Legal

Payment Processing Compliance

Last updated: July 2, 2026

1. RevenueCat as Payment Processor

The Perez Code uses RevenueCat, Inc. as our payment orchestration platform for all online transactions. RevenueCat partners with leading PCI DSS Level 1 compliant payment processors to ensure the highest level of security certification available in the payments industry. By using RevenueCat, we ensure that your payment information is handled with the highest security standards.

2. PCI DSS Compliance

We are committed to PCI DSS (Payment Card Industry Data Security Standard) compliance. Because we process payments through RevenueCat's infrastructure, we never directly handle, store, or transmit full credit card numbers, CVV codes, or magnetic stripe data on our servers. RevenueCat's payment partners handle all sensitive payment data on their PCI-compliant infrastructure, significantly reducing our PCI DSS compliance scope.

3. Data Handling Practices

Our payment data handling practices include:

  • All payment data is collected and processed through RevenueCat's secure SDK and paywall infrastructure
  • We only store limited payment information such as the last four digits of your card, card brand, and expiration date for reference purposes
  • Full card numbers, CVV codes, and magnetic stripe data are never stored on our systems
  • All payment page communications are encrypted using TLS/SSL
  • RevenueCat uses tokenization to replace sensitive card data with unique identifiers

4. RevenueCat Privacy Policy Reference

RevenueCat's privacy policy governs how RevenueCat handles your personal information during payment processing. We encourage you to review RevenueCat's privacy policy at revenuecat.com/privacy for detailed information about their data collection, use, and security practices. RevenueCat acts as an independent data controller for payment processing data.

5. Security Measures

In addition to RevenueCat's security infrastructure, we implement:
  • HTTPS across all pages with payment functionality
  • CSRF (Cross-Site Request Forgery) protection
  • Input validation and sanitization
  • Session security best practices
  • Regular security audits and monitoring

6. Compliance Updates

We regularly review our payment processing practices to maintain compliance with evolving PCI DSS requirements and RevenueCat's terms of service. We will update this page as needed to reflect any material changes in our payment processing compliance.