Purpose and scope
The policy applies to the 24-SEVEN website, shared-hosting application, administration and partner workflows, payment-provider integrations, people with payment duties, and any connected service that can affect the security of a payment page. Outsourcing payment processing does not by itself remove the merchant’s PCI DSS responsibilities.
Card-data minimisation
- Guests are handed to an approved provider-hosted HTTPS checkout. 24-SEVEN forms do not request or intentionally store primary account numbers, card-security codes or magnetic-stripe data.
- Browser redirects never prove payment. The server accepts a financial outcome only after signature validation and provider-side reference, amount, currency and status verification.
- Secrets are encrypted at rest, excluded from source and entered only by an authorised administrator. Provider and property payment switches remain disabled until commissioning evidence is recorded.
- Logs and support workflows must not contain card numbers or CVV values. Suspected card-data exposure is handled as a security incident.
Commissioning evidence gate
Operating responsibilities
Finance owns provider onboarding, settlement and reconciliation. Security owns scope, vulnerability and incident controls. Operations must use payment references—not card details—when helping guests. Engineering maintains secure configuration and release evidence. A third-party property may not enable payments until its verification, commercial terms and payment-readiness gate are complete.
Current status
The direct GlobalPAY contract is implemented for hosted checkout, transaction queries, encrypted notifications and reconciliation. It becomes selectable only after real merchant credentials, registered callbacks and production acceptance are recorded. Other gateways remain subject to their own credential, webhook and reconciliation gates.