PCI DSS scope — one pager

MR.STORE is designed so we never hold full card numbers. Founder-signed scope for Lucky Mart / tenants. Updated 2026-08-14.

What we never store

PAN (full card number)Never
CVV / CVC / PINNever
Track 1 / 2 / magnetic dataNever
Chip cryptogramNever

What we may store after a sale

Amount, tax, receipt id, time, store idYes
Last 4 digits (optional, staff typed)Yes
Auth / approval code from terminalYes
Brand (Visa / MC)Yes
Batch totals, fees, expected deposit dateYes

How cards are taken today

POS card mode is external terminal or simulate. Staff charge on Square / Clover / PAX / Ingenico. MR.STORE only logs the result. That is SAQ-A / P2PE-out-of-scope for our servers — the terminal vendor is the processor.

Stripe Terminal (when purchased) is SAQ-A-EP: reader talks to Stripe, we send amount + store id, Stripe returns a payment id. Still no PAN on luckymart.biz.

ACH / payouts

Bank deposits are sent by the card processor, not by MR.STORE. We record batch close + expected T+1 date. Connecting Stripe Connect later attaches their payout id — we still never move PAN.

Owner 2FA / access

Owner login is Supabase password + optional TOTP. Employees use PIN on POS, not owner 2FA. Secrets (TOTP) live in server files denied by .htaccess.

Desk: checklist · card batch · app