Skip to content
    Trust & Security

    How We Protect Your Data.

    This page is maintained by TL Web Design to answer common security and privacy questions about how we operate this website and the services we deliver to clients.

    Informational — not an independent certification or audit.

    HTTPS / TLS in transit
    Row-level security on customer data
    Server-side role checks
    Transactional email through Resend

    Access & Authentication

    TL Web Design uses managed authentication provided by our backend platform (Supabase). Sign-in supports email and password, and Google sign-in when enabled.

    Account passwords are hashed and stored by the authentication provider — they are never visible to TL Web Design staff.

    Admin areas of this site are protected by server-side role checks. Roles are stored in a dedicated table and validated on every request through row-level security rules.

    Platform & Hosting

    The TL Web Design website runs on Lovable, which uses Supabase for managed Postgres, authentication, edge functions, and storage. Application traffic is served over HTTPS with TLS in transit.

    Backend access is restricted to TL Web Design and the platform provider. Service-level credentials (API keys, signing secrets) are stored in the platform secrets manager and never committed to source code.

    This is not a certification — it is a factual description of the platform capabilities used by this site.

    What We Collect & Why

    Contact forms collect the name, email, phone (optional), business type, project timeline, and message that you submit so TL Web Design can respond to your inquiry.

    When you purchase a service, billing information (name, email, billing address) is collected and processed by Stripe. Payment card details are entered directly into Stripe — TL Web Design does not see or store full card numbers.

    Account holders may additionally provide a profile name and company details to be used inside the customer dashboard.

    Subprocessors & Integrations

    TL Web Design relies on a small set of trusted third-party services to operate this site:

    • Supabase — managed database, authentication, edge functions

    • Stripe — payment processing, billing portal, invoices

    • Resend — transactional email delivery

    • Lovable — hosting and platform tooling

    Each provider operates under its own privacy and security commitments. Data shared with them is limited to what is necessary to deliver the requested service.

    Cookies & Analytics

    The site uses essential cookies for authentication sessions and limited analytics to understand site usage. A cookie banner is shown on first visit.

    Full details, including how to manage preferences, are documented in the Cookie Policy.

    Retention & Deletion

    Lead submissions are retained while they are needed to respond to your inquiry and follow up on related work.

    Account and billing records are retained for as long as your account is active and afterwards as required by tax, accounting, and legal obligations.

    You may request deletion of your personal data by contacting TL Web Design — see the Privacy Requests section below.

    Privacy Requests

    If you would like to access, correct, export, or delete personal data TL Web Design holds about you, send a request to the contact address below. We aim to respond within a reasonable timeframe.

    Authenticated users can update profile information directly from the customer dashboard and manage billing through the Stripe customer portal.

    Security Contact & Incident Reporting

    If you believe you have found a security issue affecting this site, please email security concerns to the contact address on our Contact page with a clear description and reproduction steps.

    TL Web Design will acknowledge reports and work with the platform provider as needed to investigate and resolve them. Please do not publicly disclose suspected issues before they have been addressed.

    Shared Responsibility

    Security is a shared responsibility:

    • Lovable and Supabase secure the underlying platform, infrastructure, and managed services.

    • TL Web Design configures application-level access controls, validates inputs, and applies row-level security rules on customer data.

    • Customers protect their own account credentials, use strong unique passwords, and notify TL Web Design promptly of suspected account compromise.

    Questions about security or privacy?

    Reach the TL Web Design team through the Contact page and we will route your request to the right person.