PCI Payment Security & Compliance Policy

CDM INSPECTIONS PCI Payment Security & Compliance Policy Payment processor: Stripe
Business Coastal Drone Marine Inspections, LLC
Website https://cdm-inspections.com/
Effective Date: August 25, 2026

1. Purpose

This policy establishes payment-card handling and security expectations for CDM Inspections. CDM Inspections currently uses Stripe as its payment processor. The objective is to reduce unnecessary exposure to payment-card data and support compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirements applicable to the business and its payment environment.

2. Payment Processing Model

Stripe is the designated merchant payment processor for CDM Inspections. Wherever reasonably possible, payment-card information should be entered directly into Stripe-provided or Stripe-integrated payment interfaces rather than collected or stored by CDM Inspections personnel. The precise Stripe integration method used on the website or in operational workflows should be documented internally, because PCI responsibilities vary depending on whether CDM Inspections uses hosted payment pages, embedded Stripe elements, manual entry, virtual terminal functions, or other processing methods.

3. Sensitive Authentication Data

CDM Inspections personnel must not store sensitive authentication data after authorization. This includes card verification values such as CVV/CVC, PINs, PIN blocks, magnetic-stripe track data, or equivalent sensitive authentication data.

4. Full Payment-Card Numbers

CDM Inspections personnel should not record, retain, photograph, copy, email, text, or store complete payment-card numbers in internal documents, notes, spreadsheets, messaging systems, email, website forms, or other business systems. Card data should be handled within Stripe or another approved PCI-compliant payment channel.

5. Permitted Transaction Information

CDM Inspections may retain limited transaction information made available through Stripe when reasonably necessary for accounting, refunds, customer service, fraud review, and chargeback management. Examples may include transaction ID, payment status, date, amount, card brand, last four digits, receipt information, and refund or dispute status.

6. Payment by Phone or Manual Entry

If payment information is taken by phone or entered manually, staff must enter the information directly into an approved Stripe interface or other authorized payment channel and must not write down or retain full card details. Any temporary exposure to card data should be minimized and should not result in card information being stored in CDM Inspections systems.

7. Email, SMS, and Messaging

Customers should not be asked to send complete card numbers, CVV/CVC values, or other sensitive card information through email, SMS, website chat, or general messaging applications. If a customer sends such information, personnel should avoid copying it into other systems and should follow an internal incident-handling procedure to remove or secure the data as appropriate.

8. Access Control

  • Stripe access should be limited to personnel who require it for legitimate business duties.
  • Each authorized user should use an individual account where supported rather than shared credentials.
  • Strong, unique passwords should be used for Stripe and related administrative systems.
  • Multi-factor authentication should be enabled for Stripe and other sensitive administrative systems wherever available.
  • Access should be reviewed when personnel roles change or when an authorized user no longer requires access.

9. Device and Account Security

  • Keep operating systems, browsers, and security software reasonably current.
  • Use password-protected devices and secure network connections for merchant administration.
  • Avoid accessing payment administration from public or untrusted devices.
  • Do not share Stripe login credentials through insecure channels.
  • Report suspected compromise, phishing, unauthorized access, or unusual transaction activity promptly.

10. Website Payment Security

Any website page that accepts or facilitates payment should use HTTPS and a valid SSL/TLS certificate. Payment integrations should be maintained using supported Stripe components or approved integration methods. Website plugins, themes, and payment-related software should be kept reasonably current and should be limited to necessary and trusted components.

11. Invoices and Billing Descriptions

Invoices and payment requests should clearly identify CDM Inspections and the service being charged. Billing descriptions should be recognizable to the customer when possible in order to reduce confusion and unnecessary chargebacks.

12. Refunds, Disputes, and Chargebacks

Refunds should be processed through Stripe or the original approved payment channel whenever practical. CDM Inspections may use service agreements, quotes, appointment records, communications, reports, invoices, and Stripe transaction records to respond to payment disputes or chargebacks.

13. Security Incidents

Suspected payment-data compromise, unauthorized access, fraudulent activity, or account takeover should be escalated promptly to the business owner. Where appropriate, CDM Inspections should secure affected accounts, change credentials, contact Stripe, preserve relevant records, and follow any notification or investigation obligations that apply.

14. Data Retention

Payment-related business and transaction records may be retained as reasonably necessary for accounting, tax, dispute, and legal purposes, consistent with the general business retention period of up to 7 years. This retention practice does not authorize storage of prohibited cardholder or sensitive authentication data.

15. Personnel Responsibilities

Personnel with access to payments must follow this policy, protect login credentials, use only approved payment channels, and avoid unnecessary collection or storage of cardholder data. Training should be provided when payment procedures materially change.

16. PCI DSS Validation and Stripe

Using Stripe can reduce the amount of payment-card data directly handled by CDM Inspections, but it does not automatically eliminate all PCI DSS responsibilities. CDM Inspections should complete the PCI DSS validation or Self-Assessment Questionnaire (SAQ) appropriate to its actual Stripe integration and card-handling practices, and should follow Stripe’s current PCI guidance.

17. Compliance Claims

CDM Inspections should not represent itself as “PCI certified” or make similar claims unless the business has completed the specific validation required for its environment and has support for that claim. A more accurate statement is that the business uses Stripe and maintains payment-security practices intended to support applicable PCI DSS obligations.

18. Policy Review

This policy should be reviewed when the payment setup changes, when a new payment channel is introduced, after a security incident, or periodically as Stripe and PCI DSS requirements evolve.

19. Contact

Payment-security questions should be directed to the owner of CDM Inspections at Cdm.inspections@gmail.com or 850-966-0978.

Legal and Compliance Review Notice

This document is an operational payment-security policy based on information supplied by CDM Inspections. It should be reviewed against the business’ actual Stripe configuration and by qualified legal, PCI, or information-security professionals where appropriate before being treated as a definitive compliance attestation.