Legal
Security
Last updated: September 17, 2026
Security doesn't need to be complicated to be effective. Here is exactly how tavernmark.com and your order information are protected — and what you can do on your side.
1. Website Security
- HTTPS enforced: all traffic to tavernmark.com is encrypted (TLS) and plain-HTTP requests are permanently redirected. HTTP Strict Transport Security (HSTS) is enabled.
- Nothing to breach: our site is a static marketing website — it has no user accounts, no passwords, no customer database and no comment forms. There is no store of personal data on the website itself.
- Hardened headers: the site ships with Content Security Policy, X-Frame-Options, nosniff and referrer protections to block common web attacks such as clickjacking and cross-site injection.
- Minimal footprint: we keep the site simple on purpose. Fewer moving parts means fewer things that can go wrong.
2. Payment Security
- All payments are processed by PayPal, a PCI-DSS compliant payment processor. Card data is entered on PayPal's infrastructure — never on our site.
- We only ever receive your name, email and payment confirmation. We never see or store your full card number.
- We will never ask you to send card numbers, bank details or passwords by email or WhatsApp. If someone claiming to be TavernMark does, it's not us.
3. How We Protect Order Information
- Order files (artwork, proofs, invoices) are stored in access-controlled business accounts with two-factor authentication enabled.
- Access is limited to the people directly working on your order.
- We verify order-critical changes — payment requests, bank detail changes, shipping addresses — by confirming through a known channel before acting.
4. Phishing Awareness
Impersonation scams target small businesses. Please note:
- Legitimate TavernMark email comes only from @tavernmark.com addresses.
- Our only payment channels are the PayPal requests we send for your order. We will never redirect you to a different payment "agent" or personal account.
- If a message pressures you to pay urgently to a new account, verify with us first — by phone or WhatsApp at the number listed on our site — before paying.
5. Report a Vulnerability
Found a weakness on our site? Tell us instead of exploiting it. Email hello@tavernmark.com with the subject "Security Report". We'll acknowledge within 72 hours, fix genuine issues promptly, and — with your permission — credit you here for responsible disclosure. Please don't run tests that degrade our service or touch data that isn't yours.
6. Your Part
Use a unique password and two-factor authentication on your email and PayPal accounts — for most small businesses, that single habit prevents more incidents than any firewall. Questions: hello@tavernmark.com