CDM INSPECTIONS
PCI Payment Security & Compliance Policy
Payment processor: Stripe
| Business |
Coastal Drone Marine Inspections, LLC |
| Website |
https://cdm-inspections.com/ |
Effective Date: August 25, 2026
1. Purpose
This policy establishes payment-card handling and security expectations for CDM Inspections. CDM Inspections currently uses Stripe as its payment processor. The objective is to reduce unnecessary exposure to payment-card data and support compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirements applicable to the business and its payment environment.
2. Payment Processing Model
Stripe is the designated merchant payment processor for CDM Inspections. Wherever reasonably possible, payment-card information should be entered directly into Stripe-provided or Stripe-integrated payment interfaces rather than collected or stored by CDM Inspections personnel.
The precise Stripe integration method used on the website or in operational workflows should be documented internally, because PCI responsibilities vary depending on whether CDM Inspections uses hosted payment pages, embedded Stripe elements, manual entry, virtual terminal functions, or other processing methods.
3. Sensitive Authentication Data
CDM Inspections personnel must not store sensitive authentication data after authorization. This includes card verification values such as CVV/CVC, PINs, PIN blocks, magnetic-stripe track data, or equivalent sensitive authentication data.
4. Full Payment-Card Numbers
CDM Inspections personnel should not record, retain, photograph, copy, email, text, or store complete payment-card numbers in internal documents, notes, spreadsheets, messaging systems, email, website forms, or other business systems. Card data should be handled within Stripe or another approved PCI-compliant payment channel.
5. Permitted Transaction Information
CDM Inspections may retain limited transaction information made available through Stripe when reasonably necessary for accounting, refunds, customer service, fraud review, and chargeback management. Examples may include transaction ID, payment status, date, amount, card brand, last four digits, receipt information, and refund or dispute status.
6. Payment by Phone or Manual Entry
If payment information is taken by phone or entered manually, staff must enter the information directly into an approved Stripe interface or other authorized payment channel and must not write down or retain full card details. Any temporary exposure to card data should be minimized and should not result in card information being stored in CDM Inspections systems.
7. Email, SMS, and Messaging
Customers should not be asked to send complete card numbers, CVV/CVC values, or other sensitive card information through email, SMS, website chat, or general messaging applications. If a customer sends such information, personnel should avoid copying it into other systems and should follow an internal incident-handling procedure to remove or secure the data as appropriate.
8. Access Control
- Stripe access should be limited to personnel who require it for legitimate business duties.
- Each authorized user should use an individual account where supported rather than shared credentials.
- Strong, unique passwords should be used for Stripe and related administrative systems.
- Multi-factor authentication should be enabled for Stripe and other sensitive administrative systems wherever available.
- Access should be reviewed when personnel roles change or when an authorized user no longer requires access.
9. Device and Account Security
- Keep operating systems, browsers, and security software reasonably current.
- Use password-protected devices and secure network connections for merchant administration.
- Avoid accessing payment administration from public or untrusted devices.
- Do not share Stripe login credentials through insecure channels.
- Report suspected compromise, phishing, unauthorized access, or unusual transaction activity promptly.
10. Website Payment Security
Any website page that accepts or facilitates payment should use HTTPS and a valid SSL/TLS certificate. Payment integrations should be maintained using supported Stripe components or approved integration methods. Website plugins, themes, and payment-related software should be kept reasonably current and should be limited to necessary and trusted components.
11. Invoices and Billing Descriptions
Invoices and payment requests should clearly identify CDM Inspections and the service being charged. Billing descriptions should be recognizable to the customer when possible in order to reduce confusion and unnecessary chargebacks.
12. Refunds, Disputes, and Chargebacks
Refunds should be processed through Stripe or the original approved payment channel whenever practical. CDM Inspections may use service agreements, quotes, appointment records, communications, reports, invoices, and Stripe transaction records to respond to payment disputes or chargebacks.
13. Security Incidents
Suspected payment-data compromise, unauthorized access, fraudulent activity, or account takeover should be escalated promptly to the business owner. Where appropriate, CDM Inspections should secure affected accounts, change credentials, contact Stripe, preserve relevant records, and follow any notification or investigation obligations that apply.
14. Data Retention
Payment-related business and transaction records may be retained as reasonably necessary for accounting, tax, dispute, and legal purposes, consistent with the general business retention period of up to 7 years. This retention practice does not authorize storage of prohibited cardholder or sensitive authentication data.
15. Personnel Responsibilities
Personnel with access to payments must follow this policy, protect login credentials, use only approved payment channels, and avoid unnecessary collection or storage of cardholder data. Training should be provided when payment procedures materially change.
16. PCI DSS Validation and Stripe
Using Stripe can reduce the amount of payment-card data directly handled by CDM Inspections, but it does not automatically eliminate all PCI DSS responsibilities. CDM Inspections should complete the PCI DSS validation or Self-Assessment Questionnaire (SAQ) appropriate to its actual Stripe integration and card-handling practices, and should follow Stripe’s current PCI guidance.
17. Compliance Claims
CDM Inspections should not represent itself as “PCI certified” or make similar claims unless the business has completed the specific validation required for its environment and has support for that claim. A more accurate statement is that the business uses Stripe and maintains payment-security practices intended to support applicable PCI DSS obligations.
18. Policy Review
This policy should be reviewed when the payment setup changes, when a new payment channel is introduced, after a security incident, or periodically as Stripe and PCI DSS requirements evolve.
19. Contact
Payment-security questions should be directed to the owner of CDM Inspections at Cdm.inspections@gmail.com or 850-966-0978.
Legal and Compliance Review Notice
This document is an operational payment-security policy based on information supplied by CDM Inspections. It should be reviewed against the business’ actual Stripe configuration and by qualified legal, PCI, or information-security professionals where appropriate before being treated as a definitive compliance attestation.