Qstomize

Information Security Policy

Green Lunar LLC (d/b/a Qstomize) · Last updated September 29, 2026

Qstomize handles customer information every day, and we take protecting it seriously. This page summarises the information security policy that everyone who works on Qstomize is required to read and follow. It is reviewed at least once a year.

How your card payment is protected

  • All card payments on qstomize.com, including payment links we send you, are processed by PayPal, a PCI DSS Level 1 certified service provider.
  • Your card number is typed into secure fields hosted by PayPal inside our checkout page. It goes straight to PayPal and never passes through, or is stored on, Qstomize's servers.
  • We never ask for card numbers by email, phone or chat, and we never write them down. If anyone claiming to be Qstomize asks you for your card details that way, do not share them and let us know.

Protecting the data we do hold

  • We keep only the information needed to make and deliver your order, such as your name, contact details, shipping address, artwork and order history.
  • Information is classified by sensitivity and handled accordingly. Confidential customer information is shared only with the people and partners who need it to fulfil your order.
  • Data is sent over encrypted connections (HTTPS/TLS), and our website runs on a cloud hosting provider that maintains its own security and compliance programme.
  • Information that is no longer needed is securely deleted.

Access control

  • Access to our systems is limited to authorised people, on a need-to-know basis, with individual accounts and strong passwords.
  • Credentials and keys are kept in secured configuration, never in shared documents or code.
  • Access is reviewed regularly and removed promptly when someone no longer needs it.

Suppliers and service providers

  • We use established service providers for payments and hosting, and check that the providers who handle payment data are PCI DSS compliant.
  • Production partners receive only what they need to make and ship your order. We never pass them your payment details.

People and awareness

  • Everyone working on Qstomize agrees in writing to follow this policy and to keep customer information confidential.
  • Security incidents or suspected incidents must be reported immediately.

Incident response

If we suspect that customer or payment information has been compromised, we act immediately to contain it, investigate, and notify the affected customers, our payment processor and any other parties as required by law and card brand rules. We then review what happened and strengthen our safeguards.

Reporting a security concern

If you believe you have found a security issue on our website, or received a suspicious message that claims to come from Qstomize, please email support@qstomize.com with the subject line "Security".

See also our Privacy Policy and Terms & Conditions.