Payment & Financial Compliance
Information on payment security, encryption, and regulatory compliance.
1. PCI-DSS Level 1 Payment Processing via Stripe
All credit card and payment processing for Pumpkin Slices group upgrades ($2.99) is powered directly by Stripe. Stripe is certified as a PCI Service Provider Level 1, the highest level of certification available in the payments industry.
2. Zero Credit Card Storage Policy
Pumpkin Slices operates under a strict zero-card-storage policy. When you enter card information during checkout:
- Your payment details are transmitted directly from your web browser to Stripe via encrypted iframe/tokenization.
- No credit card numbers, CVVs, or expiration dates ever touch or pass through Pumpkin Slices servers.
3. 256-Bit SSL/TLS Transport Encryption
All data transmitted to and from Pumpkin Slices is encrypted using 256-bit SSL/TLS protocols, ensuring that your group information and network requests are protected from interception.
4. One-Way Passcode Hashing
Group passcodes created by users are processed using secure cryptographic one-way hashing (`passcode_hash`) before storage. Passcodes cannot be reversed or retrieved in plain text by server administrators or third parties.
5. Non-Custodial Disclaimer
Pumpkin Slices is a calculation tool for group expense tracking. We do not act as an escrow agent, money transmitter, or financial intermediary. All peer-to-peer reimbursements take place independently between individuals outside of the app.