Privacy Policy
This Privacy Policy explains how Thomas Beach Photography ("we," "us," "our") collects, uses, and protects information when you visit thomas-beach.com, book a session at book.thomas-beach.com, view a gallery at clientgalleries.thomas-beach.com, or otherwise interact with our services.
Information We Collect
We collect only what we need to deliver photography services and respond to inquiries:
- Contact information you give us via the contact form, booking form, or email — name, email address, phone number, and any details you include in your message.
- Booking details — session type, date, location, and any notes you provide.
- Payment information — processed by Stripe; we never see or store your card numbers. We retain only Stripe's transaction reference and the amount charged.
- Gallery access logs — when you view a client gallery, we record the email you used (if any), favorites, and download activity, so we can support you and improve the experience.
- Standard technical data — IP address and basic browser information when you submit a form, used only to prevent abuse.
How We Use Your Information
- Respond to inquiries and schedule sessions.
- Send transactional emails (booking confirmations, balance payment links, gallery delivery, expiration reminders).
- Send transactional SMS messages if you opted in — see "SMS Messaging" below.
- Process payments through Stripe.
- Provide ongoing client support.
We do not use your information for marketing, advertising, or to build profiles for any third party.
SMS Messaging
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Mobile opt-in data is shared only with our SMS messaging service provider (Twilio) strictly to deliver the messages you opted in to receive.
SMS program
Thomas Beach Photography operates a transactional SMS program to support the booking, payment, and delivery flow for photography sessions. This is the SMS Privacy Policy that applies to that program.
How you opt in
You opt in to SMS messages by explicitly checking an unchecked box on the booking form at book.thomas-beach.com, labeled "Text me about my session." Opting in to SMS is optional — you can book a session without it, and every message we send via SMS is also delivered via email.
What messages you'll receive
After opting in, you may receive:
- Booking request confirmations
- Appointment reminders (24 hours and 2 hours before your session)
- Balance payment links when your session balance is due
- Gallery delivery notifications with access link and PIN
- Cancellation acknowledgments
Message frequency
Message frequency varies based on your booking activity. A typical booking results in up to 5 messages across the lifecycle of a session (booking, reminders, payment, gallery delivery). We do not send recurring promotional or marketing SMS.
Cost
Message and data rates may apply. Standard messaging charges from your mobile carrier may apply to each SMS you receive. We do not charge any fee for SMS notifications.
Help and opt-out
Reply HELP for assistance. Reply STOP, CANCEL, UNSUBSCRIBE, QUIT, or END to stop receiving SMS messages at any time. Once you opt out, we will not send further SMS messages and we will record your opt-out preference so future bookings using the same phone number remain opted out unless you explicitly opt back in.
How We Protect Your Information
- All website traffic is served over HTTPS.
- Gallery PINs are stored encrypted at rest (AES-256-GCM).
- Payment information is handled directly by Stripe — we never see card numbers.
- Bookings and contact submissions are stored in access-controlled databases on Amazon Web Services.
- Access to administrative tools requires authentication.
Information Sharing
We do not sell, rent, or trade your personal information. We share information only with service providers strictly necessary to operate the business:
- Stripe — payment processing
- Twilio — SMS delivery (only for users who opted in)
- Amazon Web Services — hosting and email delivery
- Cloudflare — CAPTCHA verification on form submissions
Each of these providers is bound by their own privacy commitments and is used only to deliver the service you requested.
Data Retention
We retain booking records and contact submissions for as long as needed to provide ongoing service and to comply with legal and accounting requirements. You may request deletion of your information at any time by emailing thomasbeach@thomas-beach.com; we will honor the request unless retention is required by law (e.g., tax records).
Your Rights
You may request a copy of the information we hold about you, ask us to correct inaccurate information, or request deletion, by emailing thomasbeach@thomas-beach.com. We will respond within 30 days.
Cookies and Analytics
We use cookies and similar storage for three purposes:
- Essential website functionality — session state, gallery access tokens, admin authentication.
- Analytics — we use Google Analytics 4 (which sets
_gaand_ga_*cookies) to understand which pages visitors read and how they arrive at the site. Analytics data is aggregated and is not used to identify you personally. IP addresses are anonymized by default. - Session insights — we use Microsoft Clarity (which sets
_clckand_clskcookies) to record anonymized session replays and heatmaps. This helps us understand which parts of the site work well and where visitors get stuck. Form-field text (including names, emails, phone numbers, and message content) is automatically masked by Clarity's default privacy controls and is not recorded. We use these insights to improve usability, not to identify individual users.
You can opt out of Google Analytics by installing the official Google Analytics Opt-out Browser Add-on. You can opt out of Microsoft Clarity by enabling "Do Not Track" in your browser (Clarity honors DNT), by using an ad-blocking extension that blocks clarity.ms, or by visiting the Microsoft privacy controls.
We do not currently use third-party advertising or remarketing cookies. If we add Google Ads remarketing or similar in the future, this policy will be updated and the change reflected in the "Last updated" date above.
Children
Our services are intended for adults (18 and older). We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes are effective when posted to this page; the "Last updated" date at the top reflects the most recent revision. We will not retroactively reduce the protections that apply to information already collected.
Contact
Questions about this Privacy Policy or how we handle your information:
- Email: thomasbeach@thomas-beach.com
- Phone: (775) 354-8112