Payment Security Notice
How payment-card information is handled when you buy through TotusTix.
Actualizado el 26 de agosto de 2026
Effective Date: August 26, 2026
This Payment Security Notice explains how payment-card information is handled when a customer purchases tickets or related products through TotusTix. It supplements the TotusTix Privacy Policy, Terms of Use, and Ticket Purchase Terms. If there is a conflict regarding payment-card security, this Notice should be read together with those documents and applicable law.
1. Payment Processing Through Stripe
TotusTix uses Stripe, Inc. ("Stripe") as its payment processor. TotusTix is designed so that complete payment-card numbers and card security codes (CVV/CVC) are collected through Stripe-hosted or Stripe-controlled payment components and are not stored on TotusTix servers.
TotusTix does not intentionally collect, store, retain, or make available to its personnel a customer's complete payment-card number or CVV/CVC. Payment authorization, tokenization, and processing of sensitive card data are performed by Stripe through the payment integration used by TotusTix.
2. PCI DSS and Stripe
Stripe maintains validation as a PCI DSS Level 1 Service Provider. PCI DSS is an industry security standard for organizations that store, process, or transmit payment-card data.
Use of Stripe does not eliminate TotusTix's own security responsibilities. TotusTix remains responsible for securely implementing and maintaining its website, checkout flow, administrative accounts, integrations, and systems under its control. TotusTix does not represent that it is independently "PCI certified" unless and until any such representation is specifically supported by the validation applicable to its merchant environment.
3. Information TotusTix May Receive and Retain
To process and administer orders, provide support, prevent fraud, maintain accounting records, respond to disputes, and comply with legal and tax obligations, TotusTix may receive and retain limited transaction information from Stripe and other service providers, including:
- Payment and order status, including successful, failed, refunded, canceled, or disputed transactions;
- Order, payment, transaction, refund, and dispute identifiers;
- Card brand and the last four digits of the payment card, when provided by Stripe;
- Expiration month and year, when provided by Stripe;
- Billing name, billing address, email address, telephone number, and other information supplied during checkout;
- Fraud-prevention, authentication, and risk signals made available by Stripe; and
- Refund, chargeback, dispute, and customer-service records.
This limited information is not the same as retaining the complete payment-card number or CVV/CVC. TotusTix does not use stored card credentials outside the functionality made available through Stripe and the customer's authorized transaction flow.
4. Digital Wallets and Alternative Payment Methods
When TotusTix offers an eligible digital wallet or alternative payment method through Stripe, the payment provider may use tokenized or device-specific credentials instead of the customer's underlying card number. The availability and handling of those methods may also be subject to the terms and privacy practices of the applicable wallet or payment provider.
5. Fraud Prevention and Transaction Security
TotusTix and its service providers may use automated and manual security measures to detect suspicious activity, unauthorized purchases, account compromise, payment fraud, excessive refund activity, chargeback abuse, or other misuse. For security reasons, TotusTix does not publicly disclose the detailed configuration of its fraud-prevention controls.
6. Chargebacks and Payment Disputes
If you believe a TotusTix charge is incorrect, you may contact TotusTix customer support through the support channel identified on TotusTix.com so the transaction can be reviewed. Contacting TotusTix first does not waive or limit any rights you may have with your card issuer or payment provider. Additional terms regarding refunds, reversals, and chargebacks appear in the Ticket Purchase Terms.
7. Security Incidents
TotusTix maintains processes intended to identify and respond to security incidents affecting systems or information under its control. If TotusTix determines that notice of a security incident is required by applicable law, TotusTix will provide notice in the manner and within the timeframe required by that law.
8. Changes to This Notice
TotusTix may update this Payment Security Notice to reflect changes in law, payment technology, security practices, service providers, or the TotusTix checkout architecture. The version posted on TotusTix.com will identify its effective date. Material changes will apply prospectively unless otherwise required by law.
9. Questions
Questions regarding payment security may be submitted through the customer support or legal contact channel identified on TotusTix.com
