Trust matters when you share brand assets, business details, and payment information. This page summarizes our public-facing security practices.
Website security
We use HTTPS/TLS for the public website and aim to follow modern security practices for hosting, routing, and site delivery.
Payment safety
Payment card information is handled through hosted, PCI-compliant payment infrastructure. We do not ask customers to send full card numbers by email, text, or contact form, and we do not store full card numbers on our servers.
Access controls
Access to client information is limited to people and vendors who need it to provide services, operate the business, support customers, maintain records, or meet legal obligations.
Data minimization
We collect project and billing information that is reasonably needed to respond to inquiries, provide quotes, complete approved work, process payments, and maintain records.
Consent and privacy controls
The website uses Termly as its consent manager. Termly loads before optional third-party scripts, provides accept, decline, and category choices where applicable, and keeps the tawk.to live-chat widget blocked until Performance and Functionality consent permits it.
Vendor review
We choose service providers based on business need, reliability, and security posture. Vendors that process personal information are expected to protect that information and use it only for authorized purposes.
Incident response
If we become aware of a security incident affecting personal information, we will investigate, take reasonable steps to contain it, and provide notices required by applicable law.
Customer responsibilities
Please do not send sensitive payment card numbers, passwords, government IDs, medical information, or unnecessary confidential data through the contact form. Use approved payment links or invoicing channels for payments.