How your payment is actually handled
Some plain mechanics, because "your payment is secure" on its own means nothing.
- The whole of maisonaurevia.com is served over HTTPS with TLS encryption. There is no unencrypted version of this site, and the checkout will not load over plain HTTP.
- The card fields at checkout are not ours. They are an isolated frame served directly by Stripe or Square.
- When you submit, your card number is encrypted in your browser and sent straight to the processor. It is exchanged for a single-use token.
- Our server receives only that token and asks the processor to charge it for the amount we calculated.
- We are told the result, the card brand and the last four digits. That is all we ever see.
The consequence: Maison Aurevia LLC never receives, processes, transmits or stores a full card number, expiry date or CVC. There is no card data on our servers to steal.
PCI DSS compliance
Card payments are processed by Stripe, Inc. and Block, Inc. (Square), both certified PCI-DSS Level 1 service providers — the most rigorous certification in the payment-card industry, independently audited every year.
Because card data is tokenised in your browser and never reaches our systems, Maison Aurevia LLC's own environment falls within the lowest-risk merchant validation category. We maintain that position by using the processors' hosted payment fields and never introducing our own card input.
Cards we accept and network rules
We accept Visa, Mastercard, American Express and Discover. Depending on your device and browser, Stripe may also present Apple Pay, Google Pay or Link. All transactions are in United States Dollars (USD).
We conduct card acceptance in accordance with the Visa Core Rules and Visa Product and Service Rules, the Mastercard Rules, the American Express Merchant Operating Guide and the Discover Network Operating Regulations, as well as the merchant agreements we hold with Stripe and Square.
Fraud and card-testing protection
Card testing — where someone runs stolen card numbers through a checkout to find which ones work — hurts cardholders and merchants alike. We actively defend against it:
- Rate limiting on every payment endpoint, by IP address and by session, so a script cannot hammer the checkout.
- Server-side price authority. Totals are recalculated on our server from our own catalogue. A tampered price in the browser is rejected, not charged.
- Idempotency keys on every charge, so a retry or a double-click cannot take payment twice.
- Hidden honeypot fields and submission timing checks to catch automated form fills.
- Stripe Radar and Square's fraud tooling, which score each attempt using signals from across their networks, including previously failed transactions.
- 3-D Secure / Strong Customer Authentication is triggered automatically where the issuing bank asks for it.
- Logging and monitoring of declined attempts, reviewed for patterns.
Some of this may occasionally decline a legitimate card. If that happens to you, email Maisonaureviallc@outlook.com or call (828) 998-4813 and we will sort it out.
What we store about your payment
| Stored by us | Never stored by us |
|---|---|
| Order reference, items, amounts and currency Your name, email, phone, delivery address Card brand and last four digits Processor transaction ID and status Date and time of the charge |
Full card number (PAN) Expiry date CVC / CVV security code Cardholder authentication data Bank account or routing numbers |
Order records are held outside the public web root and cannot be reached from a browser. Retention periods are in our Privacy Policy.
What you can do
- Check the address bar says
https://before entering card details. It always will on this site — if it does not, stop and email us. - We will never ask for your full card number, CVC or a password by email, phone or text. If someone claiming to be us does, it is not us.
- Keep your order confirmation email. It is the fastest route to support.
- If you see a charge from MAISON AUREVIA you do not recognise, contact us before filing a chargeback — we can usually resolve it the same day.
Security questions, or to report a vulnerability: Maisonaureviallc@outlook.com. We read every report and we will not pursue anyone who reports a genuine issue in good faith.