Last updated: August 27, 2025
For your safety, our platform never stores full credit card numbers, CVV, or magnetic stripe data on our servers or in our databases. All credit card processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. Stripe securely tokenizes payment details and returns a token that we use to complete transactions.
This design keeps sensitive card data out of our environment and reduces risk while leveraging Stripe’s world‑class security controls.
We follow security best practices across our application, infrastructure, and operational processes. Below are the highlights of how we protect information for children, parents/guardians, and staff.
Stripe is a leading global payments platform certified to the highest PCI DSS level. When you enter card details during checkout, they are sent directly to Stripe over a secure connection. We receive a non‑sensitive token from Stripe and use that token to create charges or set up billing. This means your card details do not pass through or reside on our servers.
No. We never store full credit card information in our servers or databases. Stripe handles all card data.
All credit card payments are processed by Stripe over secure, PCI‑compliant infrastructure.
TLS encryption in transit, tokenization by Stripe, and fraud prevention help keep your payments safe.
If you discover a vulnerability or have a security concern, please contact us promptly so we can investigate and remediate. Provide enough detail to reproduce the issue and avoid accessing data you are not authorized to view.
For information on data handling and user rights, see our Privacy Policy and Terms of Service.