Skip to content
Meet Penni Cart. All the work around ecommerce, beautifully connected.Learn more
Security

Clear boundaries. Responsible commerce.

Understand how checkout, account access and payment integrations fit together, and how to report a concern to our team.

Payment fields belong to the payment provider.

For Stripe and Square integrations, checkout uses the provider’s payment interface to handle sensitive card entry. Penni Cart’s commerce workflow manages the cart, order details and payment references around that integration.

Gateway implementations differ. Review the documentation for the processor you use, configure the correct environment and credentials, and complete a test checkout before going live. This page is not a claim of a particular compliance certification.

Store access and cart identity have different roles.

The dashboard requires account authentication. Store operations are scoped to the merchant’s store, while storefront cart operations use the SDK’s cart identity and signed cart token.

A cart token does not grant dashboard access. Keep private gateway credentials and other secrets out of frontend code, public repositories and support messages.

A secure store includes your website.

Protect the accounts and deployment tools that can change your storefront. Review third-party scripts, limit who can publish changes, and keep your website dependencies maintained.

Customer names, addresses and order records are business data. Share only what is needed with team members and services involved in operating the store.

Report a concern with enough detail to investigate.

Email hello@pennicart.io with the affected URL, a description of the issue and safe reproduction steps. Do not include another person’s private data, secret keys or raw payment details.

If you suspect your merchant account or gateway credentials have been exposed, secure the affected account and contact the relevant provider as well as our team.

Contact the team