Compliance frameworks, security audits, and quality certifications this company maintains.
Squarespace maintains SOC 2 Type II certification, with annual third-party audits verifying that its infrastructure, hosting, and data handling controls meet the Trust Services Criteria for security, availability, and confidentiality across its website builder platform.
Squarespace Commerce and its integrated payment processing are certified PCI DSS Level 1 compliant, the highest standard for payment card data security, ensuring that merchants selling on Squarespace-powered stores do not bear direct card data liability.
Squarespace complies with the EU General Data Protection Regulation, providing data processing agreements, consent management tools, and data subject rights workflows to help European website owners and their visitors manage personal data in accordance with GDPR requirements.
Squarespace supports California Consumer Privacy Act compliance for both its platform customers and website visitors, offering data deletion requests, opt-out mechanisms, and a privacy center aligned with CCPA obligations.
Squarespace designs its templates and website editor to meet WCAG 2.1 AA accessibility guidelines, enabling users to build websites that are navigable by visitors using screen readers, keyboard navigation, and other assistive technologies.
Squarespace's information security management system is certified to ISO/IEC 27001, demonstrating a systematic approach to managing sensitive company and customer data through documented risk assessment, access controls, and security policy enforcement.
All Squarespace-hosted websites are served over HTTPS with TLS 1.2 or 1.3 encryption by default, with SSL certificates automatically provisioned and renewed, ensuring that every site on the platform encrypts traffic between visitors and the server.
Squarespace's platform and data collection practices are structured to comply with the Children's Online Privacy Protection Act, restricting data collection from children under 13 and providing guidance to website owners on COPPA obligations for their own sites.
Regulatory
ICANN Accreditation
CertifiedFollowing the acquisition of Google Domains, Squarespace operates as an ICANN-accredited domain registrar, meeting the technical, financial, and policy requirements to register and manage generic top-level domain names on behalf of its customers.
Squarespace is certified to ISO 27018, ensuring that personally identifiable information of its five million website creators and their visitors is handled according to internationally recognized cloud privacy standards across Squarespace's hosting, e-commerce, and domain services.