Payment security

How PayFacile protects your customers’ payments: PCI DSS compliance via Stripe, SSL encryption, 3D Secure, SEPA mandates, and EU hosting.

What protects your customers’ data

Your customers are hesitant to pay online? Here’s what protects their data: no card numbers ever pass through PayFacile, payments are encrypted end-to-end, and strong authentication is enabled automatically.

No card data on our servers

This is the most critical point: when your customer enters their card information, it is sent directly to Stripe via an embedded form (Stripe Elements). PayFacile only receives a payment confirmation and a transaction identifier. Your card data stays exclusively with Stripe.

PCI DSS compliance via Stripe

Stripe is certified PCI DSS Level 1, the highest compliance level in the payment industry. This certification covers collection, processing, and storage of card data.

By using Stripe as a payment processor, you benefit from this compliance without managing it yourself. No PCI DSS steps required on your end.

SSL encryption and strong authentication

All PayFacile pages (dashboard, sales pages, checkout) are served over HTTPS with a valid SSL certificate. Data exchanged between your customer’s browser and our servers is encrypted.

European regulation (PSD2) requires strong customer authentication (SCA) for online payments. Stripe automatically triggers 3D Secure when the customer’s bank requires it. You don’t need to configure anything on the PayFacile side.

SEPA mandates and European hosting

For SEPA direct debits, GoCardless manages the creation and storage of debit mandates. The customer signs an electronic mandate during the first payment.

PayFacile is hosted on Meteor Galaxy EU West 1 (Ireland). Your business data (orders, customers, products) is stored in the European Union. Payment data is held by Stripe and GoCardless, who also have European infrastructure.

Expected result: your customers’ trust

Your customers see a recognized Stripe payment form, an SSL padlock in the address bar, and 3D Secure authentication from their bank. You don’t need to configure anything—it’s all active by default.

FAQ

Is PayFacile PCI compliant?
PayFacile does not handle card data—Stripe does. Stripe is certified PCI DSS Level 1, the highest standard in the industry. You benefit from this compliance automatically.
Where is my data stored?
Your business data is hosted in the EU (Meteor Galaxy EU West 1, Ireland). Payment data is stored by Stripe and GoCardless on their own secure infrastructure.
Is 3D Secure enabled automatically?
Yes. Stripe triggers 3D Secure automatically when the customer’s bank requires it, in compliance with PSD2 regulation. No configuration needed on your part.
What happens in case of fraud?
Stripe has a fraud detection system (Stripe Radar) that blocks suspicious transactions. In case of a dispute (chargeback), you are notified through your Stripe dashboard to provide evidence.
Was this helpful?