No raw card data
Card numbers, CVVs, and expiry dates are entered into iframes or native SDK fields hosted by Stripe. They never traverse our servers, logs, or databases.
3D Secure 2 / SCA
EU + UK transactions enforce Strong Customer Authentication via 3D Secure 2.2. The checkout transparently triggers issuer challenge flows where required.
One global processor
Stripe handles every transaction worldwide under a single PCI DSS Level 1 certification, with tokenized references and local acquiring that maximizes approval rates.
What we accept
Card networks
Digital wallets
Apple Pay and Google Pay use device-bound tokens; the merchant (us) never sees the underlying card number even once.
Local methods
- • Klarna (select EEA + US markets, via Stripe)
Our processor & its certifications
All regions
- PCI DSS Level 1 Service Provider
- SOC 1 + SOC 2 Type II
- ISO 27001:2022
- EU-US Data Privacy Framework
Fraud prevention
- Stripe Radar scores every authorization against device fingerprints, BIN-country mismatches, and the card network's velocity rules.
- Bookings get a per-traveller velocity check (max 4 attempts / 24h on the same email or device fingerprint).
- Refunds, chargebacks, and disputes are reconciled to the underlying booking via a deterministic Idempotency-Key — no double-charge or double-refund paths.
- Sanctions screening (OFAC SDN) runs on every payer name before capture; payouts to listed entities are blocked.