Credit Card Security Policy
This sets out the policy of Crane Brothers with respect to the protection of customer credit card information.
Our Commitment to Your Security
At Crane Brothers, protecting your credit card information is a top priority. We are committed to maintaining the highest standards of security and compliance to ensure your payment data remains safe and secure.
How We Protect Your Information
Industry-Standard Security
We comply with the Payment Card Industry Data Security Standard (PCI DSS), the gold standard for credit card data protection. Our security measures include:
- Encryption: All credit card information is encrypted both when transmitted to us and when stored in our systems.
- Secure Networks: We use advanced firewalls and network security measures to protect against unauthorized access.
- Access Controls: Only authorized personnel have access to payment systems, and all access is monitored and logged.
- Regular Security Testing: We conduct regular security assessments and vulnerability testing to maintain our defences.
What Information We Collect
When you make a purchase with your credit card, we collect only the information necessary to process your transaction, being as follows:
- Credit card number.
- Expiration date.
- Cardholder name.
- Billing address.
- Security code (for verification only - never stored).
What We Never Store
For your protection, we never store:
- Full magnetic stripe data.
- Security codes (CVV/CVC).
- PIN numbers.
- Any sensitive authentication data.
Data Handling Practices
Secure Processing
- All transactions are processed through secure, encrypted connections.
- We use tokenization technology to replace sensitive card data with unique tokens.
- Payment processing occurs in isolated, monitored environments.
- All systems are regularly updated with the latest security patches.
Data Retention
- We retain only the minimum card information necessary for business purposes.
- Credit card numbers are masked in our systems (showing only the first six and last four digits).
- We automatically purge unnecessary payment data according to industry best practices.
- Transaction records are maintained only as long as required by law or business necessity.
Third-Party Security
- All payment processors and service providers must meet our strict security standards.
- We verify that all partners maintain PCI DSS compliance.
- Vendor access to payment systems is strictly controlled and monitored.
Your Rights and Our Responsibilities
Your Rights
You have the right to:
- Receive secure processing of your payment information.
- Be notified if a security incident affects your data.
- Request information about how your payment data is protected.
- Report any suspected fraudulent activity on your account.
Our Responsibilities
We commit to:
- Maintaining PCI DSS compliance at all times.
Implementing industry-leading security technologies. - Training our staff on proper data security procedures.
- Responding promptly to any security incidents.
- Continuously improving our security measures.
Security Incident Response
In the unlikely event of a security incident:
- We will immediately investigate and contain any potential breach.
- Affected customers will be notified promptly according to applicable laws.
- We will work with law enforcement and card companies as appropriate.
- We will provide support and guidance to affected customers.
Safe Shopping Tips
To help protect yourself when shopping online:
- Only shop on secure websites (look for "https://" and the lock icon).
- Never share your credit card information via email or unsecured messages.
- Monitor your credit card statements regularly.
- Report any suspicious activity to your card issuer immediately.
- Use strong, unique passwords for your online accounts.
Secure Payment Methods
We accept the following secure payment methods:
- All major credit cards (Visa, MasterCard, American Express, Discover).
- Secure digital wallets (Apple Pay, Google Pay, PayPal).
- All payments are processed through certified, secure payment gateways.
Technical Security Measures
Encryption Standards
- We use TLS 1.2 or higher for all data transmissions.
- Stored data is encrypted using industry-standard AES encryption.
- All encryption keys are securely managed and regularly rotated.
Access Controls
- Multi-factor authentication for all administrative access.
- Role-based access controls limit data access to authorized personnel only.
- All access to payment systems is logged and monitored.
- Regular access reviews ensure proper authorization levels.
Monitoring and Detection
- 24/7 security monitoring of all payment systems.
- Automated fraud detection and prevention systems.
- Real-time alerts for suspicious activities.
- Regular security audits and penetration testing.
Compliance and Certifications
Industry Standards
- PCI DSS Level [X] Certified: We maintain compliance with Payment Card Industry Data Security Standards.
- Regular Audits: Independent security assessments verify our compliance.
- Continuous Monitoring: Ongoing security monitoring ensures maintained compliance.
Regulatory Compliance
We comply with all applicable data protection regulations, including:
- The Privacy Act 2020.
- International data protection requirements where applicable.
- Industry-specific security regulations.
Contact Us About Security
Reporting Security Concerns
If you have questions about our security practices or need to report a security concern:
- Email: info@crane-brothers.com
- Phone: +6493775333
General Questions
For general questions about your orders or account:
- Customer Service: +6493775333
- Email: info@crane-brothers.com
Policy Updates
We may update this policy periodically to reflect changes in our security practices or regulatory requirements. We will post any material changes on this page. Continued use of our services after any changes constitutes acceptance of the updated policy.