Card data transmission security policy
My Company
The store does not capture, process or store card numbers in its infrastructure. Card data is transmitted encrypted directly to the authorized payment processor.
1. Transmission encryption
The entire site operates under the HTTPS protocol with a valid SSL/TLS certificate. The information the customer enters travels encrypted end to end between their browser and the server, so it cannot be read or altered by third parties during transmission. The padlock shown by the browser in the address bar confirms that the connection is secure.
2. Capture of card data
Sensitive authentication data (card number, expiration date and CVV/CVC security code) is captured in the payment processor's environment, through forms hosted by that processor. At no time does this data pass through our systems or get recorded in our databases, backups or application logs. Our staff has no access to it.
3. Payments and external providers
The payment methods used by the store are third-party services. Card processing is carried out through an authorized payment processor that complies with the security and encryption standards applicable to the payments industry, and that uses the information only to complete the authorization and settlement of the transaction.
Los métodos de pago utilizados son servicios de terceros que cumplen con los estándares de seguridad y cifrado de la industria.
We recommend that the cardholder also review that provider's privacy policy to understand how it handles the information provided.
The information that the store does keep, such as billing data and order history, is stored encrypted and with restricted access.
4. PCI DSS compliance
Payment processing is carried out through processors and acquiring entities that maintain valid certification under the PCI DSS (Payment Card Industry Data Security Standard), the international standard governing the protection of cardholder data. The store keeps its PCI scope reduced precisely by not storing card data.
5. 3D Secure authentication
Transactions are subject to the 3D Secure authentication protocol, under the Verified by Visa and Mastercard ID Check programs. The card issuing bank validates the cardholder's identity before authorizing the charge, using a one-time code or another mechanism defined by the issuer. This additional verification protects the customer against unauthorized use of their card.
6. Internal controls
- System access restricted by role and under the principle of least privilege.
- Multi-factor authentication for staff with administrative access.
- Audit log of the operations performed on orders and payments.
- Encrypted backups and security updates applied periodically.
- Transaction monitoring for the detection of fraud patterns.
7. Recommendations for the cardholder
- Check the security padlock and that the address starts with https:// before entering data.
- Do not share your security code (CVV), your passwords or the one-time codes sent by your bank. Our staff will never ask you for them.
- Avoid making payments from public Wi-Fi networks or shared devices.
- Review your statements and immediately report to your bank any charge you do not recognize.
8. In the event of an incident
If you detect an unrecognized charge or suspect misuse of your card on our site, immediately contact your issuing bank and notify us through the customer service channels published on this page to start the corresponding investigation.
Contact for this policy
Any question about this policy can be directed to our customer service. We respond to every request received through the published channels.