MR.STORE is designed so we never hold full card numbers. Founder-signed scope for Lucky Mart / tenants. Updated 2026-08-14.
| PAN (full card number) | Never |
| CVV / CVC / PIN | Never |
| Track 1 / 2 / magnetic data | Never |
| Chip cryptogram | Never |
| Amount, tax, receipt id, time, store id | Yes |
| Last 4 digits (optional, staff typed) | Yes |
| Auth / approval code from terminal | Yes |
| Brand (Visa / MC) | Yes |
| Batch totals, fees, expected deposit date | Yes |
POS card mode is external terminal or simulate. Staff charge on Square / Clover / PAX / Ingenico. MR.STORE only logs the result. That is SAQ-A / P2PE-out-of-scope for our servers — the terminal vendor is the processor.
Stripe Terminal (when purchased) is SAQ-A-EP: reader talks to Stripe, we send amount + store id, Stripe returns a payment id. Still no PAN on luckymart.biz.
Bank deposits are sent by the card processor, not by MR.STORE. We record batch close + expected T+1 date. Connecting Stripe Connect later attaches their payout id — we still never move PAN.
Owner login is Supabase password + optional TOTP. Employees use PIN on POS, not owner 2FA. Secrets (TOTP) live in server files denied by .htaccess.
Desk: checklist · card batch · app