Legal
PCI Compliance
Last updated: July 25, 2026
LinkInBioPremium is committed to protecting payment information for creators and coaches who subscribe to Premium membership and who sell through Premium Selling on their bio pages. This page summarizes our approach to Payment Card Industry Data Security Standard (PCI DSS) compliance and how cardholder data is handled for platform billing and visitor checkouts.
1. Our compliance approach
LinkInBioPremium is designed so that we do not receive, process, or store sensitive authentication data or full primary account numbers (PANs) on our infrastructure. Premium membership checkout, recurring billing, and card/PayPal creator Selling payments (Stripe Checkout / Connect and PayPal hosted flows) are handled by PCI DSS-validated third-party payment processors using secure, tokenized payment flows.
This architecture aligns with common SAQ A–style deployments where card data is entered directly into the payment processor’s environment and only tokens or limited billing references are shared with the merchant application.
Optional crypto Selling checkouts are non-custodial: buyers send native cryptocurrency (such as ETH or POL) directly to the seller’s wallet address. The platform does not operate custodian wallets or process card data for those transfers.
2. What we do not store
LinkInBioPremium application systems do not persist:
- Full payment card numbers (PAN).
- Card verification values (CVV/CVC).
- PIN blocks or magnetic stripe data.
- Unencrypted sensitive authentication data.
3. What we may store
To manage subscriptions, Selling orders, and support billing inquiries, we may retain non-sensitive payment metadata provided by our processors, such as:
- Payment processor customer and payment method tokens.
- Last four digits and card brand for display in account settings (membership billing).
- Billing name, email, and address associated with the invoice.
- Transaction IDs, invoice amounts, tax, subscription status, and Selling order references.
- Connected-account or merchant identifiers for Stripe Connect / PayPal payouts.
4. Payment processing
When you subscribe to Premium or a visitor pays a creator via Selling, payment fields are served over HTTPS/TLS and processed by our payment partners’ PCI-compliant infrastructure (for example Stripe Checkout / Connect and PayPal). We use industry-standard hosted fields, checkout sessions, or tokenization APIs so card data bypasses LinkInBioPremium servers. Recurring membership charges use processor-issued tokens rather than raw card numbers.
5. Security controls
We maintain administrative, technical, and organizational measures appropriate to a B2B SaaS platform, including:
- Encryption in transit (TLS) for web and API communications.
- Access controls and least-privilege permissions for production systems.
- Monitoring and logging of authentication and billing-related events.
- Vendor due diligence for payment and infrastructure providers.
- Secure development practices and periodic review of payment integrations.
6. Your responsibilities
Business customers using LinkInBioPremium should protect account credentials, use strong passwords, enable available multi-factor authentication, and ensure only authorized personnel manage billing and Selling payout settings. Creators who accept payments are responsible for their own merchant relationship with Stripe/PayPal and for compliance with applicable consumer and tax laws for their sales. If you embed payment or lead capture on external properties, you remain responsible for compliance with applicable laws and any payment flows outside our hosted checkout.
7. Third-party services
Payment processors (such as Stripe and PayPal), CRM platforms (such as HubSpot or ActiveCampaign), and cloud providers maintain their own compliance programs. Their PCI attestations, privacy policies, and security documentation govern data handled within their systems. We select partners that support secure payment acceptance and contractual data protection obligations.
8. Incident reporting
If you suspect unauthorized charges, compromised credentials, or a payment security issue related to LinkInBioPremium, contact us immediately through our Contact page. We will investigate and coordinate with our payment processor as appropriate. For billing disputes, also see our Refund Policy.
9. Scope and limitations
This page is an informational summary for customers and partners. It does not constitute a PCI DSS Attestation of Compliance (AOC) or replace contractual security exhibits. Enterprise customers requiring formal compliance documentation may request available materials by submitting a request through our Contact page.
10. Changes
We may update this PCI Compliance page as our payment stack, processors, or security practices evolve. Revisions will be reflected in the “Last updated” date above.