do not knowingly collect information
from anyone under 16 directly.
Security, honestly stated
Galleries are password protected with a second code sent by email, files are served through signed links that expire
rather than public URLs, and contract records are cryptographically signed so tampering is detectable. No system is
perfect. If we ever have a breach affecting you, we will tell you.
Contact
Zenith Shots, 30 N Gould St, Ste N, Sheridan, WY 82801. hello@zenithshots.com · (661) 443-6066