Skip to main content

Security & Data Protection

Last Updated: February 1, 2026

Clients trust Think1 Designs with their websites, their customer data and their business operations. This page explains, in plain language, the practices we use to protect that information. It is maintained by Think1 Designs, LLC and describes our own controls; it is not a certification or an independent audit.

Access to the Think1 Designs Client Portal and internal Agency OS requires an individual account tied to a verified email address. Sign-in runs over encrypted connections, sessions expire after a period of inactivity, and repeated failed attempts are rate limited. Client Portal access can additionally be verified with a one-time PIN sent to the email address on file.

Passwords are never stored in readable form. They are hashed using industry-standard algorithms by our authentication provider, and our staff cannot view them. We encourage strong, unique passwords and support password resets through a verified email link.

Every account is assigned a role — for example owner, administrator, staff, contractor or client — and each role grants only the permissions needed for that person's work. Permissions are enforced on the server, not just hidden in the interface, so a user cannot reach data outside their role by manipulating the browser.

Client Portal accounts are scoped to a single client organization. Projects, documents, invoices, appointments and support tickets are filtered by that scope at the database level, so one client can never see another client's records. Portal activity such as sign-ins, document views and signatures is recorded in an append-only audit trail.

Our CRM holds contact, lead, project and communication history. It is accessible only to authorized Think1 Designs staff, protected by row-level security rules on the database and by permission checks on every server request. Administrative actions are logged for accountability.

All traffic to our website, the Client Portal and our internal systems is served over HTTPS with modern TLS. Certificates are managed automatically and renewed before expiry. Data is also encrypted at rest by our hosting and database providers.

Proposals, contracts, signed documents and uploaded files are stored in access-controlled storage. Signature requests use unique, expiring links, and each signed document is fingerprinted so any later modification is detectable. Signature events record the signer, timestamp and verification details.

Transactional email is sent through a reputable delivery provider with SPF, DKIM and DMARC configured for our sending domain, which protects recipients from spoofed messages. Delivery events are logged so we can confirm whether an important message such as an invoice or PIN reached its recipient.

Databases and hosted client websites are backed up on a regular schedule by our infrastructure providers, with point-in-time recovery available on supported plans. Backups are encrypted and retained for a rolling period so we can restore after accidental deletion or corruption.

Administrative and infrastructure access is limited to a small number of trusted personnel who need it. Credentials for client systems are stored in an access-controlled vault rather than shared in email or chat, access is reviewed when roles change, and it is revoked promptly when someone leaves a project or the company.

We monitor application errors, delivery failures and unusual account activity. If we identify a security incident affecting client data, we investigate immediately, take steps to contain it, and notify affected clients without undue delay with the facts as we understand them and the actions we are taking.

If you believe you have found a security vulnerability in a Think1 Designs website or system, please tell us at info@think1designs.com with the subject line “Security Report”. Include the steps to reproduce and any supporting detail. We ask that you avoid accessing or modifying data that is not yours, avoid disruptive testing such as denial-of-service, and give us reasonable time to remediate before public disclosure. We acknowledge reports promptly and will keep you updated on our progress.

We use established providers for hosting, databases, authentication, email delivery, payments, scheduling and analytics. We select vendors with recognized security practices, connect to them over encrypted channels, and share only the data required for the integration to work. Payment card details are handled entirely by our payment processors and never touch our servers.

We collect only what we need, use it for the purpose it was given, and retain it no longer than necessary. We do not sell client or visitor data. Full detail on what we collect and your rights is available in our Privacy Policy.

Security is a partnership. Think1 Designs is responsible for the platforms and services we build and operate for you. Clients are responsible for protecting their own account credentials, granting portal access only to people who should have it, keeping their internal devices secure, and telling us promptly if an account may be compromised. Third-party platforms you use alongside our work remain governed by their own security practices.

For any security or data protection question, contact Think1 Designs, LLC at info@think1designs.com or +1 210-580-6646, San Antonio, Texas.