Privacy Policy
This policy explains what personal information Pines Design LLC collects through pinesdesign.com, project inquiries, payments, and client communication.
Information we collect
We collect information you choose to provide when you request a quote, contact us, approve a project, or communicate with the studio. This may include your name, email address, phone number, company name, project type, budget or timeline notes, and the details you include in a message.
If you make an online payment, Stripe processes your payment details on a Stripe-hosted payment page. This website does not receive or store complete card numbers or card security codes. We receive transaction confirmations and limited billing information needed for records, tax, fraud prevention, and project administration.
When you submit the contact form, the inquiry is stored in a Cloudflare D1 database and transmitted through Resend to a Pines Design mailbox hosted by Migadu. For abuse prevention, the site stores a one-way hash derived from the requesting IP address in Cloudflare KV for no more than 10 minutes; the raw IP address is not placed in that rate-limit record.
Cloudflare may also process basic network and request information needed to deliver and protect the site, such as IP address, browser and device information, requested pages, timestamps, and security logs.
How we use information
We use personal information to respond to inquiries, prepare scopes and quotes, schedule work, provide design services, process payments, deliver files, keep project records, protect the website, and meet legal, accounting, and tax obligations.
If you ask to receive updates or continue a business conversation with us, we may use your contact information to send relevant service communications. You can ask us to stop non-essential communications at any time.
Legal bases for processing
Where privacy laws require a legal basis, we rely on contractual necessity to prepare and perform design services, legitimate interests to respond to inquiries and protect the studio, legal obligations for accounting and compliance records, and consent where consent is required for optional communications or non-essential cookies.
Service providers and their roles
Cloudflare hosts and delivers the production website, provides network security, and supplies the D1 and KV services used for inquiries and short-lived rate-limit records. Termly provides the cookie consent banner, preference center, AutoBlocker, website scanning, and provider-managed consent records. Resend transmits contact-form notifications and their message content to Pines Design. Migadu hosts Pines Design business mailboxes and processes messages sent to or received from addresses at pinesdesign.com.
Stripe hosts the payment page and processes payment and fraud-prevention information. Depending on the processing activity, Stripe may act as a processor for Pines Design or as an independent controller for purposes described in Stripe's own privacy terms. Pines Design receives transaction confirmation and limited billing records, not complete card numbers or card security codes.
Professional advisers and project-specific vendors may receive information only when reasonably necessary for accounting, legal support, dispute handling, or a service the client has requested. When a project requires another vendor, the scope or project communication identifies that vendor where practical.
Categories of personal information
The categories of personal information we may collect include identifiers such as name, email address, phone number, business name, mailing or billing details provided for a project, internet or network activity from basic site logs, commercial information such as project scopes and payment confirmations, and project content you choose to send us.
We collect these categories directly from you, automatically from the site and hosting systems, or from service providers that support payments, email, file delivery, hosting, and security.
Cookies and analytics
Termly provides the site's consent banner, preference center, and AutoBlocker. Termly stores your consent choice in this browser so the site can remember which categories you allowed. Essential technologies remain active; Performance and Functionality, Analytics and Customization, Advertising, and Social Networking technologies remain disabled unless you permit the relevant category.
The site does not currently run optional analytics, advertising, chat, social-media, or embedded-media technologies. Cloudflare appends a Web Analytics beacon tag to the production HTML, but the site's Content Security Policy does not permit that origin, so the beacon cannot execute. If an optional technology is activated later, Termly's AutoBlocker is configured to prevent it from running before the applicable consent. You can review, withdraw, or change choices at any time through the single Cookie Settings button in the footer.
Consent records
Termly may process consent choices and related consent metadata to provide the banner, remember preferences, and document consent. Pines Design does not operate a separate consent-recording service or write those records to its inquiry database.
Consent choices are not used by Pines Design as advertising identifiers. See Termly's privacy policy for information about Termly's own processing.
Global Privacy Control
Pines Design does not sell personal information, share it for cross-context behavioral advertising, or run targeted advertising. Because those activities are not present, the site does not currently expose a separate Do Not Sell or Share control or rely on a Global Privacy Control signal to switch them off.
Optional technologies remain off until a visitor permits the relevant Termly category. If the site's practices change so that a sale, sharing, targeted-advertising, or GPC opt-out is applicable, Pines Design will update the consent configuration and notices before that activity begins.
Data retention
Quote requests that do not become projects are ordinarily retained in the inquiry database and business mailbox for up to 24 months after the last substantive communication, then deleted unless an active dispute, fraud concern, legal hold, or legal obligation requires longer retention.
For accepted projects, Pines Design ordinarily keeps the written scope, client communications, approvals, invoices, payment confirmations, and delivery records for the life of the project and seven years after completion or cancellation. This period supports tax, accounting, contract, warranty, and dispute-resolution needs. Working files that are not part of those records may be deleted sooner when they are no longer needed.
The hashed rate-limit record used by the contact form expires after 10 minutes. Termly-managed consent metadata and provider-managed network and security logs follow the applicable provider and account retention settings.
Termly, Stripe, Resend, Migadu, and other providers may retain information under their own terms and legal obligations. A verified deletion request is applied to records Pines Design controls unless retention is required by law or remains necessary for an active project, security matter, legal claim, or dispute.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including HTTPS, access controls, use of a Stripe-hosted payment page, and limited access to project and payment records.
No method of transmission or storage is perfectly secure. If we become aware of a security incident affecting personal information, we will take appropriate steps to investigate, contain, notify affected parties where required, and improve safeguards.
Your privacy rights
Depending on where you live, you may have the right to request access to, correction of, deletion of, restriction of, or portability of personal information. You may also object to certain processing or withdraw consent where processing is based on consent.
California residents may request information about categories of personal information collected, sources, purposes, categories of recipients, retention, and whether information is sold or shared. Pines Design does not sell personal information and does not knowingly share personal information for cross-context behavioral advertising.
To protect privacy, we may need to verify your identity before responding to a rights request. We aim to respond within the time required by applicable law, including 45 days for California consumer requests when that law applies.
Children's privacy
The site and services are intended for business owners and adults. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us and we will take reasonable steps to delete it.
International visitors
Pines Design is based in Georgia, USA. Cloudflare, Resend, and Stripe may process information in the United States and other countries in which they or their subprocessors operate. Migadu provides email hosting from Switzerland and may use the locations described in its privacy and data-processing notice.
When personal information protected by EEA, UK, or Swiss law is transferred to a country that does not have an applicable adequacy decision, the provider terms used by Pines Design state that an available lawful transfer mechanism applies. Depending on the provider and transfer, those mechanisms include the European Commission's Standard Contractual Clauses, the UK Addendum, Swiss adaptations, or a recognized Data Privacy Framework. Cloudflare, Resend, and Stripe describe their mechanisms in the provider materials linked above.
You may request more information about a relevant transfer safeguard by contacting hello@pinesdesign.com. Any copy provided may be limited or redacted where needed to protect confidential or security information.
Contact
Questions or privacy requests can be sent to hello@pinesdesign.com, by phone at +1 (912) 915-0729, or through the contact page.