Security & PCI compliance
Last updated October 7, 2026. TermReceipt is owned and operated by Aldenworth Consulting LLC.
Card payments never touch TermReceipt
Every TermReceipt purchase is paid on Lumino's hosted checkout page. Card numbers, expiry dates and security codes are entered on that page and handled by Lumino and its processing partner under the Payment Card Industry Data Security Standard (PCI DSS). TermReceipt's own systems never receive, transmit or store full card numbers or security codes.
Our PCI scope
Because cardholder data is fully outsourced to a PCI DSS validated payment provider through a hosted payment page, TermReceipt completes the Self-Assessment Questionnaire that applies to merchants with no electronic cardholder data on their own systems, and keeps it current with our processor.
- No card data is stored, processed or transmitted by TermReceipt servers, databases, emails or logs.
- We never ask customers or merchants to send card numbers by email, chat or phone.
- Payment links point only to the processor's hosted checkout.
How we protect your records
- Every page and API is served over HTTPS with HSTS; our pages cannot be framed by other sites.
- Transaction records are frozen when created and every step is sealed to the one before it, so any change is detectable.
- Customer email codes, session tokens and record links are stored only as one-way hashes.
- Each company's data is isolated in the database by row-level security; staff access requires sign-in and, where enabled, an authenticator code.
- Data is backed up and restores are tested.
Reporting a security issue
Email support@termreceipt.com or call (904) 709-7055. Please do not include card numbers or passwords.