Legal
Trust and Security
Last updated: August 13, 2026 - Irwin Space
This page summarizes the public-facing security, privacy, and operational practices Irwin Space uses for its website and digital design planning services.
01
Service scope
Irwin Space provides design planning and visual concept services. We do not operate a customer account portal, store full payment card data on our own systems, or ask customers to submit highly sensitive personal information through the website.
02
Data minimization
We ask for the information reasonably needed to respond to quotes, scope projects, deliver services, maintain records, and comply with legal obligations. Customers should avoid sending unnecessary sensitive information.
03
Website and transmission security
The production website should be served over HTTPS. We use reasonable technical safeguards for the website and related systems, including access controls and reputable hosting, communication, file delivery, and payment service providers.
Online card checkout is live through Stripe-hosted payment pages for the published USD packages and for approved written quotes. Card numbers and security codes are entered on Stripe's page, never on this website, in email, or in chat. This page is not a PCI DSS certification or a Stripe endorsement.
04
Access controls
Access to business records, project communications, and service provider accounts is limited to people or providers who need it for business purposes. We use practical access controls, authentication, and vendor account management practices appropriate for a small design planning studio.
05
Vendor and service provider practices
We may use third-party providers for hosting, email, file storage, invoicing, payment processing, and business administration. We choose providers based on practical security, reliability, and business fit, and we limit their access to what is needed for the service they provide.
06
Incident response
If we become aware of a security incident affecting personal information, we will investigate, take reasonable containment steps, and provide notices required by applicable law. When GDPR or another applicable law requires notice to a supervisory authority, we will give that notice without undue delay and, where feasible, within 72 hours of becoming aware. We will notify affected people when the law requires it.
Customers can report suspected security issues at studio@jackirwindesign.com.
07
Customer responsibilities
Customers are responsible for sending accurate project information, protecting any shared links or downloaded deliverables, and using qualified professionals where needed before implementing any design concept.
08
No absolute guarantee
No security practice can guarantee that information will always remain secure. This page is a public summary of practices, not a warranty, certification, audit report, or service-level agreement.