Privacy policy
Last updated
What this website and our client tools collect about you, why, who else sees it, and what you can ask us to do about it.
Who we are
Lavender Bouquet Photography is Cydney and Jason Macomber, photographing weddings and portraits since 2011, first in Washington State and, since 2021, from home in Rapid City, South Dakota. We don't have an office or a staff department, so what you send is read by Cydney, the photographer, or by Jason, who runs our systems. Write to us at [email protected] about anything on this page.
What we collect, and why
When you send an inquiry. The contact form asks for your name, your email address, a phone number if you want to give one, and what we need to know about the photographs: for a wedding, the date and the venue; for a session, things like a due date, a senior's name, school and class year, or who is coming. It also keeps whatever you choose to tell us. We use it to answer you and, if you book, it carries into the booking. With it we store a one-way fingerprint of your email and date (so a form sent twice becomes one inquiry), a hashed form of your network address for spam control, and your browser's user-agent string.
When you join our newsletter. The newsletter popup stores the email address you type, the page you were on, the exact wording you saw next to the form when you signed up, and a hashed network address that limits signups to five a day from one connection. The list is kept on our own system and is not passed to a mailing service. No newsletter has gone out yet; when one does, every issue will include a way to unsubscribe.
When you become a client. A booking holds your names, contact details and mailing address, the date and place, the agreement you sign, invoices and payments, the questionnaire you fill in, your planning workspace (schedule, guests, vendors, budget, seating, notes), each person's answer about portfolio use, and the messages between us. When you sign an agreement we record the time, your device and browser and a hashed form of your network address, as the record of signing. Your guests' names and details are yours; we hold them only to build your day-of schedule and seating with you.
When you sign in. Clients sign in with a link we email; our own accounts use a password or a passkey. For each signed-in device we keep the browser, a hashed form of the network address and a shortened form of it you can recognize, so you can see your own signed-in devices and so an odd sign-in stands out. Sign-in links expire after twenty minutes and are deleted after seven days.
When you view a gallery. A gallery opens by its link, a password or an invitation to your email address, depending on how it is set up, and it may ask for your name and email address. We keep a record of each visitor (with the browser and a hashed network address), favorites, selections and downloads, so we can see that the gallery reached you and so your favorites are there when you come back. A print order keeps the name, email address and shipping address you give at checkout, because the lab needs them.
When you pay. Card payments run through Square. You type your card number into Square's own form and it goes to Square; it never reaches our server. We keep Square's record of the payment, which includes the card brand and last four digits, a receipt link and whether the payment went through. Square's own privacy notice covers what Square keeps.
How we count website visits
We count visits to the public website ourselves, on our own server, with no advertising network involved. Nothing is counted in the client hub or in galleries.
What it records: the page you viewed and the page that sent you here, how far down you scrolled, the words on a button or link you clicked (the first sixty characters), how long the page took to load, the portfolio tab or filter you chose, a film you played, and which popup you saw and closed. Each visit is filed under a visitor code made by hashing your network address with a random value that changes every day, so the same person cannot be followed from one day to the next, and the address itself is not stored. If we have location switched on, we also record the country and region and, for visitors in the United States, the town; the place comes from our hosting network or from a lookup service that is sent the network address and returns only a place. Individual events are kept for 180 days; after that only daily totals remain, for two years.
What we never do
We do not sell or rent any of it, and we do not share it for advertising. We text only people who have told us that texting is fine, and we record when they told us and who noted it.
Who else sees it
The platform runs on a server we rent. A few companies do part of the work, and each receives only what its part needs: Backblaze B2 stores photographs and documents; Resend delivers our email, and Twilio our text messages when you have agreed to them; Square takes card payments; WHCC, our print lab, receives the name, address and files needed to make and ship a print order; and if we connect Google Calendar, a booking appears in our calendar there with its title, date and place.
We sometimes use an AI writing assistant, reached through OpenRouter. Before anything is sent to it, email addresses, phone numbers, street addresses, guest lists, contract text and payment details are removed, and requests go only to providers that OpenRouter lists as not collecting the data they are sent. Client names are sent unless we switch that off.
We share a client's details with nobody else unless the law requires it or you ask us to, for example when you ask us to send photographs to your planner or your venue. What vendors may do with photographs we send them is on the Licensing page.
How long we keep it
Inquiries that never become a booking are anonymized 24 months after we last hear from you. E-mail we send is logged; the body of each message is removed after 180 days and only the fact of sending stays. Sign-in links are deleted after seven days, and records of sign-in attempts after a day. Signed agreements, invoices and payment records are kept for at least seven years after the final payment or delivery, as your agreement says. A gallery stays online for at least a year after delivery (a gallery with an end date shows it), and we keep an archive copy of the photographs for at least two years after delivery. The photographs themselves are our work; see Licensing.
Your choices
You can ask us for a copy of everything we hold about you, and we will send a file with your profile, bookings, invoices and payments, messages, questionnaire, planning data and the names of your galleries. You can ask us to correct anything that is wrong. You can ask us to delete your personal details: we remove your names, addresses, phone numbers and notes, take your name and address off the messages and our activity log, and purge the email log for your addresses. Agreements, invoices and payment records stay as business records. We cannot delete while an invoice is unpaid or a booking is still ahead, and we will tell you if that is why.
You can say yes or no to your photographs appearing in our portfolio, and change your answer at any time, in your client hub or by writing to us. You can leave the newsletter by replying to any issue or by writing to us. Write to [email protected] for any of this, and one of us will answer, usually within two business days.
Children
This website is not directed to children under 13, and we do not knowingly collect personal information online from a child under 13. Newborn, family and senior sessions are arranged by a parent or guardian, who gives us the details about a child that we need, such as a due date or a senior's name, school and class year. A senior who is 18 or older may book for themselves; for a senior under 18, a parent or guardian signs the agreement and answers for the senior about portfolio use.
Changes
When this page changes, the date at the top changes with it.