Back
Security
Natty Hatty — PCI Compliance Statement (Website)
Effective Date: November 15, 2025
Version: v1.1
Natty Hatty, Inc. (“Natty Hatty,” “we,” “our,” or “us”) takes payment security seriously.
This PCI Compliance Statement describes how payment information is handled when customers make payments on Natty Hatty–hosted public pages, including:
Program registration checkout
Event/tryout payments
Membership or booking payments
Signature + payment combined flows
Any checkout on a Natty Hatty website URL
This statement applies only to the public website and public checkout flows.
Platform-level PCI documentation is provided separately for Organizations.
1. Stripe Processes All Payments (PCI Level 1)
Natty Hatty uses Stripe, Inc. to process all debit/credit card and ACH transactions.
Stripe is certified as a:
PCI DSS Level 1 Service Provider — the highest level of certification available.
Natty Hatty does not store, process, or transmit full card numbers or CVV codes.
2. Natty Hatty’s PCI Scope (SAQ-A)
Because Natty Hatty fully outsources payment processing to Stripe:
Natty Hatty qualifies under PCI SAQ-A scope.
Natty Hatty is PCI-DSS compliant via SAQ-A using Stripe (PCI Level 1 Service Provider).
This means:
Natty Hatty never touches raw card data
Checkout uses Stripe-secured fields and tokenization
PCI obligations are inherited from Stripe’s certification
Sensitive cardholder data bypasses Natty Hatty infrastructure entirely
3. No Card Data Stored on Natty Hatty Systems
Natty Hatty:
Does not store full credit card numbers
Does not store CVV
Does not store unencrypted payment data
Has no access to decrypted card numbers
All saved payment methods are stored by Stripe using secure tokenization.
4. Secure Website Checkout
Natty Hatty uses:
HTTPS/TLS 1.2+ encryption for all website sessions
AES-256 encryption for stored data
Stripe Elements / hosted fields for inputting card details
Stripe’s PCI-compliant tokenization
Stripe Radar for fraud detection
Cloudflare WAF + DDoS protection
These security layers protect all checkout flows.
5. Stripe Security Controls (Inherited by Natty Hatty)
Stripe provides:
PCI DSS Level 1 certification
Industry-leading encryption
Independent annual audits
Secure network segmentation
24/7 fraud monitoring
Hosted PCI-compliant payment fields
NACHA ACH compliance
Natty Hatty inherits all applicable PCI protections through Stripe.
6. Signature + Payment Security (Combined Flow)
When signatures are collected during checkout:
Signature data and payment data are kept separate
Stripe handles all payment info
Natty Hatty handles signature and audit trail generation
Both systems use encrypted, compliant workflows
Signatures remain legally valid (ESIGN/UETA/eIDAS)
No payment information is ever stored in the signature system.
7. Fraud Prevention & Authentication
Natty Hatty uses:
Device & browser fingerprinting
IP verification
Stripe fraud scoring
Rate limiting
Cloudflare bot protection
Real-time anomaly detection
Suspicious activity may temporarily block payments.
8. Responsibilities of Organizations
Organizations using Natty Hatty to collect payments are responsible for:
Completing Stripe onboarding
Setting program pricing
Setting refund/cancellation rules
Maintaining their own financial compliance
Responding to chargebacks and disputes
Natty Hatty is not the merchant of record.
9. Reporting Security Concerns
If you believe your payment information may have been compromised:
Contact your bank immediately
Notify the Organization
Email Natty Hatty at:
security@nattyhatty.com
Natty Hatty will investigate using Stripe logs and internal audit logs.
10. Updates to This Statement
We may update this statement as needed.
The “Effective Date” will indicate the most recent version.
11. Contact
For PCI or payment security questions: