support@designbyuapparel.shop+1 818 383 0239

Trust

Payment and site security

Two things are worth being precise about on a site that takes card payments and accepts file uploads: what happens to your card number, and what happens to your files. Both are below.

Last updated August 11, 2026

01Your card details

We never see, transmit or store your full card number. Card details are entered on a payment page operated by a licensed payment processor. That processor holds the card data and returns to us only a confirmation that a payment succeeded, the amount, and the last four digits so we can match a payment to an order.

This matters because a merchant that never holds card data cannot leak it. There is no database on our side containing card numbers, expiry dates or security codes, because we never receive any.

Refunds go back to the original payment method through the same processor. We cannot send a refund to a different card or account, because we do not hold the details that would let us.

02PCI DSS

The Payment Card Industry Data Security Standard sets the rules for anyone who processes, transmits or stores cardholder data. Compliance is shared: our processor is certified to the standard for the part it handles, and our obligation is to keep card data out of our own systems and to keep the site that links to the payment page secure.

We meet that obligation by never putting a card field on our own pages, serving the site over HTTPS end to end, and keeping the checkout flow free of third-party scripts that could observe it.

03Cards we accept

We accept the following card brands:

  • Visa
  • Mastercard
  • American Express
  • Discover

All charges are made in United States Dollars (USD). Card brand names above are the trademarks of their respective networks and appear here only to tell you which cards work.

04Transport security

  • Every page and every request is served over HTTPS. There is no plain HTTP path.
  • HTTP Strict Transport Security is enabled with a two-year window and subdomain coverage, so a browser that has seen this site once will refuse to connect insecurely afterwards.
  • Responses carry the standard hardening headers: content type options, frame options, referrer policy and a permissions policy that switches off camera, microphone and geolocation.

05Your artwork

  • Uploaded files go into a private storage bucket with no public read access. There is no address that serves them to the open internet.
  • Each file is stored under a randomly generated name. Nothing from your file name, your name or your order number appears in it, so the storage cannot be guessed at or enumerated.
  • Production staff open files through short-lived signed links that expire in ten minutes.
  • Camera, device and location metadata is removed from images on receipt, before storage.
  • Files are deleted automatically once the retention window ends, and you can ask for deletion sooner.

Full detail, including retention periods and what we will and will not use artwork for, is in the privacy policy.

06Who can see your data

Order data is visible to the staff who need it to make and ship your order and to answer your questions. Artwork is visible to reviewers and to production staff. Nobody else in the business has routine access, and we do not give access to third parties except as described in the privacy policy.

07Fraud prevention

Our processor runs its own fraud checks on every transaction. On our side we look at order patterns for signs of card testing and unusual behaviour, and we may contact you to confirm an order before producing it. That is a delay, not an accusation, and we say so when we call.

08Reporting a problem

If you believe you have found a security problem with this site, tell us at support@designbyuapparel.shop with the subject “Security”. Give us enough detail to reproduce it. We will acknowledge within two business days and keep you updated.

Please do not run automated scanning or load testing against the site, and do not access data belonging to anyone else while investigating. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it first.