Plain-language summary
- Private order files require verified access or a time-limited token.
- Login and upload abuse is rate-limited and uploaded images are validated.
- Payment success must be verified by the server before paid access is granted.
- No website can make screenshots or all security incidents impossible.
This summary helps with reading. The complete sections below control if a summary and the detailed text differ.
1. Current protection layers
- HTTPS transport and browser security headers.
- HttpOnly, Secure and SameSite session cookies on production.
- Server-side customer, order and administrator authorisation.
- Rate limits for authentication and uploads.
- Image type, size, dimension and pixel-count validation followed by safe re-encoding.
- Private media delivery with order ownership checks and no-store responses.
- Expiring, watermarked preview copies separated from final HD delivery.
- Secrets stored outside the public web directory.
2. Payment safety
Card details must be collected by the approved payment provider, not by Little Frames Studio forms. The server must create the provider order, verify payment signatures and reconcile signed webhooks before marking an international payment paid or releasing protected delivery.
Never send a card number, CVV, OTP or banking password through support.
3. What customers should do
- Use only littleframesstudio.com and check HTTPS before uploading or paying.
- Do not share login codes, preview links or account access.
- Sign out on a shared device and report an unfamiliar order or login promptly.
- Send support the order ID first; do not post baby photos or payment proof publicly.
4. Report a security concern
Use the verified support channel displayed on the website. Include the affected URL, time observed, a concise description and safe reproduction steps. Do not include another customer's personal data or download private files to prove the issue.
Please allow us a reasonable opportunity to investigate before public disclosure. We do not authorise destructive testing, denial of service, social engineering, credential attacks, payment fraud or access beyond your own account.
5. Incident response
We investigate credible reports, contain affected access, preserve necessary evidence, correct the issue and notify affected people or authorities when applicable law requires it. Security controls and this page are reviewed when the service or providers materially change.
6. Honest limitations
No internet service is risk-free. A customer who can view an image can take a screenshot, so watermarking is a deterrent rather than absolute prevention. We do not claim certification, encryption at rest or a completed international payment integration unless each has been independently verified.