Preloader

Last updated September 21, 2026

This explains what we collect, why, and what you can ask us to do about it. It is written to be read rather than to
be impressive.

What we collect, and why

  • When you enquire: your name, email, phone number, event type, date, venue, guest count, budget
    range and whatever you write in the message box. We need these to answer you with a real price and honest
    availability.
  • If you book: the above plus your signature, the email address you sign with, your IP address, your
    browser’s user-agent string and the exact text of the agreement as it appeared to you. That is what makes an electronic
    signature provable, and we are required to keep it.
  • Your event brief: the running order, the people who matter to you, and anything you tell us to
    handle carefully. This can include health or accessibility information if you choose to share it — you do not have
    to.
  • Payments: handled by Stripe. We receive a confirmation and the last four digits. We never
    see or store your full card number.
  • Your photographs: stored in our private delivery system and on Amazon S3.
  • This website: standard server logs (IP, page, time, browser) kept for security and
    troubleshooting.

What we do not do

We do not sell your data. We do not share it with advertisers. We do not run advertising trackers or profile you
across other websites.

Who else touches it

  • Stripe — card payments.
  • Amazon Web Services (S3) — encrypted storage of delivered photographs.
  • Twilio — text messages, only if you opted in.
  • Our photographers — the ones working your event get your name, contact details and your brief, and
    are contractually required to keep them confidential and delete them afterwards.

How long we keep things

  • Your online gallery: 60 days from delivery, then the image files are permanently deleted.
  • Signed agreements and their audit records: seven years. These are legal and tax records and we
    cannot delete them on request.
  • Enquiries that never became bookings: two years, then deleted.
  • Your event brief: deleted with the gallery.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, delete it, or stop emailing and texting you.
If you are in California, the CCPA gives you those rights explicitly and the right not to be discriminated against for
using them. If you are in the UK or EU, the UK GDPR and GDPR do the same.

Ask at hello@zenithshots.com and we will respond within 30 days. We will not charge you and we will
not make it difficult.

Two honest limits: we cannot delete a signed contract or its audit record while we are legally required to keep it,
and we cannot recover a gallery once its 60 days have passed.

Texts and emails

Reply STOP to any text. Every marketing email has an unsubscribe link. Emails about a booking you have made are
service messages and will keep coming until the work is finished.

Children

We photograph children at family events with their parents’ consent, and we do not knowingly collect information
from anyone under 16 directly.

Security, honestly stated

Galleries are password protected with a second code sent by email, files are served through signed links that expire
rather than public URLs, and contract records are cryptographically signed so tampering is detectable. No system is
perfect. If we ever have a breach affecting you, we will tell you.

Contact

Zenith Shots, 30 N Gould St, Ste N, Sheridan, WY 82801. hello@zenithshots.com · (661) 443-6066

TOP