DOC LM-TR1 · EFFECTIVE 21 AUG 2026
what we actually do, not a wall of badges
Our approach
minimization beats mitigation
Lesson Mugs LLC is a Wyoming LLC formed in Wyoming and operates a workshop in Leonia, New Jersey. Our security model starts with collecting almost nothing. No accounts, no passwords, no card numbers, no ad trackers — the less data we hold, the less there is to protect, and the less there is to lose.
Transport security
https everywhere, no exceptions
The Site is served over HTTPS/TLS on every page, with HSTS enabled so browsers refuse insecure connections. Anything you send us travels encrypted.
Payments
card numbers never touch us
This Site has no live checkout and stores no payment data. Card payment is planned: after a written USD quote is approved, the intended architecture is full-page Stripe-hosted Checkout so the PAN never enters our Worker, D1, Resend, tawk.to, or email. Lesson Mugs LLC is not PCI DSS certified and has not completed an SAQ, AOC, or QSA assessment. The quote form collects no payment information of any kind. Do not send card numbers through forms, chat, or email.
What we store & who helps us
the subprocessor list, in the open
We store quote requests, order records, and the newsletter list — nothing more. Named processors: Cloudflare (hosts these pages), Migadu (inbound email), Resend (quote and newsletter mail), Termly (consent), tawk.to (optional chat after Performance and Functionality consent), shipping carriers, and planned Stripe-hosted Checkout. Typefaces are self-hosted. Each recipient gets the minimum required, under contract.
Access & operations
few keys, few doors
Access to business systems is limited to the people who need it, protected with strong passwords and two-factor authentication, and reviewed when roles change. Software and dependencies are kept updated. We don’t sell data under any circumstances, so there’s no advertising pipeline to secure.
Incident response
if something breaks, you hear it from us
If we ever suffer a data breach that affects you, we’ll notify the relevant supervisory authority within 72 hours where GDPR requires it, email affected customers promptly in plain English, and publish what happened and what we changed. Hiding bad news is not on the syllabus.
Reporting a vulnerability
found something? tell us, get thanked
If you’ve found a security issue, email records@educationalmugs.com (or call +1 (551) 348-8301) with the details. We acknowledge reports within one school day, don’t threaten researchers acting in good faith, and credit you in the fix notes if you’d like.
Honest limitations
we’d rather be straight than certified-looking
We don’t hold SOC 2 or ISO 27001 certifications, and we do not claim PCI DSS certification. We’re a small studio, not a data center, and we won’t pretend otherwise with badge clip-art. This page describes what we genuinely do. If your school district or organization needs a specific security questionnaire or DPA filled out, email records@educationalmugs.com and we’ll do the paperwork properly.