Client Data Storage and Security Overview
Document prepared on 26 July 2026
For visitors in the European Union, cookies and similar technologies are governed by the ePrivacy rules and GDPR. Non-essential cookies normally require clear, specific, informed and freely given consent before they are stored or read.
What Data Is Stored
Clients Company name, client name, email, phone, billing and
shipping addresses.
Wix Data collections, primarily
WorkflowJobs client-directory records.
Quotes and invoices
Quote/invoice numbers, tokens, project details, line items,
quantities, turnaround, totals, VAT, payment status and
correspondence status.
Quotes collection and WorkflowJobs
invoice/workflow records.
Artwork approval
Artwork links, version links, approval status, proof response,
amendment notes, signature/name fields and proof tokens.
WorkflowJobs proof/artwork records.
Artwork files may be stored in Google
Drive where upload links are used.
Suppliers/products
Supplier contact details, product names, description variants,
turnaround values and supplier mappings.
WorkflowJobs supplier-directory and
product-directory records.
Timesheets
Month, client, invoice, note/job reference, time category,
start/end times and duration.
WorkflowJobs timesheet records.
Backups
Exported page or directory backup data, including chunked
backup records.
WorkflowJobs data-backup and
data-backup-chunk records; optional
emailed/downloaded backup files.
Security Controls Visible in the Current System
Admin functions require an admin access key or a valid staff portal session before private pages are shown.
Workflow pages require workflow-level access or an admin session.
Staff sessions use a signed portal session cookie called dp_portal_session with a one-hour expiry.
Customer-facing quote, invoice, upload and artwork proof pages use tokenised URLs rather than public index pages.
API keys and integration credentials are requested through Wix Secrets, including SendGrid, Stripe and QuickBooks secrets.
The backend sanitises many text fields before rendering them into HTML and normalises artwork/Drive URLs.
Client upload files are routed through a Google Apps Script/Drive workflow rather than being attached directly to emails.
Backup and restore pages require admin access.
Third-Party Services
Wix
Provider Purpose: Website hosting, HTTP functions, Wix Data storage, media handling, member authentication, triggered emails and secrets storage.
SendGrid
Provider Purpose: Transactional email delivery for quotes, invoices, artwork proof notifications and workflow
messages.
Stripe
Provider Purpose: Payment links and payment webhook processing.
QuickBooks / Intuit
Provider Purpose: Accounting and payment/accounting integration.
Google Drive / Apps Script
Provider Purpose: Artwork/client upload storage and transfer where Drive upload links are used.
Recommended Operational Controls
Keep the admin and workflow access keys private and rotate them when staff access changes.
Review Wix roles, member permissions and collection permissions regularly.
Keep Google Drive artwork folders restricted to staff who need access.
Use unique staff logins where possible rather than sharing passwords.
Keep a dated restore backup after each major site publish.
Confirm retention periods for client data, invoice data, artwork proofs and backups, then document those retention periods in the live privacy notice.
Official References
ICO, Guide to the UK GDPR - transparency and the right to be informed: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-to-be-informed/
ICO, Security principle and data security guidance:
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/
ICO, Cookies and similar technologies under PECR: https://ico.org.uk/for-organisations/direct-marketing-and-privac
y-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/
European Commission, Cookies and EU/ePrivacy information: https://commission.europa.eu/cookies_en
European Data Protection Board, Guidelines 05/2020 on consent under GDPR: https://www.edpb.europa.eu/our-wo
rk-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en








































