MultiverseWorks

DOCUMENT 05 OF 06

Trust & Security

Issued by
Multiverse Works LLC
Last updated
August 13, 2026
Applies to
multiversalpolymathcreative.com
Governs
Security, incidents, and accessibility

ABOUT THIS DOCUMENT

This document was written by the studio to describe how it actually operates. It is provided for general information, it is not legal advice, and no attorney review is claimed. The summaries marked "In plain terms" are for convenience only; the full text of each section controls.

IN PLAIN TERMS

We keep the studio small and careful. Card payments run through a PCI-DSS compliant payment provider, so we never see or store your full card number. We encrypt data in transit, limit who can access your files, vet the tools we use, and privacy is built into the site by default.

1 — Our commitment

Multiverse Works LLC is a Wyoming limited liability company formed in Wyoming, USA. We operate from 547 NE Eliason St, Poulsbo, WA 98370, USA. We treat the security of your project files, payments, and personal information as part of doing good work. This page describes the practical steps we take. It is written for a small, remote studio and reflects how we actually operate. It is not a SOC 2 report and does not claim ISO 27001 or similar certifications we do not hold.

2 — Payment security

All payments are handled online through a third-party payment provider that maintains PCI-DSS compliance, the card industry’s security standard. Your card details are entered on and processed by the provider, not by us. We do not receive or store your full card number. We keep only limited billing records, such as the invoice, the amount, and a confirmation reference.

We will never ask you to send a full card number by email or chat. A genuine invoice arrives as a link we send you to our payment provider.

3 — Data in transit and at rest

Our website is served over HTTPS, so information you send through it is encrypted in transit. Project files and correspondence are stored with reputable providers that offer encryption and access controls. We use secure links for file delivery rather than sending sensitive files as open attachments.

4 — Access controls

Access to your information is limited to what is needed to run your project. We protect the accounts we use with strong, unique credentials and, where available, multi-factor authentication. We remove access that is no longer needed.

5 — Service providers

We rely on a small set of trusted providers for payments, email, hosting, analytics, and file delivery. We choose established providers that maintain their own security programs and process your information under their own security and privacy obligations. Our Privacy Policy explains how information is shared with them.

Typical provider categories, used only as needed, include:

  • Website hosting and content delivery.
  • Email and contact-form delivery.
  • A PCI-DSS compliant payment provider.
  • Secure file delivery.
  • Optional analytics, error monitoring, support chat, and advertising tools, which load only if you allow their cookie category.

6 — Privacy by design

We collect only what we need to scope, deliver, and bill a project. Non-essential cookies and third-party tools are blocked until you allow them, we honor Global Privacy Control, and we do not sell your personal information. Our consent tool loads outside tools only for the categories you have allowed.

7 — Reliability and delivery

Final deliverables are provided as organized files by secure link once the closing payment is received. If a delivered file is ever corrupted or missing, we re-deliver it at no charge. We keep project records for the life of your engagement and as required by law, as described in our Privacy Policy.

8 — If something goes wrong

No system is perfectly secure. If we become aware of a security incident that affects your personal information, we will investigate promptly, take steps to contain and fix it, and notify you and any authorities as required by applicable law.

Where GDPR or UK GDPR applies and the incident is a personal-data breach that must be reported, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will notify affected individuals when the law requires that notice.

9 — Accessibility

We design the Site to be usable by as many people as possible. That includes a skip-to-content link, labeled form fields, visible focus, semantic headings, and a layout that works on small screens. We aim to meet the Web Content Accessibility Guidelines (WCAG) 2.2 Level AA where it is reasonably practical for a small studio site.

If you have trouble using the Site, email hello@multiversalpolymathcreative.com or call +1 (360) 994-1062 and describe the page and the barrier. We will work with you to provide the information another way and to fix the issue where we can.

10 — Your part in staying secure

You can help keep your project safe. Keep your email account secure, be cautious with unexpected messages, and confirm payment details with us directly if anything looks off. We will never ask you to send full card numbers by email, and any real invoice comes from our payment provider through a link we send you.

11 — Reporting a security concern

If you believe you have found a security issue with our website, or you have a question about how we protect your information, contact us and we will respond promptly:

YOUR CONTROLS

Privacy choices stay within reach.

Review cookie categories or opt out of sale, sharing, and targeted advertising for this browser at any time.