Scope and roles
This policy covers our marketing site, contact and quote forms, checkout, intake, billing-link requests, support inbox, permitted support attachments, ticket workflow, client-service work, and transactional communication.
DesignSpark Studio LLC is responsible for its own prospect, client, billing, site-measurement, and support information. When we receive an authorized submission through a client website, such as a Webflow lead form, we act as that client’s service provider or processor for the contracted workflow. The client remains responsible for its visitor-facing notice and instructions.
Information we collect
We may collect identity and business contact information; project and website details including URLs, platform, host, domain provider, integrations, goals, scope, assets, stakeholders, approvals, and access invitations; and support messages, thread history, permitted attachments, ticket status, and follow-up answers.
Transaction information can include selected plan, billing period, subscription state, invoices, billing address, payment status, and payment-processor identifiers. We do not receive full card numbers. Client-site workflows may process fields in an authorized form. Device and request information can include IP address, user agent, referrer, timestamps, security signals, and server logs. We use aggregate, cookieless site analytics and performance measurements.
Workflow records may include request classification, entitlement disposition, ticket identifiers, and policy-consent versions. An unfinished intake draft may remain in browser session storage until that session ends; it is not a server account or client workspace.
How we use information
We use information to answer inquiries, prepare quotes, create and administer subscriptions, verify plan coverage, provide services, coordinate authorized access, manage tickets, review permitted attachments, send transactional status and billing messages, schedule calls, secure and debug the service, prevent fraud and abuse, comply with law, enforce agreements, and maintain appropriate business records.
Automated processing and AI
Support emails and permitted attachments may be processed by automated systems and AI providers to understand requests, identify missing information, classify documented plan coverage, create or update tickets, and prepare or send routine workflow messages. Human escalation is available through our support email.
Automated output may be incomplete or incorrect. Plan classification is not an unreviewable legal decision: server entitlement rules remain authoritative, and automated systems cannot independently change billing, contracts, privacy rights, or production publishing authority.
Service providers and disclosures
We may disclose information to service providers supporting operations and when required by law or reasonably necessary to protect rights, security, or operations. Those categories can include hosting and analytics, billing, a support inbox, AI-assisted processing, ticket and work management, transactional email, optional scheduling when used, internal alerts, and business email. We share only the information reasonably needed for the applicable service.
Client-authorized platforms such as Webflow may be used when necessary to perform contracted work. We may update this disclosure as our operational services change.
Client platform data
When we access a client-authorized platform, we use the minimum access reasonably needed for agreed work. We request access by invitation where available and process client-platform data according to the client’s instructions, our agreement, and applicable law. The client remains responsible for its visitor notice and instructions; visitor privacy requests are routed to the client or handled with human review under the client’s instructions.
Sale, advertising, and communications
DesignSpark does not sell personal information, use it for cross-context behavioral advertising, or share it for targeted advertising. This service adds no advertising pixels, marketing cookies, or cross-site trackers.
Contact, quote, purchase, intake, and support activity authorizes necessary transactional or relationship communication only. A future newsletter or promotion requires separate affirmative opt-in, an unsubscribe method, accurate sender information, and the required physical postal address. Promotional content is not mixed into ticket receipts, lifecycle updates, or billing notices.
Sensitive information and children
Please do not submit passwords, recovery codes, private keys, API tokens, full payment-card data, government identifiers, medical information, or unrelated highly sensitive data. A mistakenly submitted secret is escalated for containment and deletion rather than copied into knowledge or a ticket description.
Our service is for U.S. businesses and authorized adults. It is not directed to children, and we do not knowingly collect children’s information.
Retention
Unconverted contact and quote submissions are retained for 12 months after the last interaction. Client intake, tickets, support messages, and attachments are retained for 3 years after the client relationship ends. Contracts, invoices, payment, and tax records are retained for 7 years. Security and operational logs are retained for the provider’s configured period or the period needed for an active investigation.
Verified deletion may occur earlier. Legal, accounting, fraud-prevention, security, and dispute holds override normal deletion only for the necessary records and period. Provider backups and logs disappear through normal provider deletion cycles; we do not promise instantaneous removal from every backup. A client relationship ends on the latest of subscription access ending, the final ticket completing, and an open billing or legal dispute resolving.
Privacy rights and requests
Every U.S. visitor and client may request access, correction, deletion, a portable copy, an explanation of categories, sources, uses, and providers, an opt-out of sale or targeted advertising, or an appeal of a denied request. Send requests to support@mail.designspark.studio.
We reasonably verify identity and authority without collecting excessive information. Our operational target is a response within 45 days. We may extend or refuse a request only when allowed by law and explained, and we do not discriminate for exercising these rights.
Security
We use proportionate controls including TLS, access controls, scoped provider keys, signed webhooks, input limits, exact inbox and client guards, security headers, least-privilege invitations, and provider oversight. No internet or storage system is completely secure.
Changes
We may update this policy to reflect operational or legal changes. Material changes receive advance notice when appropriate. Existing subscription clients receive at least 30 days’ notice and transition at a later renewal where applicable; ordinary clarifications use the published effective and last-updated dates and any notice required by law.
