Security and data handling
What happens to your information here.
Facts about this site, stated plainly: where it runs, what it keeps, who handles what, and the audits behind each provider. Our Privacy Notice covers the legal side.
Where the site runs
jmrlawgroup.com and its filing tools are hosted on Netlify. The code that pulls USPTO records, prepares your filing record and starts a payment runs as Netlify functions on Amazon Web Services in the United States. Every page and request is served over HTTPS.
What we keep on the site
Nothing. There is no database behind this site. When you complete a filing, the record — your elections, specimens, signature and the USPTO snapshot — is emailed to the firm and referenced by its record ID in our payment processor. The site itself retains no copy. The only things that persist on our hosting are a one-hour cache of the public USPTO records you look up, so repeat lookups are fast, and short-lived operational logs.
Payments
Payments are taken by Stripe on Stripe's own pages. Card and bank details never reach jmrlawgroup.com; we receive confirmation, the amount, the card brand and last four digits, and Stripe's reference numbers. Stripe is certified annually as a PCI DSS Level 1 Service Provider, the highest level of certification in the payments industry. Where a bank in Europe requires strong customer authentication, Stripe handles that step on its pages.
Everything we send — confirmations, receipts, filing updates — goes from tm@jmrlawgroup.com through Resend, a transactional email provider, and the filing record travels the same way to our mailbox on Microsoft 365. Resend transmits and logs under a data-processing agreement; no one there reads your message. Our mail domain is authenticated (SPF and DKIM) so mail from us can be told from mail pretending to be from us.
The USPTO
Status lookups and the contact form's verification call the USPTO's TSDR service from our server, using the firm's own API key; your browser does not talk to that service. Mark images on status pages are the one exception: your browser loads them directly from the USPTO. The filing we make for you becomes part of the USPTO's public record, as every trademark filing does.
On your device
The site sets no cookies and runs no analytics, advertising or tracking scripts. Fonts and every other asset are served from jmrlawgroup.com, so a visit here makes no request to a third party except Stripe at checkout and the USPTO for mark images. The filing tool keeps your in-progress answers in your browser's session storage so you can come back from the payment page; that storage never leaves your browser and clears when the tab closes.
Links and codes
Private links that pre-fill a matter, and codes that apply an agreed fee arrangement, are signed with a secret held only on the server, so they cannot be altered or forged, and they expire. Codes themselves never appear in the site's code. Every use is recorded in the filing record the firm receives. Filing pages are excluded from search engines.
Keys and accounts
API keys and secrets are held as encrypted environment variables on the hosting platform, never in the site's code. The email key can send but not read.
Who handles what
| Provider | Role | Independent attestations | Terms |
|---|---|---|---|
| Netlify | Hosting, functions, TLS | SOC 2 Type 2, ISO 27001, ISO 27018, PCI DSS v4.0, HIPAA — trust center | DPA |
| Stripe | Payments | PCI DSS Level 1 Service Provider — security | DPA · Data Privacy Framework |
| Resend | Email delivery | SOC 2 Type II — report | DPA |
| Microsoft 365 | The firm's mailbox | SOC 2, ISO 27001 and others — trust portal | DPA |
| USPTO | Public trademark records; receives filings | United States government agency | — |
Attestations are each provider's own, as published on the pages linked, and are not a certification of this site or of the firm. Data is processed and stored in the United States.
What we do not do
We do not sell personal information, share it for advertising, build marketing lists from it, or send anything you enter here to an artificial-intelligence service. We keep only what a filing needs, for as long as the Privacy Notice says.
Report a concern
If you believe you have found a security problem with this site, email tm@jmrlawgroup.com with "Security" in the subject line. We read those first.