Security

How we keep payments safe.

Last reviewed 24 September 2026.

Card data never reaches us

Every payment is taken by Stripe on a Stripe-hosted checkout page. Card numbers, bank details and identity documents are entered directly into Stripe and are never transmitted to, stored by, or visible to Levy & Loom. Stripe is a certified PCI DSS Level 1 service provider.

Merchants keep their own money

Customer payments go straight into each merchant's own Stripe account. Levy & Loom never holds merchant funds. Our 1% fee is collected by Stripe at the moment of payment as a separate application fee.

What we store

We keep a ledger of payment events: amounts, currencies, Stripe identifiers, timestamps and the fee and Pour calculations derived from them, together with each merchant's business name, contact email and Stripe account identifier. Merchant API keys are stored only as one-way hashes. Data is stored on encrypted disks in the European Union.

Everything signed

Messages from Stripe to us are verified against Stripe's signature before they are trusted. Messages from us to merchants carry an HMAC signature the merchant can check. Public statistics and Pour Ledger Proof certificates are signed with Ed25519 and can be verified with our published keys.

Reporting a vulnerability

If you believe you have found a security issue, please email hello@levyandloom.com with enough detail for us to reproduce it. We will acknowledge your report within two working days, keep you informed while we fix it, and credit you if you wish. Please do not access data that is not yours, and do not test against live merchant accounts. Our machine-readable disclosure details are at /.well-known/security.txt.