Data & Security
Last updated: August 31, 2026
1. Overview
CreativeWork uses technical and organizational measures to protect accounts, marketplace data, booking information, communications, and payment-related records. This page describes the current practices used to operate the service.
It should be read with the Privacy Policy, Cookie Policy, and Payments & Disputes. No online service can guarantee absolute security.
2. Security Responsibilities
Security is shared between CreativeWork, its infrastructure, payment and authentication providers, and users.
CreativeWork protects the platform, access controls, and the systems it operates. Users are responsible for protecting their login and account, not sharing access, using secure devices, and reporting suspicious activity.
3. Account Authentication
CreativeWork uses Firebase Authentication for account sign-in. Users may verify an email address or sign in with Google. Firebase / Google may process authentication data, including password handling where email sign-in is used.
CreativeWork does not store user passwords or password hashes for ordinary user accounts. After authentication, CreativeWork issues its own session so the signed-in user can use the platform.
4. Account and Session Security
When you sign in, CreativeWork sets an httpOnly session cookie so the browser does not expose the token to ordinary page scripts. In production, that cookie is marked Secure and uses a SameSite restriction. It is normally set to expire after 7 days.
Requests that need an account are checked against a valid session and an active account. Deactivated accounts cannot use an ordinary session. More detail on browser storage is in the Cookie Policy.
5. Access Controls and Authorization
CreativeWork uses access controls so users should only perform actions and see records associated with their account or role. Examples include:
- booking records for the client and creator on that booking
- chat rooms for members of that conversation
- service and portfolio changes for the owning creator
- payment and wallet records for the signed-in account
Authorized people and systems may access information needed to operate, support, or secure the service. This page does not claim that every endpoint has been independently audited.
6. Payment Security
Payment-card entry and processing are handled through Stripe, including Stripe.js and Stripe APIs. CreativeWork does not store full card numbers or CVC codes.
CreativeWork may store Stripe identifiers, card brand and last four digits returned by Stripe, amounts, currency, payment status, and transaction references. Payment rules are in Payments & Disputes.
CreativeWork is not itself PCI DSS certified. Card data is handled through Stripe’s payment infrastructure.
7. Creator Payment / Stripe Connect Security
Creators who receive payouts complete Stripe Connect onboarding. Identity, business, bank, and verification information is provided directly to Stripe.
CreativeWork stores Stripe connected-account identifiers and onboarding status needed to operate bookings and payouts. It does not store creator bank or KYC documents.
8. Data Storage and Infrastructure
CreativeWork runs Dockerized application services with a PostgreSQL database. Production traffic is served over HTTPS/TLS. Uploaded files are stored on CreativeWork’s application storage, not a separate object-storage product such as S3.
Authentication uses Firebase. Payments use Stripe. Email is sent through an SMTP mail provider. Hosting, database, and related infrastructure providers may process information as needed to operate those services.
9. File and Media Security
Users may upload profile images, banners, service covers, portfolio media, and chat attachments. Uploads require a signed-in account. CreativeWork applies file-type and file-size limits. Chat attachments allow a wider set of types than profile images.
CreativeWork does not currently operate automatic malware scanning of uploads. Stored file URLs may be used to display the file through the service. Users should not upload content they are not permitted to share.
10. Communications and Messaging
Messages are transmitted and stored so CreativeWork can provide chat and booking communication. Access is limited to conversation members and to authorized support or operational access where needed.
Messages are not end-to-end encrypted. If you delete a message, it is hidden from ordinary chat display. The original content may remain in CreativeWork records for authorized dispute, safety, or trust-and-safety review.
11. Booking, Dispute and Safety Records
CreativeWork may retain or review booking details, messages, delivery information, payment history, reports, and related evidence to resolve disputes, investigate abuse or fraud, enforce platform rules, and meet legal or accounting requirements.
Users can report problems and block other users. Dispute conversations may include CreativeWork support where that process is used. This is not unrestricted access to all user data.
12. Logging and Monitoring
CreativeWork may generate application logs such as timestamps, request paths, and error information. IP addresses may be processed for rate limiting, security, and service operation. Payment-provider events may be received and verified so booking and payment status can stay accurate.
CreativeWork does not operate a dedicated 24/7 security operations center and does not publish internal logging formats or thresholds.
13. Fraud and Abuse Prevention
CreativeWork uses rate limiting, authentication checks, report and block tools, account and payment review, and Stripe’s payment-security capabilities. Payment or payout actions may be delayed while a dispute, fraud, or security issue is reviewed.
These controls reduce risk. They do not amount to guaranteed real-time fraud detection.
14. Third-Party Infrastructure
CreativeWork depends on third-party providers to operate the service, including:
- Firebase / Google Authentication
- Stripe, for payments and Connect onboarding
- hosting, database, and storage infrastructure
- email delivery
Those providers maintain their own security practices and policies. CreativeWork does not control their entire infrastructure.
15. Data Retention and Deletion
Retention and account deletion follow the Privacy Policy. Information may remain where needed for payment and accounting records, disputes, fraud or security, legal obligations, or technical backups.
Account deletion removes ordinary profile and listing use, but does not instantly delete every backup, payment record, or anonymized review. An account cannot be deleted while a connected Stripe account has pending or available funds.
16. Security Incidents
If CreativeWork suspects a security incident, it may investigate and take steps such as restricting access, ending sessions, suspending accounts, contacting affected users where appropriate, and working with infrastructure or payment providers.
This page does not promise a specific notification deadline unless a legal obligation requires one.
17. What Users Can Do
You can reduce risk by:
- protecting access to your email and CreativeWork account
- signing out of shared devices
- reporting suspicious messages or activity
- not sending card or bank credentials in chat
- using the official payment flows on CreativeWork
18. Limits of Security
No online system can guarantee absolute security. CreativeWork works to reduce risk but cannot guarantee that unauthorized access, technical failure, or malicious activity will never occur.
19. Changes to This Policy
CreativeWork may update this policy. Material changes apply prospectively, subject to applicable law. The Last updated date on this page will change when the policy is revised.
20. Contact
For security questions, use the Contact page and choose Customer support, or email security@creativework.com.