Trust & Security
This page summarizes the security practices Ben Creative LLC uses for the website, client communications, payments, galleries, and project files.
Security overview
We use reasonable administrative, technical, and organizational safeguards.
Ben Creative LLC uses reputable website hosting, HTTPS, access controls, limited administrative access, secure service providers, and routine software updates to reduce risk.
No website, email system, payment workflow, or storage system can be guaranteed completely secure, but we work to use reasonable safeguards for the size and nature of the business.
Privacy controls and audit logs
Consent records are limited and designed for accountability.
The website uses a first-party consent tool to keep optional third-party scripts out of the page until allowed by category, region, saved choice, and GPC status.
Consent logs use an anonymous consent ID and hashed user agent for auditability. The consent log is not intended to store full IP addresses.
Payment security
Card data is handled through secure hosted payment technology.
Electronic card payments are handled through secure hosted or embedded payment technology provided by third-party payment services. Ben Creative LLC does not store full payment card numbers or card security codes on its own servers.
Payment workflows are designed to reduce our exposure to cardholder data and support PCI DSS responsibilities by keeping sensitive card entry and processing with payment service providers.
Access control
Access to client and business records is limited to people and providers who need it.
We limit access to client communications, galleries, billing records, and project materials to the people and service providers who need access to operate the business and provide services.
Clients should use secure devices and avoid sending highly sensitive information through ordinary email or form messages unless necessary.
Incident response
We investigate security issues and provide legally required notices.
If we become aware of a security incident affecting personal information, we will investigate, take appropriate containment steps, work with service providers as needed, and provide notices required by applicable law.
For EEA or UK personal data incidents where notification is legally required, we will work toward regulator notification within the applicable legal timeframe.
No certification claims
We do not claim independent security certifications unless posted here.
This website does not claim SOC 2, ISO 27001, or other independent certification unless a current certification is posted on this page. Security practices may change as the business and service providers change.
Contact
Questions may be sent through the contact page or by mail to 609 Scott St, Hinesville, GA 31313, USA.