Everything you need to know about protecting your business from fraud, managing disputes, and keeping your account secure.
Paayed uses multiple layers of security to protect every transaction you process.
Paayed is certified PCI DSS Level 1 compliant. This means all card data is encrypted, tokenised, and stored securely. Your business never handles raw card numbers.
All online transactions are protected by 3D Secure 2 (3DS2). This adds an extra verification step for the cardholder, reducing fraud and shifting liability away from your business.
Every transaction passes through Paayed’s fraud detection engine before it is processed. Suspicious transactions are flagged or blocked automatically based on risk signals.
A chargeback occurs when a cardholder disputes a transaction with their bank. The disputed amount is temporarily reversed while the case is investigated.
Submitting strong evidence is the best way to win a chargeback dispute.
Go to Disputes in your dashboard. Each dispute shows the transaction details, reason code, deadline for response, and current status.
Paayed’s fraud engine applies rules to every transaction to identify and block fraudulent payments.
Contact Paayed support to configure custom fraud rules for your business. For example, you can set maximum transaction amounts, restrict certain countries, or require 3DS for all transactions above a threshold.
Protect your Paayed account with strong authentication and access controls.
Enable 2FA in Settings > Security. Once enabled, you will need to enter a code from your authenticator app each time you log in. All team members should enable 2FA.
Use a unique password of at least 12 characters with a mix of letters, numbers, and symbols. Do not reuse passwords from other services.
Paayed automatically logs you out after 30 minutes of inactivity. You can view and revoke active sessions in Settings > Security > Active Sessions.
Control what each team member can see and do in your Paayed account.
Go to Settings > Team to invite new members, change roles, or remove access. Changes take effect immediately.
All actions taken by team members are logged in Settings > Activity Log with the user’s name, action, and timestamp.
Paayed handles all sensitive card data so your business does not have to.
When a customer enters their card details, Paayed immediately tokenises the data. The token is a random string that represents the card but cannot be used to reconstruct the card number. Your systems never store or process raw card data.
All data transmitted between your customer’s browser and Paayed’s servers is encrypted using TLS 1.2 or higher. Card data at rest is encrypted using AES-256.
Because Paayed handles card data on your behalf, your PCI compliance requirements are minimal. You need to ensure your website uses HTTPS and that you do not store card details in your own systems (emails, spreadsheets, databases).
Friendly fraud occurs when a legitimate customer makes a purchase and then disputes the charge with their bank.
Paayed monitors your account for unusual patterns and alerts you when something looks wrong.
Alerts are sent via email and appear as notifications in your Paayed dashboard. Critical alerts (such as suspected account compromise) are also sent via SMS if you have a phone number on file.
Review each alert in your dashboard. You can mark it as resolved, block the flagged card, or contact Paayed support for assistance.
Protect your business from customers who abuse the refund process.
Refunds are always returned to the original payment method. Paayed does not allow refunds to be redirected to a different card or bank account.
Display your refund policy clearly on your website and include it in your invoice terms. A clear policy helps you defend against unjustified chargeback claims.
Paayed is fully compliant with UK GDPR and the Data Protection Act 2018.
If a customer requests access to their data under GDPR, you can export their transaction history from Customers > [Customer Name] > Export Data.
Customer records can be deleted on request, subject to legal retention requirements. Financial transaction records must be retained for 7 years under UK law, but personal identifiers can be anonymised.
A Data Processing Agreement (DPA) is available in Settings > Legal for your records.
Paayed uses cookies to keep our website secure, improve performance, remember your preferences, and personalise content where you allow it. You can accept, reject, or manage your choices in Cookie preferences.
Paayed uses cookies to keep our website secure, make the platform work properly, improve performance, and remember your preferences. Some cookies are essential, while others help us understand how visitors use our website and personalise content where you allow it. You are in control of your choices. You can allow or disable optional cookies below. Strictly necessary cookies are always active because they are required for security, login, fraud prevention, payment processing, and core platform functions. Read our Cookie Policy for more information.