Security · privacy · payments
How we protect your data
Blaze is built so we never handle raw credit card numbers. Payment cards are entered only on Stripe. We store contact, shipping, order details, and payment reference ids — nothing more.
Payments · PCI SAQ A
Target model: Stripe Checkout (hosted) only. Card data is not collected, logged, or stored on Blaze systems. We may keep stripe_checkout_session_id and stripe_payment_intent_id only.
- Never store: Primary Account Number (PAN)
- Never store: CVV / CVC / CID
- Never store: Full magnetic stripe / track data
- Never store: PIN / PIN block
Accounts & orders
Login identity (email / Google / X) is stored in our auth database via Better Auth. Orders and ship-to are recorded server-side without card fields. Guest checkout does not require an account.
What we may store
- Name, email, phone
- Shipping address
- Order line items and amounts
- Stripe session / payment intent ids
- Spocket order id
Browser storage
Cart and optional local preferences may stay on your device for convenience. They never include card numbers. Clear site data anytime in your browser settings.
This page describes engineering controls aimed at a PCI SAQ A style integration with Stripe. It is not a PCI QSA certification or legal advice. Production deploys must use live Stripe keys, webhook signature verification, HTTPS, and least-privilege database access.