Data minimization
Preliminary applications exclude bank details, Social Security numbers, card data, identity documents, and other sensitive underwriting information.
Server-side field allowlists and validation
Review how the platform minimizes data, protects documents, controls access, and keeps public claims subject to verification.
These are application practices, not certification claims. Certifications publish only when supported by current documentation.
Preliminary applications exclude bank details, Social Security numbers, card data, identity documents, and other sensitive underwriting information.
Server-side field allowlists and validation
Statement uploads are type-checked, stored privately, assigned retention metadata, excluded from analytics, and prepared for malware scanning.
Private object storage and access-control workflow
Administrative access requires authenticated sessions, role checks, multi-factor authentication, lockout protection, and auditable activity.
MFA-enforced role-based access control
The platform exposes a minimal health signal and supports redacted structured events without placing merchant documents or form contents in logs.
Health endpoint and privacy-safe event logging
Merchant statements are never sent to analytics tools or used to train AI models without separate, explicit consent.
Only information needed to respond, qualify, support, or coordinate the requested service is collected.
Server-side validation, private storage, role checks, MFA, secure sessions, and restricted administrative access protect operational data.
Information is used for the submitted request, service coordination, required communications, and consented follow-up.
Statement records receive a 30-day retention target. Other records follow configured legal and operational requirements.
Deletion requests and retention workflows are supported, subject to legal, fraud-prevention, contractual, and recordkeeping obligations.
The site does not collect card numbers or CVV. Any future checkout uses a hosted payment page from an approved provider.
Pina Merchant Services does not claim PCI, SOC, or ISO certification, bank sponsorship, or registration until the applicable documentation is received and reviewed.
Need to review our controls?
Include security and procurement requirements in the enterprise consultation.