Security and data handling, in plain terms
Fundraising runs on trust. Here is exactly how TPG-POS handles supporter data, card payments and campaign separation — written to be shared with your board, your compliance team and your partners.
How the platform protects your supporters
Card data never touches the platform
Card numbers and security codes are entered on the payment provider's own hosted checkout page, on the payment terminal, or through the provider's contact-centre payment path. They are never posted to a campaign site or to the platform, and are never stored. The platform keeps only the amount, status, card brand, last four digits, timestamps and receipt reference — keeping campaigns within PCI-DSS SAQ-A scope.
Data held in Australia
Supporter data is processed and stored in Australia on AWS Sydney (ap-southeast-2). There are no self-managed servers, and daily backups with point-in-time recovery are held in the same region.
Encrypted everywhere
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Server-side credentials are held in a managed secret store and never reach the browser.
Access enforced in the database
Access rules are enforced at the database layer for every user and every table — not just hidden in the menus. Reporting and exports are limited to the user's own scope: a charity's export contains that campaign's supporters and nothing else.
Strict separation between campaigns
Each campaign uses its own payment provider account with its own restricted key, and funds settle to the campaign's own account — nothing is pooled. Payment confirmations arrive as signed server-to-server messages verified against a per-account signing secret.
Your email identity, not ours
Each campaign sends from its own address on its own subdomain, with its own SPF, DKIM and DMARC records — never from a shared sender. Outbound email carries recipient address and message content only.
No behavioural tracking
No third-party behavioural analytics or marketing pixels are placed on supporter-facing pages or in supporter emails.
No connected service has database access
Every integration — payments, email, agent registries, contact centres — exchanges a defined set of data through authenticated endpoints. Nothing is given direct access to the platform's database.
Scope boundaries
Firm lines the platform does not cross:
- Supporters have no accounts, passwords or logins.
- Full card numbers and security codes are never stored, under any circumstances.
- Supporter data is processed and held in Australia.
- No third-party behavioural analytics or marketing pixels on supporter-facing pages or in supporter emails.
- No connected service has direct access to the platform database; every exchange goes through a defined, authenticated endpoint.
- Reporting and exports are limited to the user's own scope.
Questions from your compliance team?
We're happy to walk your team through the architecture, data flows and payment separation in detail.
Contact us