FAQ / Data Security
Data Security
Security, privacy and compliance for checkout, billing and the customer portal.
Who processes payments?
Payments run through Stripe. Card data is handled by Stripe under their PCI scope — Checkivo does not store raw card numbers on our servers. You connect your own Stripe account.
Is Checkivo PCI compliant?
Cardholder data is processed by Stripe (PCI DSS Level 1). Checkivo is designed so sensitive payment fields stay in Stripe-hosted / Stripe.js flows rather than hitting our application servers as PAN data.
Where is data hosted?
Application and database infrastructure runs on modern cloud providers in the EU / regions appropriate for European merchants. Payment data residency follows your Stripe account settings.
How do you handle GDPR?
Checkivo supports GDPR-aligned processing for EU merchants: clear roles (you are typically the controller for customer data; we act as processor for platform data), data processing terms, and tools to export or delete customer data via the portal and APIs where applicable.
Do you sell customer data?
No. Merchant and shopper data is used to operate checkout, subscriptions and support — not sold to third parties for advertising.
How is access to merchant accounts protected?
Access uses authenticated sessions, Shopify app OAuth for install, and Stripe Connect / API keys scoped to your account. We recommend enabling 2FA on Shopify, Stripe and email accounts tied to your store.
What about the customer portal?
Shoppers manage subscriptions through a secured portal link or login flow. Actions like pause, skip, cancel and payment-method update are authorized per customer and subscription.
Do you run penetration tests?
We follow secure development practices and review critical payment and auth paths regularly. For formal questionnaires, trust documentation or DPAs, contact us via /contact/ or see /security/.
How long do you retain logs?
Operational and security logs are retained only as long as needed for reliability, fraud prevention and legal obligations, then rotated or deleted according to our retention policy.
Where can I read more?
Visit the Trust Center at /security/ for product security, GDPR and compliance overviews, or email [email protected] for a DPA / security questionnaire.