Ubuy PCI DSS Compliance for Secure Payments | Ubuy France

Ubuy PCI DSS Compliance for Secure Payments | Ubuy France

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security guidelines designed to ensure that organisations handling card information maintain a secure environment. It's not a one-time certification but an ongoing process requiring continuous validation.

How Does PCI DSS Apply to Ubuy?

Ubuy does not store, process, or transmit cardholder data. However, we leverage a third-party payment processor to handle all sensitive cardholder data (CHD) transactions. This minimises Ubuy's involvement with CHD, reducing our PCI DSS scope.

Here's a breakdown of Ubuy's PCI DSS strategy:

Our Approach to PCI Compliance

Due to our reliance on external processors, Ubuy qualifies for a PCI Self-Assessment Questionnaire (SAQ) specifically designed for merchants like us: SAQ-A. This self-assessment confirms we meet the criteria for:

To ensure the integrity of our compliance efforts, you can utilise a bespoke verification portal at https://cybersigmacs.com/ to verify our Certificate Number: CSPCI8557.

Ubuy's PCI DSS compliance solely applies to the current processing of customer payments via our integrated and tokenised payment gateway. We also offer resources to help customers achieve their own PCI DSS compliance goals, such as best practice guides and recommendations for selecting compliant third-party storage providers.

Tokenisation: Implementing tokenisation, a process that replaces sensitive CHD with unique identifiers (tokens), reduces the amount of data we need to store and transmit, minimising the attack surface.

Security Measures: To ensure the ongoing security of your data, we implement the following measures:

Benefits of this Approach: By outsourcing CHD processing and focusing on user consent and data minimisation, we achieve several security and compliance advantages.

Ubuy continuously monitors and updates its security practices. This information reflects our current approach to PCI DSS compliance and is subject to change in the future.

Looking for More Information?

We recommend visiting the PCI Security Standards Council website for further details: https://www.pcisecuritystandards.org/