Your Data Security is Our Priority
PayCamp protects your customer data with strong encryption, access controls, daily encrypted backups, and managed cloud hosting in the UK and EU.
AES Encryption
Transport Security
Encrypted Backups
Backup Retention
Data Residency
Enterprise-Grade Infrastructure
Built on enterprise-grade cloud infrastructure with multiple layers of redundancy and protection.
EU & UK Cloud Data Centres
All data is stored in EU & UK cloud data centres. Your customer information stays within Europe, ensuring compliance with UK and EU data sovereignty requirements.
Enterprise Cloud Infrastructure
Built on managed enterprise cloud infrastructure in the UK and EU. We do not publish an uptime SLA — our Terms set out the service commitment we do make.
Daily Encrypted Backups
Automatic daily backups with 30-day retention. All backups are encrypted with AES-256 and stored in separate geographic locations for disaster recovery.
Real-Time Replication
Continuous data replication ensures minimal data loss in case of hardware failure. Point-in-time recovery available.
Strong Encryption
Your data is protected with AES-256 encryption at rest and TLS in transit.
TLS 1.3 in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.3 - the latest and most secure transport protocol.
AES-256 at Rest
All stored data is encrypted with AES-256 at rest and TLS in transit.
Encrypted Database
Customer data is encrypted in transit (TLS) and at rest, and separated by per-tenant row-level security so each site can only access its own data. We monitor for security issues and remediate them promptly.
Secure Password Storage
Passwords are hashed using industry-standard bcrypt with salt. We never store plain-text passwords.
Access Controls & Monitoring
Comprehensive controls to manage who can access your data and track all activity.
Role-Based Access Control
Granular permissions ensure staff only see the data they need. Assign roles like Admin, Manager, or Staff with different access levels.
Complete Audit Trail
Every login, data access and modification is logged with timestamps and user details for compliance and security investigations.
Session Management
Automatic session timeout, secure cookie handling, and the ability to see and revoke active sessions from any device.
Authenticated Requests
Every request the app makes is authenticated and rate-limited. JWT tokens with short expiry times prevent unauthorised access.
Your Data, Your Control
PayCamp's Privacy Shield puts you in complete control of who can access your business data — with full transparency and one-click revocation.
Data Isolation
When Privacy Shield is enabled, our support team cannot see your customer details, financial records, or payment information. We can only see your site structure and support tickets.
You Control Support Access
Need help? Grant us temporary, scoped access — you choose what we can see and for how long (24 hours to 7 days). Revoke at any time with one click.
Full Transparency
Every support access request, what was viewed, and when access ended is recorded in your Transparency Dashboard — visible from Settings at any time.
Your Stripe Keys Stay Yours
Payment processing goes directly through your own Stripe account. We never see your bank details or process payments on your behalf.
Data Processor under UK GDPR
We act as a Data Processor under UK GDPR. Your customers' personal data is processed solely on your instructions, and you retain full Data Controller rights.
Backup & Disaster Recovery
Multiple layers of protection ensure your data is always safe and recoverable.
Daily Backups
Automatic daily backups run every night. All backups are encrypted with AES-256 and stored in geographically separate data centres.
- 30-day retention
- Encrypted storage
- Geographic redundancy
Point-in-Time Recovery
Continuous transaction logging allows us to restore your data to any point in time within the retention window.
- Minute-level granularity
- Minimal data loss
- Fast recovery times
Disaster Recovery
In the event of a major incident, our disaster recovery procedures ensure your service is restored quickly and completely.
- Multi-region failover
- Tested regularly
- Documented procedures
Our Security Practices
Regular Security Audits
We conduct regular security assessments and code reviews to identify and address potential vulnerabilities.
Dependency Monitoring
Automated monitoring of all software dependencies for known vulnerabilities with rapid patching.
Employee Security Training
All team members receive security awareness training and follow strict access protocols.
Incident Response Plan
Documented procedures for detecting, responding to, and recovering from security incidents.
Secure Development Practices
Code is developed following OWASP guidelines with security reviews before deployment.
DDoS Protection
Enterprise-grade DDoS mitigation protects against distributed denial of service attacks.
Compliance & Standards
UK ICO registered
Towpath Digital Ltd is on the ICO public register (registration C1995119), and PayCamp is operated in accordance with the UK GDPR.
Learn more →PCI DSS Aware
Payments are processed through Stripe, a PCI Level 1 Service Provider.
ICO Registered
Registered with the UK Information Commissioner's Office as required.
Report a Security Vulnerability
We take security seriously. If you believe you've found a security vulnerability in PayCamp, please report it responsibly.
Ready to Secure Your Site Data?
Built in the UK, encrypted at rest and in transit, and isolated per site.