See The World TravelTrust Centre
SEE THE WORLD TRAVEL ยท LEGAL & TRUST

Payment Security & Hosted Payment Policy

Protecting payment information and limiting card-data exposure
Effective 29 September 2026

Download PDF

1. Card-data boundary

The See The World Travel website is designed not to receive or retain raw card numbers or CVV data.

2. Hosted/tokenised payments

When card payments are enabled, entry should take place on a properly commissioned hosted or tokenised payment provider flow.

3. Provider due diligence

Before activation, the provider's contractual, privacy, settlement, refund, security and PCI responsibilities must be documented.

4. Payment webhooks

Automated payment status changes must be accepted only from authenticated provider notifications with signature validation and replay protection appropriate to the provider.

5. Records retained

The platform may retain transaction status, amount, currency, method category and provider/reference identifiers required for booking and accounting.

This document forms part of the See The World Travel compliance framework and should be reviewed when material legal, operational, supplier or technology changes occur.