EyewearPlatform should collect only the information needed to process orders, provide support, and maintain records. Prescription uploads must be stored privately with restricted admin access.
Use signed URLs for prescription files, keep service keys off the client, and document access with an audit log.