Security & payments
Last updated: {{DATE_EFFECTIVE}}
How your payment details are handled when you buy from this website, and what we do and do not hold.
We never see your card number
Payments on this website are processed by Stripe, Inc. Card details are entered into a payment form hosted and served by Stripe, transmitted directly to Stripe over an encrypted connection, and never pass through or rest on our servers. We do not store, log or have any way to retrieve your full card number, expiry date or security code.
What we receive from Stripe, and keep, is limited to: the last four digits of the card, the card brand, the country the card was issued in, the amount, the currency, the date, and whether the charge succeeded. That is what lets us identify a charge for you if you ask about it.
PCI compliance
Stripe is certified as a PCI Service Provider Level 1, the most stringent level of certification available in the payments industry. Because card data is captured directly by Stripe's hosted payment form and never touches our infrastructure, our own PCI scope is limited accordingly, and we maintain it under the applicable self-assessment questionnaire.
This website
- Every page, including every payment page, is served over HTTPS with a valid TLS certificate. Plain HTTP requests are redirected.
- Traffic passes through a content delivery network that filters common attack patterns and rate-limits abusive request volumes.
- Administrative access to our hosting, our payment dashboard and our email is protected by multi-factor authentication.
- Payment attempts are monitored for card testing patterns, and suspicious volumes are blocked automatically.
Cards we accept
Visa, Mastercard, American Express and Discover, plus Apple Pay and Google Pay on supported devices.
Your statement
Charges from us appear as {{STATEMENT_DESCRIPTOR}}. If you do not recognise a charge, email {{EMAIL_SUPPORT}} before opening a dispute with your bank. We will identify it the same business day, and refund it if it should not have been made.
Reporting a vulnerability
If you believe you have found a security flaw in this website or in one of our products, write to {{EMAIL_SECURITY}} with enough detail to reproduce it. We acknowledge reports within two business days. Please do not access, modify or delete data belonging to anyone else while testing.
How we handle your personal data
Described in full in our Privacy Policy.