Trust

Security at Paytab

This page is maintained by Paytab Ltd to answer common security and privacy questions about the Paytab platform. It describes the controls that are enabled in the product today; it is not an independent certification.

Access & authentication

  • Email and password sign-in with strength requirements
  • Optional two-factor authentication on merchant accounts
  • Role-based access control for admin functions
  • Session revocation from the account settings page
  • Rate-limiting and lockout on repeated failed sign-in attempts

Data protection in the application

  • TLS in transit for every request to paytab.co.uk and our APIs
  • Row-level security on merchant data so each account only sees its own records
  • Sensitive card details entered in our hosted checkout are not returned to merchant systems in clear
  • Server functions validate inputs with Zod before writing to storage

Monitoring & response

  • Sign-in alerts and new-device notifications on merchant accounts
  • Fraud and risk decisioning applied to every payment attempt
  • Support contactable in-app via the chat bubble on every dashboard page
  • Security enquiries triaged separately from general support

Privacy & data rights

  • Full Privacy Policy describing collection, use, sharing and retention
  • Cookie Policy with the categories we use and how to control them
  • Requests for access, correction or deletion via privacy@paytab.co.uk
  • Retention periods aligned to UK regulatory obligations for payment institutions

Report a vulnerability

If you believe you've found a security issue in Paytab, please emailsecurity@paytab.co.ukwith reproduction steps. We ask that you give us reasonable time to investigate and remediate before public disclosure, and that you avoid testing that could impact the availability of the service or the confidentiality of other merchants' data. We do not currently operate a paid bug-bounty programme, but we recognise good-faith reports and will keep you updated as we triage.

Shared responsibility

Paytab is responsible for the security of the platform — the infrastructure, the application, and the controls listed above. As a merchant you are responsible for keeping your account credentials safe, managing your team's access appropriately, protecting your API keys, and complying with any obligations that apply to your own business and end customers.