Trust & Security
This page describes the practical safeguards Pines Design LLC uses for inquiries, client files, Stripe-hosted payments, and digital delivery.
Who we are
Pines Design LLC is a Wyoming limited liability company. 105 W Franklin St, Ludowici, GA 31316, USA is its operational and customer-service address.
These security notes apply to pinesdesign.com and to how the studio handles inquiries, project files, and Stripe-hosted payments.
Security approach
Pines Design uses reasonable safeguards designed for a small design studio handling client inquiries, project files, approvals, invoices, and electronic deliverables.
Security is reviewed as tools and workflows change, with a preference for reputable hosted services, limited access, and clear project records.
Website and transport security
The production website should be served over HTTPS. Forms and site traffic should be protected in transit. Administrative access should use strong passwords and, where available, multi-factor authentication.
The site avoids collecting sensitive payment details directly. Card entry happens on a full-page Stripe-hosted checkout after you start payment from a service page or from a quote we send.
Current payment state
Fixed-price checkout is live through Stripe-hosted pages. This site does not accept, process, or store payment card data, and no page on this site asks for card numbers.
Payment confirmations and limited billing records may be retained for accounting, tax, dispute-resolution, and fraud-prevention purposes.
Payment architecture
Each fixed-price service has a Stripe Payment Link for its published USD amount. The Pay button on the service page is that link. You leave pinesdesign.com and enter card details only on Stripe.
A success page on this site is informational. We treat the payment as paid after a verified Stripe webhook. Custom work is still quoted first; after you approve the written scope we send a Stripe page for that amount.
How a charge will appear
The Stripe account's long statement descriptor is PINES DESIGN. The shortened descriptor, or card prefix, is PINESDES* [PRODUCT]. The text after the asterisk identifies the product or order and can change from charge to charge.
Banks and card issuers sometimes shorten, capitalize, or reformat descriptor text, so spacing and punctuation may look a little different on a statement.
Never send card details
Never send full card numbers, security codes, PINs, passwords, or bank credentials through any form, email, phone call, chat, SMS, or social channel. Pines Design will never ask for them through those channels.
As a safeguard, the quote form on this site actively rejects input that looks like a payment card number.
Stripe's role
Stripe publishes that it is a PCI DSS Level 1 service provider, per Stripe's public security documentation. That status covers Stripe's own systems, not this website.
Stripe's status does not certify, endorse, or approve Pines Design, and no PCI DSS validation of any kind has been completed for this site.
What this page is not
This page describes payment-security readiness, not completed PCI DSS compliance. Pines Design has not undergone PCI DSS certification, a Self-Assessment Questionnaire (SAQ), an Attestation of Compliance (AOC), or any other formal payment-security assessment.
The correct validation path will be confirmed when checkout is actually integrated, and this page will be updated to reflect the validated posture at that time. This studio is not a SOC 2 certified service organization.
Client files and access
Client files are shared electronically using reasonable access controls. Final source files are released after final approval and full payment. Clients are responsible for downloading and backing up delivered files.
If a project requires confidential handling, access restrictions, or a non-disclosure agreement, those requirements should be agreed in writing before work begins.
Incident response
If Pines Design learns of a security incident affecting personal information or client files, it will investigate, take reasonable containment steps, document what happened, notify affected parties where required, and improve safeguards where appropriate.
Where GDPR or UK GDPR applies, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach, unless the breach is unlikely to result in a risk to individuals.
Responsible reporting
If you believe you found a vulnerability or security issue on pinesdesign.com, please contact hello@pinesdesign.com with enough detail for us to investigate. Please do not access, modify, delete, or disclose data that is not yours.
Questions about this page? Contact hello@pinesdesign.com, +1 (912) 915-0729, or write to 105 W Franklin St, Ludowici, GA 31316, USA.