Legal

PCI-DSS Compliance

Last updated: August 7, 2026

Effective Date: November 01, 2025

Last Reviewed: May 01, 2026

1. Purpose

This PCI-DSS Compliance Policy describes how Nuvbook ("Nuvbook," "we," "our," or "us") approaches the security of payment card data in connection with our Platform. It explains the roles and responsibilities of Nuvbook, our third-party payment processors, and our business owners ("Providers") in maintaining compliance with the Payment Card Industry Data Security Standard (PCI-DSS).

This policy applies to all users of the Platform, including Providers who accept payments through Nuvbook and the clients ("End Users") who submit payment information when booking or purchasing services.

2. Scope

This policy applies to all payment-related activity conducted through the Nuvbook Platform, including the collection, transmission, and processing of payment card data via integrated third-party payment processors. It covers Nuvbook's own obligations as a Platform operator, the obligations of our payment processing partners, and the responsibilities of Providers who use Nuvbook to accept payments from their clients.

3. Nuvbook's Approach to Payment Card Data

Nuvbook does not store, process, or transmit payment card data on its own servers. All payment transactions conducted through the Platform are handled exclusively by PCI-DSS-compliant third-party payment processors, currently Stripe and PayPal. By routing all payment activity through these providers, Nuvbook significantly limits its own PCI-DSS scope and ensures that cardholder data is handled by organizations that maintain the highest level of payment security certification.

Because payment card data never touches Nuvbook's infrastructure, users can be confident that their card numbers, expiry dates, and security codes are not held by Nuvbook at any point during or after a transaction.

4. Third-Party Payment Processors

Stripe and PayPal are each certified as PCI-DSS Level 1 service providers, which is the highest level of compliance available under the standard. They are responsible for the secure collection, encryption, transmission, and storage of all cardholder data processed through the Platform. Their security practices are governed by their own compliance programmes, security policies, and privacy notices, which users are encouraged to review directly.

Nuvbook maintains active relationships with these providers and requires, as a condition of integration, that they uphold their PCI-DSS certification on an ongoing basis. Any changes to our payment processing partners will be reflected in updates to this policy.

5. Nuvbook's Security Controls

Although Nuvbook does not handle cardholder data directly, we maintain a range of security controls to protect the broader Platform environment in which payment activity occurs. These include SSL and TLS encryption for all data transmitted between users and the Platform, firewalls and intrusion detection systems to monitor and protect our infrastructure, role-based access controls that limit system access to authorized personnel only, and regular review of security practices to align with current industry standards.

These controls support a secure environment for initiating and completing payment transactions, even though the processing of card data itself takes place entirely within the systems of our payment processor partners.

6. Provider Responsibilities

Providers who use Nuvbook to accept payments from their clients do so through the integrated payment processing tools provided by the Platform. Providers must not attempt to collect, record, or store payment card data outside of the designated payment processing flow. This includes not requesting card numbers, expiry dates, or security codes via email, SMS, chat, or any other channel not specifically designed for secure payment capture.

Providers are responsible for ensuring that their own business practices comply with PCI-DSS requirements to the extent that they apply. If a Provider operates additional payment systems outside of Nuvbook, those systems fall entirely outside the scope of this policy and the Provider bears sole responsibility for their compliance.

Providers are also responsible for understanding and complying with the terms of service of Stripe and PayPal where those services are used through the Platform.

7. What Nuvbook Does Not Do

Nuvbook does not store payment card numbers, CVV codes, PINs, or magnetic stripe data on its servers at any time. Nuvbook does not have access to full card numbers following a completed transaction. Nuvbook does not sell or share payment data with any third party for marketing or non-operational purposes. Billing records retained by Nuvbook, such as invoices and subscription histories, contain only transaction summaries and do not include raw cardholder data.

8. Incident Response

In the event that Nuvbook becomes aware of a security incident that may affect the payment environment, we will act promptly to assess the situation, contain any potential exposure, and notify affected users in accordance with applicable breach notification requirements. For incidents involving cardholder data held by Stripe or PayPal, those providers maintain their own incident response programmes and will notify affected parties in accordance with their obligations under PCI-DSS and applicable law.

Nuvbook will notify the relevant supervisory authority within 72 hours and will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Articles 33 and 34 and applicable U.S. state-level breach notification laws.

9. Compliance Reviews

Nuvbook reviews its payment-related security practices on a regular basis to ensure continued alignment with PCI-DSS requirements and the standards maintained by our payment processor partners. Where changes to the Platform, our service providers, or the PCI-DSS standard itself require updates to our approach, those updates will be reflected in revisions to this policy.

10. Updates to This Policy

Nuvbook may update this policy from time to time to reflect changes in our payment infrastructure, legal obligations, or business practices. Updates will be communicated via email or in-platform notice. Continued use of the Platform after such updates constitutes acceptance of the revised policy. The effective date will always be displayed at the top of this document.

11. Contact

For questions about this policy or our payment security practices, please reach out to us at privacy@nuvbook.com,

by mail at

418 Broadway STE 8805, Albany, NY 12207, USA

or by phone at +1 (914) 371-8990.

Our response time is 5 to 10 business days.

Questions or Concerns?

If you have any questions about this pci-dss compliance , please don't hesitate to reach out to our support team.

Contact Support