Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Security

icon

Natty Hatty — PCI-DSS Attestation Statement

Version: v1.1

Effective Date: November 15, 2025

Natty Hatty, Inc. (“Natty Hatty”) is committed to maintaining the security of all payment-related information processed through our platform. This PCI-DSS Attestation Statement describes Natty Hatty’s compliance posture in relation to the Payment Card Industry Data Security Standard (PCI-DSS).

1. Natty Hatty’s Role in the PCI-DSS Payment Ecosystem

Natty Hatty does not store, process, or transmit cardholder data on its servers.

All card data entry, tokenization, transmission, and storage is handled exclusively by Stripe, a PCI-DSS Level 1 Service Provider.

Natty Hatty uses:

  • Stripe Elements

  • Stripe.js

  • Hosted Stripe tokenization

  • Secure redirect / iframe-based collection

As a result, all sensitive cardholder data bypasses Natty Hatty’s infrastructure completely.

2. Stripe PCI-DSS Level 1 Compliance

Stripe is independently certified as:

  • PCI-DSS Level 1 Service Provider (the highest available level)

Stripe’s PCI-DSS AOC (Attestation of Compliance) is available from Stripe upon request.

By utilizing Stripe exclusively for payments, Natty Hatty leverages Stripe’s validated PCI compliance controls.

3. Natty Hatty’s PCI-DSS Scope classNameification

Because Natty Hatty never stores, processes, or transmits cardholder data directly, Natty Hatty qualifies as:

“PCI-DSS SAQ-A Out-of-Scope Service Provider.”

Natty Hatty maintains all controls required for SAQ-A compliance, including:

  • Verified out-of-scope architecture

  • Use of tokenized/hosted payment fields

  • TLS 1.2+ enforced encryption end to end

  • No card data touching Natty Hatty infrastructure

  • Restricted access, logging, and monitoring

  • Annual internal PCI review

  • Security scans and penetration testing

Required Statement:

Natty Hatty is PCI-DSS compliant via SAQ-A using Stripe, Inc. (PCI Level 1 Service Provider).

This is our formal compliance statement for enterprise and audit requirements.

4. What Natty Hatty Does Not Do (Scope Clarification)

Natty Hatty does not:

  • Store card numbers

  • Process card information on Natty Hatty servers

  • Transmit PAN, CVV, or magnetic stripe data

  • Store any sensitive authentication data

  • Access raw cardholder data at any time

Stripe manages all PCI-scoped operations.

5. Annual Validation & Ongoing Security Controls

Natty Hatty conducts the following annually:

  • PCI-DSS SAQ-A validation

  • Internal compliance and architecture review

  • Vulnerability scans

  • Penetration testing

  • Verification that no card data enters Natty Hatty systems

  • HTTPS/TLS validation

  • Security training for all employees

  • Access control and token security audits

These measures ensure that Natty Hatty continuously meets PCI-DSS SAQ-A obligations.

6. Contact for PCI-DSS Inquiries

For PCI or security documentation requests:

security@nattyhatty.com

legal@nattyhatty.com

Enterprise customers may request:

  • Stripe AOC

  • Natty Hatty Security Overview

  • Natty Hatty Incident Response Policy

  • Natty Hatty BC/DR Plan

  • Platform Architecture & Data Flow Diagram

7. Statement of Attestation

Natty Hatty hereby attests that:

  • Natty Hatty is PCI-DSS compliant via SAQ-A, relying exclusively on Stripe, Inc., a PCI Level 1 Service Provider, for all cardholder data functions.

  • Natty Hatty does not store, process, or transmit cardholder data.

  • Natty Hatty maintains all technical and organizational controls required under PCI-DSS SAQ-A.

  • Natty Hatty’s architecture ensures no PCI-scoped data enters or passes through Natty Hatty infrastructure.