Legal

PCI Compliance

Effective September 2, 2026. Flowpay is a d/b/a of QuantPro Logistics LLC.

Every business that accepts credit or debit cards has to follow the Payment Card Industry Data Security Standard (PCI DSS). It is a set of security requirements written by the card brands and maintained by the PCI Security Standards Council, and it is enforced through your merchant agreement rather than by a government agency.

This page explains what the standard requires, what Flowpay handles, and what stays your responsibility.

Flowpay's role

Flowpay is an independent sales organization and referral agent. We place merchants with acquiring banks and processors and support the accounts afterward. We are not the acquirer of record and we are not a payment gateway.

Flowpay does not store, process, or transmit cardholder data. We do not collect full card numbers, magnetic stripe or chip data, CVV codes, or PINs, and we never ask a merchant or a merchant's customer to send them to us. Card transactions run on the systems of PCI DSS validated acquirers, processors, and gateways.

Because we handle merchant application and account data rather than cardholder data, our obligations focus on protecting the business and owner information you give us. That is covered in our Privacy Policy.

What we do for merchants

What you are responsible for

PCI compliance follows the merchant. Under your processing agreement, your business is responsible for:

Which questionnaire applies to you

SAQTypical setup
SAQ AE-commerce that fully outsources payment pages to a validated third party. No card data touches your systems.
SAQ A-EPE-commerce where your site controls the payment page but a third party processes the transaction.
SAQ BStandalone dial-up or imprint terminals with no electronic cardholder data storage.
SAQ B-IPStandalone IP-connected terminals validated to the PCI PTS standard, with no electronic storage.
SAQ C-VTVirtual terminal on an isolated computer, entered manually one transaction at a time.
SAQ CPayment application connected to the internet, with no cardholder data storage.
SAQ P2PEHardware terminals on a validated point-to-point encryption solution. The shortest questionnaire available.
SAQ DEveryone else, including merchants who store cardholder data.

If you are not sure which one fits, reach out and we will map it to how you actually take payments.

Merchant levels

The card brands assign a level based on annual transaction count, which determines how compliance is validated. Levels 2 through 4 generally validate with a Self-Assessment Questionnaire and an Attestation of Compliance. Level 1 merchants, and any merchant following a breach, require an onsite assessment by a Qualified Security Assessor. Thresholds differ slightly among Visa, Mastercard, Discover, and American Express.

Why it matters

If you suspect a compromise

Contain the problem but do not wipe or rebuild affected systems, since forensic evidence must be preserved. Notify us and your processor immediately using the contact details in your merchant agreement. Card brand rules require prompt reporting and, in most cases, a forensic investigation by a PCI Forensic Investigator.

Further reading

The full standard, the questionnaires, and the lists of validated service providers are published by the PCI Security Standards Council at pcisecuritystandards.org.

Questions

Flowpay, a d/b/a of QuantPro Logistics LLC
Reach us through the request forms at getflowpay.net, or at the contact address listed in your signed agreement.

This page is general information about PCI DSS, not legal advice or a certification of your compliance status. Your obligations are set by your merchant processing agreement and the card brand rules.