How TakeTheme and payment gateways protect your customers' payment data.
Last updated: 2026-09-07
🔒 Payment data security in TakeTheme
Protecting your customers' payment data is a shared responsibility between TakeTheme and the payment gateway you choose. Here are the key points you need to know:
TakeTheme does not store customer card data directly. When a customer pays by card, their data is sent directly from the customer's browser to the payment gateway's own servers (Kashier, Paymob, etc.), which is the licensed, accredited party (PCI-DSS) for handling and storing this data securely.
The connection keys (API Keys) you enter in the payment gateway settings (like Secret Key and Public Key) are used only for secure communication between the TakeTheme server and the gateway server — keep them confidential like any password, and don't share them with anyone else.
Enable Two-Factor Authentication on your TakeTheme account and on your account with each payment gateway, to reduce the risk of unauthorized access to your payment settings.
Review user permissions in your store regularly (from Settings → Users & Permissions, if available on your plan) and restrict access to payment gateway settings to only the staff who genuinely need it.
💡 If you notice any strange or unexpected activity on any payment gateway connected to your store (unrecognized login attempts, API key changes you didn't make), change the keys immediately from the gateway's own dashboard and contact TakeTheme support.
❓ Frequently asked questions
Is TakeTheme PCI-DSS compliant?
Card data itself is handled directly by the accredited payment gateway, not by TakeTheme's servers — check each gateway's own compliance certifications (Kashier, Paymob, etc.) on their official website for exact details on their level of accreditation.
Can I see a customer's card data from the TakeTheme dashboard?
No, the TakeTheme dashboard does not display customers' full card numbers — that data is handled by the payment gateway only.