
How we protect your donors, volunteers, and funds
At PayPinz, the security of your transactions, donor personal data, and fundraising integrity is our highest priority. We use industry-standard protocols to ensure enterprise-grade protection.
All credit card payments are processed securely via **Stripe, Inc.** PayPinz never has access to, nor stores, sensitive card numbers, bank routing credentials, or CVVs. All transactions are tokenized at the browser level. Stripe is certified as a **PCI-DSS Level 1 Service Provider**, the most stringent security level in the payments industry.
* **In Transit:** All communications between your browser, our servers, and payment elements are encrypted using high-grade **TLS 1.3 (HTTPS)** protocols. * **At Rest:** All donor databases, user profiles, and logs are encrypted at rest using **AES-256** (Advanced Encryption Standard), ensuring data remains unreadable even in the event of physical database access.
We use **Firebase Authentication** (backed by Google) for secure logins, sign-ups, and password recoveries. All user account credentials are encrypted and stored inside Google's secure credential vaults. We enforce strict password complexity policies, and session authorization tokens (JWTs) are validated server-side for every dashboard action.
Our application servers are hosted on **Vercel's global edge network**, featuring built-in web firewalls, automated threat monitoring, and enterprise-grade DDoS mitigation. Database servers run on **Google Cloud Platform (GCP)** within secure regional data centers, backed by Google's top-tier physical security and automated redundancy sweeps.
We process donor details for Gift Aid declarations (Name, Address, Postcode) in strict compliance with the UK Data Protection Act / GDPR. These records are held solely for the statutory **6-year HMRC retention period** and are encrypted. Only verified, authorized administrators of the recipient charity have access to export these files.
We actively review our dependencies and database rules to maintain a secure environment. If you believe you have discovered a vulnerability, please contact our security team directly at **security@paypinz.com**.
We use cookies to improve your experience
We use Google Analytics to understand how visitors use PayPinz. No personal data is sold. Privacy Policy