Security and GDPR

What happens to your data and your customers' data when you sell through Checkout Page, and the commitments we make about it.

Card details never reach us

Payments run on your own Stripe account. Card numbers and security codes go straight from the buyer's browser to Stripe, and money lands in your Stripe balance without passing through us. We store only what we need to show you an order: the card brand, the last four digits, the country, the payment status and Stripe's transaction reference.

Because the payment lives in your Stripe account, you keep the payment record even if you stop using Checkout Page.

Where your data is stored

Our application and database run in the United States. Some of the services we use store data in the EU. Every company that processes data for us is listed on the subprocessors page, with what it does, where it runs, and what data it sees. We update that page and email account owners at least 30 days before we add or replace a subprocessor.

GDPR

For the personal data of your buyers, you are the controller and Checkout Page is your processor. You decide what to collect and why. We process it to run your checkouts and nothing else.

Our Data Processing Addendum is part of our Terms of Service, so it applies to your account automatically and nobody has to sign a contract. It includes the EU Standard Contractual Clauses for transfers outside the EEA, the UK Addendum and the Swiss adaptations. If your procurement team needs a copy for their records, they can save or print the page.

Your buyers' requests to access, correct or delete their data come to you, and you can act on them in the dashboard. If you need help with a request, email security@checkoutpage.com.

How we protect the data

  • Data is encrypted in transit, and encrypted at rest in our database and file storage.
  • Access to production systems is limited to the people who need it, uses strong authentication, and is removed when someone no longer needs it.
  • We log system activity and monitor for availability problems and suspicious behaviour.
  • Backups run on a fixed schedule and expire within 3 months. We can restore the service after an incident.
  • If a breach affects your data, we tell you by email without undue delay, and where feasible within 72 hours of becoming aware of it.

What you control

  • Export your customers, payments, subscriptions, bookings and form submissions as CSV at any time.
  • Delete a store and its data goes with it. Backup copies expire within 3 months.
  • Add and remove team members, each with their own login.
  • Sign in with Google to put your Google account's two-factor authentication in front of your Checkout Page account.

Who else can reach your data

Nobody, until you say so. The API keys you create in Settings, the apps you connect over MCP, and integrations like Zapier and Google Sheets all read your store data with your permission, and you can revoke any of them at any time.

Once data reaches a tool you connected, that tool's provider handles it under your agreement with them, not ours. If you connect an AI assistant over MCP, treat that the same way you would treat any other place you send customer data.

Payments and PCI

Stripe is certified PCI DSS Level 1 and hosts the card fields on your checkout, so card numbers never touch our servers or yours. For most sellers that means the shortest PCI questionnaire, SAQ A. Your acquirer or Stripe can confirm which applies to your business.

Questions from your security team

For security questions or to report a vulnerability, email security@checkoutpage.com. TheDPA is available on our site, with a signed PDF to download.