A payment company is only worth as much as the trust people place in it. This page explains, in plain language, how card data, merchant money and your account are protected, and what we will never do.
Card data never touches us
Card numbers are entered on, and processed by, a PCI DSS Level 1 certified platform. Kuentoo receives a token and a result, never the card number.
3-D Secure 2.2
Online payments use strong customer authentication where the card issuer requires it. That shifts fraud liability away from the merchant.
Two-factor login, always
Every portal and back-office login requires an authenticator code. There is no way to switch it off.
Signed webhooks & keys
Every event we send to your systems is signed. API keys are shown once, stored hashed, and can be revoked instantly.
Your customers' card data
The payment page at kuentoo.com/pay shows the amount, the merchant and the reference, then hands the cardholder to a hosted, certified payment form. That form is served by our acquiring partner, not by us. What comes back to Kuentoo is a transaction reference, the last four digits and the card scheme, which is what you see in your portal. Full card numbers, CVC codes and PINs are never transmitted to, stored by or visible to Kuentoo or the merchant.
Merchant money
- Every cent is recorded in an append-only ledger: nothing is edited or deleted, corrections are new entries. You see the same ledger we see.
- Payouts only go to the bank account verified during onboarding. Changing it requires a new verification and is confirmed by e-mail.
- Payouts above a threshold need approval by two separate Kuentoo staff members before they are sent.
- Monthly statements carry a sequential invoice number, so nothing can be inserted or removed afterwards.
- Nightly encrypted backups, kept for 35 days, in a separate storage location.
Your account
Logging in always takes a password and a one-time code from an authenticator app. Sessions expire. Each team member has their own login with their own permissions, so a cashier cannot issue refunds and a bookkeeper cannot change bank details. Every action in the portal is written to an audit trail with who, what and when.
Chargebacks and disputes
If a cardholder disputes a payment, you see it in your portal the moment it arrives, with the evidence deadline and a checklist of what to upload. We submit the evidence to the card scheme on your behalf and keep you informed at every step. Clear descriptions and merchant names on the payment page are the best prevention; we help you set both.
What we will never do
- Ask for your password, authenticator code, card number or PIN by e-mail, phone, WhatsApp or chat.
- Send a payment page or login link on any domain other than kuentoo.com.
- Change your payout bank account without a verification you complete yourself.
- Sell, share or use transaction data for anything other than processing your payments and meeting our legal obligations.
Report a security concern
Found something that looks wrong, or received a suspicious message that claims to be from us? Write to security@kuentoo.com. We reply to every report and we do not take action against researchers who report in good faith.
This page describes our current practices in general terms. The Merchant Agreement and the terms of our acquiring partner govern the contractual relationship.
