Legal information
Privacy Policy
This policy explains how LENS N’ LIGHT handles information when customers browse rental equipment, make or track a booking, and submit booking documents or payment proof.
Effective date: September 5, 2026
About LENS N' LIGHT
LENS N' LIGHT operates the camera and equipment rental booking service available at https://lensnlight.net. In this policy, “we,” “us,” and “our” refer to LENS N' LIGHT.
Information we collect
Information customers provide
When you make a booking, the service may collect:
- your first name and surname;
- your Philippine mobile number;
- your Facebook profile link;
- your address, selected ID type, and an image of your valid ID; and
- whether you select pickup or delivery.
The customer booking flow does not ask for an email address or require you to create a customer account.
Booking and rental information
We process the equipment selected, rental start and end times, rental purpose, optional notes, availability and pricing details, security-deposit information, booking number, terms acceptance and version, booking status, and relevant status timestamps or administrative notes.
Payment information
If you proceed to payment, we collect the payment method you select, the payment reference number you enter, the expected amount, payment status, and the payment-proof image you upload. The website records proof of an external payment for manual review; the source code does not collect or process payment-card numbers.
Technical information
The service derives an irreversible request fingerprint from request data such as an IP address, browser user-agent, and language header for rate limiting and abuse prevention. Application and hosting logs may also contain operational details such as timestamps, error categories, booking or event references, and request status. The application is designed to keep logged errors bounded and to avoid logging credentials or uploaded ID and payment images.
How we use information
We use this information to:
- create, price, reserve, review, update, and track rental bookings;
- check equipment availability and prevent conflicting reservations;
- verify customer identity information and payment submissions;
- manage pickup, delivery, returns, and security-deposit records;
- send booking-related notifications to the administrator;
- protect the service, enforce rate limits, diagnose errors, and prevent abuse; and
- meet applicable legal, accounting, dispute-resolution, and operational requirements.
Google API Services
LENS N' LIGHT uses server-side Google OAuth credentials to access a business-authorized Google Drive account or drive. Customers do not sign in with Google, authorize their own Google accounts, or give this website access to their personal Google Drive.
The configured OAuth connection requests the Google Drive scope. That scope permits access to files in the authorizing Google account. The application uses the authorization to locate and create its configured storage folders; upload, retrieve, and delete managed files; inspect file metadata and folder permissions; and confirm that managed storage is not broadly public.
Managed Drive storage may contain customer ID images, customer payment-proof images, payment-method QR images, and rental-item images. Supabase stores the related provider file identifiers and metadata needed by the application. Private customer files are retrieved only through server routes that require an authorized administrator session; item images are streamed through the website without exposing raw Drive identifiers.
LENS N' LIGHT's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Third-party service providers
We use service providers for the following operational purposes:
- Supabase provides the PostgreSQL database, administrator authentication, access controls, scheduled booking cleanup, rate-limit records, realtime admin updates, and server-side notification functions.
- Google Drive and Google APIs provide the managed file storage described above.
- Vercel hosts and delivers the production website and may process normal web-request and operational-log information.
- Telegram and Resend deliver administrative booking notifications. Those notifications may include a booking number, customer name, item, rental schedule, pickup or delivery mode, amount, payment method, and current status. The application does not attach ID images, payment-proof images, private Drive links, or credentials to these notifications.
These providers process information for the services they provide and under their own applicable terms and privacy practices.
Cookies and browser storage
The customer booking flow uses strictly necessary, HttpOnly cookies to link your browser to an unfinished booking and, after a booking number is issued, to the private payment session. The unfinished-booking cookie is configured for up to one hour. The payment-session cookie is configured for up to seven days, although an expired or completed booking cannot be reopened merely because a cookie remains in the browser.
Supabase authentication cookies are used for the protected administrator portal. The administrator booking screen also uses session storage to avoid showing the same realtime notification more than once during a browser session. The source code does not include advertising cookies, customer analytics, or customer local-storage tracking.
Data storage, retention, and deletion
Booking records and file metadata are stored in Supabase, while managed image files are stored in Google Drive. Unfinished bookings may be marked expired by scheduled database cleanup. The repository does not define a single fixed retention period for completed booking records.
We retain information only as reasonably necessary for rental operations, recordkeeping, security, dispute handling, and applicable legal obligations. An authorized administrator can permanently delete a booking. That operation deletes related payment, file-metadata, deposit, and status-history records through database relationships and attempts to delete the corresponding managed Drive files. File cleanup is best-effort and may require follow-up if a storage provider is temporarily unavailable.
Data security
The application uses access controls appropriate to its current architecture, including administrator authentication, database row-level security, server-only credentials, private-file checks, validated uploads, restricted file routes, security headers, and request rate limiting. No internet service can guarantee absolute security, and we do not promise that unauthorized access or loss can never occur.
Sharing of information
We disclose information to the service providers above only as needed to operate the booking service, protect the service, or complete an action you request. We may also preserve or disclose information when reasonably necessary to comply with applicable law, lawful process, or valid government requests; enforce agreements; or protect customers, the business, or others. The source code contains no advertising-network or data-broker integration.
The public booking tracker accepts a booking number and returns only a limited view: a masked customer name, item, rental period, pickup or delivery mode, duration, and booking status. It does not return the customer's address, mobile number, Facebook link, ID, payment details, or uploaded files.
Your privacy rights and requests
Subject to the Philippine Data Privacy Act of 2012, its implementing rules, and other applicable law, you may have rights to be informed, access personal data, correct inaccurate data, object to certain processing, request erasure or blocking where legally available, obtain data portability where applicable, and lodge a complaint with the National Privacy Commission.
To request access, correction, or deletion, use the contact information below. We may need to verify your identity and booking relationship before acting on a request. A request may be limited where retention or processing remains necessary under applicable law or for legitimate operational, security, or dispute-related purposes.
Children's privacy
The website does not offer a child-specific service and does not ask customers to provide their age. If a parent or guardian believes a child submitted personal information through the booking service, please contact us so the matter can be reviewed under applicable law.
Changes to this policy
We may update this policy when the booking service, our data practices, or applicable requirements change. The revised page will state its new effective date. Material changes affecting information already provided will be handled as required by applicable law.
Contact information
For privacy questions or requests, contact LENS N' LIGHT at:
[BUSINESS CONTACT EMAIL]
This placeholder must be replaced with the owner-approved public business contact address before relying on this page for customer support or production OAuth review.
