Security
Trust and Security
Last updated: July 8, 2026
This page summarizes the practical safeguards Worth Lens LLC uses to protect clients, inquiries, booking information, payments, galleries, and communications. It is a public overview, not a complete description of every internal control.
Secure website connection
The website should be served over a secure connection in production. That secure connection helps protect information sent between your browser and the website. We also aim to keep the site lightweight, limit third-party scripts, and use reputable hosting and deployment practices.
Payment safety
Online card checkout is planned, not live. The intended architecture is a full-page Stripe-hosted checkout after you approve a written amount in USD. We do not ask you to send full card numbers, security codes, or account numbers by email or through the contact form. The form rejects likely card numbers before a record is stored or an email is sent.
This page describes payment-security readiness only. It is not PCI DSS certification, an SAQ, an AOC, or any other completed assessment. Those remain pending until a real Stripe account and hosted checkout exist. When checkout is activated, Worth Lens is responsible for never collecting card data on this origin and for keeping the inquiry form’s card-number rejection in place. Stripe is responsible for the hosted payment page, card processing, and its own PCI obligations. Future validation, if required, will follow the SAQ path that matches hosted Checkout at that time.
Who runs which system
- Cloudflare delivers the website over HTTPS.
- The contact form writes to our Cloudflare D1 database and notifies the studio through Resend.
- Migadu receives inbound studio email.
- Termly presents cookie choices and blocks optional scripts until allowed.
- tawk.to provides optional chat after performance consent.
Only what we need
We ask for information that is reasonably needed to answer inquiries, prepare quotes, reserve dates, provide photography services, deliver galleries or albums, process payments, and keep required business records. We avoid collecting sensitive information unless it is necessary for the requested service or required by law.
Limited access
Access to client, inquiry, payment, and gallery information is limited to people and service providers who need it for business purposes. Accounts and systems should use reasonable access controls, authentication, and role-based access where available.
Trusted service partners
We may use trusted service providers for hosting, forms, email, payment processing, online galleries, printing, albums, live chat, and business operations. We choose providers based on business needs, reliability, and appropriate security and privacy practices.
If something goes wrong
If we learn of a security incident that may affect personal information, we will investigate, take reasonable containment steps, work with relevant providers, and notify affected people and authorities where the law requires it, including the GDPR 72-hour supervisory notice when that regulation applies.
A few helpful safety tips
- Use trusted devices and networks when opening invoices, galleries, or downloads.
- Do not send full payment details by email or contact form.
- Download and back up delivered image files before gallery access expires.
- Contact us promptly if you suspect a suspicious message or payment issue.
Related policies
See our Privacy Policy, Delivery and Booking Policy, and Refund and Cancellation Policy.
Contact
Worth Lens LLC - 6248 Hollywood Dr, Hollywood, SC 29449, USA
Phone +1 (854) 226-1376 - Emailhello@weddingphotographyfortworth.com