Secure payments
How payments are protected
Casa separates sensitive payment handling from store management and confirms orders only after a trusted payment result is received.
Last updated: 12 July 2026
Secure payment pages
Subscription, domain, and postage payments are processed through Stripe. Customer order payments are completed through the secure Casa Payments checkout. Payment information is entered into payment-provider interfaces rather than being stored in the Casa Commerce database.
Card information
Casa Commerce does not store complete card numbers or card security codes. Payment providers handle card data and may request additional authentication, including 3D Secure, when required by the card issuer or applicable regulation.
Merchant verification and payouts
Merchants complete secure Stripe onboarding before Casa Payments can be activated. Stripe performs the required business and identity checks and controls connected-account payout availability. Casa never asks a merchant to send payment passwords or complete card details by email or through support messages.
Order confirmation
Creating an order does not confirm payment. Orders remain pending until Casa Payments sends a successful payment status that matches the original checkout. Duplicate callbacks are handled safely so the same payment event does not confirm an order twice.
Encrypted connections and protected access
Powered by Casa and merchant domains use HTTPS to encrypt information in transit. Dashboard actions require an authenticated merchant session, and sensitive provider credentials are kept on the server rather than exposed in storefront code.
Questions or concerns
If a payment appears unfamiliar, contact the merchant shown on the order first. Security concerns involving the Casa platform can be reported to hello@codecasastudios.com. Never include a complete card number or password in an email.