Security and data handling, in plain terms

Fundraising runs on trust. Here is exactly how TPG-POS handles supporter data, card payments and campaign separation — written to be shared with your board, your compliance team and your partners.

How the platform protects your supporters

Card data never touches the platform

Card numbers and security codes are entered on the payment provider's own hosted checkout page, on the payment terminal, or through the provider's contact-centre payment path. They are never posted to a campaign site or to the platform, and are never stored. The platform keeps only the amount, status, card brand, last four digits, timestamps and receipt reference — keeping campaigns within PCI-DSS SAQ-A scope.

Data held in Australia

Supporter data is processed and stored in Australia on AWS Sydney (ap-southeast-2). There are no self-managed servers, and daily backups with point-in-time recovery are held in the same region.

Encrypted everywhere

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Server-side credentials are held in a managed secret store and never reach the browser.

Access enforced in the database

Access rules are enforced at the database layer for every user and every table — not just hidden in the menus. Reporting and exports are limited to the user's own scope: a charity's export contains that campaign's supporters and nothing else.

Strict separation between campaigns

Each campaign uses its own payment provider account with its own restricted key, and funds settle to the campaign's own account — nothing is pooled. Payment confirmations arrive as signed server-to-server messages verified against a per-account signing secret.

Your email identity, not ours

Each campaign sends from its own address on its own subdomain, with its own SPF, DKIM and DMARC records — never from a shared sender. Outbound email carries recipient address and message content only.

No behavioural tracking

No third-party behavioural analytics or marketing pixels are placed on supporter-facing pages or in supporter emails.

No connected service has database access

Every integration — payments, email, agent registries, contact centres — exchanges a defined set of data through authenticated endpoints. Nothing is given direct access to the platform's database.

Scope boundaries

Firm lines the platform does not cross:

  • Supporters have no accounts, passwords or logins.
  • Full card numbers and security codes are never stored, under any circumstances.
  • Supporter data is processed and held in Australia.
  • No third-party behavioural analytics or marketing pixels on supporter-facing pages or in supporter emails.
  • No connected service has direct access to the platform database; every exchange goes through a defined, authenticated endpoint.
  • Reporting and exports are limited to the user's own scope.

Questions from your compliance team?

We're happy to walk your team through the architecture, data flows and payment separation in detail.

Contact us