Legal
PCI Compliance
Effective September 2, 2026. Flowpay is a d/b/a of QuantPro Logistics LLC.
Every business that accepts credit or debit cards has to follow the Payment Card Industry Data Security Standard (PCI DSS). It is a set of security requirements written by the card brands and maintained by the PCI Security Standards Council, and it is enforced through your merchant agreement rather than by a government agency.
This page explains what the standard requires, what Flowpay handles, and what stays your responsibility.
Flowpay's role
Flowpay is an independent sales organization and referral agent. We place merchants with acquiring banks and processors and support the accounts afterward. We are not the acquirer of record and we are not a payment gateway.
Flowpay does not store, process, or transmit cardholder data. We do not collect full card numbers, magnetic stripe or chip data, CVV codes, or PINs, and we never ask a merchant or a merchant's customer to send them to us. Card transactions run on the systems of PCI DSS validated acquirers, processors, and gateways.
Because we handle merchant application and account data rather than cardholder data, our obligations focus on protecting the business and owner information you give us. That is covered in our Privacy Policy.
What we do for merchants
- Place you on validated platforms. The processors, gateways, and terminals we deploy are PCI DSS validated by their providers and appear on the card brands' compliant service provider lists.
- Deploy encryption and tokenization where available. Point-to-point encryption devices and tokenized gateway storage keep card data out of your systems, which reduces both your risk and the scope of your annual assessment.
- Program equipment to standard. Terminals are configured so that full card numbers are not retained on the device and sensitive authentication data is not stored after authorization.
- Walk you through your annual validation. We help you identify the right Self-Assessment Questionnaire, complete it, and get quarterly scanning arranged if your setup requires it.
- Flag noncompliance fees. Most processors assess a monthly fee when validation lapses. We monitor for it and help you resolve the underlying issue rather than pay it indefinitely.
What you are responsible for
PCI compliance follows the merchant. Under your processing agreement, your business is responsible for:
- Completing a Self-Assessment Questionnaire or Report on Compliance every year and re-attesting on schedule.
- Passing quarterly network scans by an Approved Scanning Vendor if you accept cards online or have card systems reachable from the internet.
- Never storing full magnetic stripe data, chip data, CVV codes, or PIN data after a transaction is authorized, in any system or on paper.
- Protecting any stored card numbers with encryption, restricted access, and a documented retention and destruction schedule.
- Changing vendor default passwords, using unique credentials per user, and enabling multi-factor authentication on remote access.
- Keeping systems patched, running anti-malware where applicable, and segmenting card systems from general business networks.
- Inspecting terminals and PIN pads for tampering or substitution.
- Training staff on card handling and maintaining an incident response plan.
- Using PCI DSS validated service providers and maintaining a list of them.
Which questionnaire applies to you
| SAQ | Typical setup |
|---|---|
| SAQ A | E-commerce that fully outsources payment pages to a validated third party. No card data touches your systems. |
| SAQ A-EP | E-commerce where your site controls the payment page but a third party processes the transaction. |
| SAQ B | Standalone dial-up or imprint terminals with no electronic cardholder data storage. |
| SAQ B-IP | Standalone IP-connected terminals validated to the PCI PTS standard, with no electronic storage. |
| SAQ C-VT | Virtual terminal on an isolated computer, entered manually one transaction at a time. |
| SAQ C | Payment application connected to the internet, with no cardholder data storage. |
| SAQ P2PE | Hardware terminals on a validated point-to-point encryption solution. The shortest questionnaire available. |
| SAQ D | Everyone else, including merchants who store cardholder data. |
If you are not sure which one fits, reach out and we will map it to how you actually take payments.
Merchant levels
The card brands assign a level based on annual transaction count, which determines how compliance is validated. Levels 2 through 4 generally validate with a Self-Assessment Questionnaire and an Attestation of Compliance. Level 1 merchants, and any merchant following a breach, require an onsite assessment by a Qualified Security Assessor. Thresholds differ slightly among Visa, Mastercard, Discover, and American Express.
Why it matters
- Processors charge monthly noncompliance fees when validation lapses, and those fees typically exceed the cost of completing the questionnaire.
- A breach at a noncompliant merchant can bring card brand fines, forensic investigation costs, card reissuance costs, and liability for fraud losses.
- Compliance is a contractual obligation in your merchant agreement. Failure to maintain it can result in account termination.
If you suspect a compromise
Contain the problem but do not wipe or rebuild affected systems, since forensic evidence must be preserved. Notify us and your processor immediately using the contact details in your merchant agreement. Card brand rules require prompt reporting and, in most cases, a forensic investigation by a PCI Forensic Investigator.
Further reading
The full standard, the questionnaires, and the lists of validated service providers are published by the PCI Security Standards Council at pcisecuritystandards.org.
Questions
Flowpay, a d/b/a of QuantPro Logistics LLC
Reach us through the request forms at getflowpay.net, or at the contact address listed in your signed agreement.
This page is general information about PCI DSS, not legal advice or a certification of your compliance status. Your obligations are set by your merchant processing agreement and the card brand rules.