Trust
Security Practices
Phosphor Digital handles client contact details, booking records, deposit payments, and creative files. This page describes how we protect them, written and maintained by us.
Encryption
All traffic to this site is served over HTTPS, and client data is stored in a managed database that encrypts data at rest.
Access control
Client accounts can only read their own bookings, messages, and profile — enforced by row-level rules in the database, not just in the interface. Studio access is limited to named administrator accounts.
Payments
Deposits run through Stripe Checkout. Card numbers are entered directly with Stripe and never touch our servers; we keep only the receipt reference, amount, and status.
Change logging
Administrative actions taken through our internal tools — booking changes, site content edits, agent-assisted requests — are recorded with the account that made them, and content changes are versioned so they can be rolled back.
Data minimization
We ask for the details needed to quote, schedule, and deliver a project, and we keep them only as long as our retention schedule allows.
Vendors
We rely on established providers for hosting, database, payments, email, and messaging. Each is bound by its own data-processing terms.
Certifications and audits
Phosphor Digital is a small studio and does not currently hold a SOC 2, ISO 27001, or similar third-party audit report. The practices above describe controls we operate today. If your organization requires an audited report or a signed data processing agreement before working with us, email contact@phosphordigital.com and we'll work through your requirements directly.
Reporting a vulnerability
Found something that looks wrong? Email contact@phosphordigital.com with the details and steps to reproduce. Please give us a reasonable window to respond before sharing publicly, and don't access other people's data while testing. We acknowledge reports within five business days.
Your data rights
Read what we collect and request a copy, correction, or deletion on our Privacy Policy page.