The short version
The rest of this page has the detail. If you only read three things, read these.
Where does my money go?
Straight into your own Stripe account. We never hold it, and we are not sitting in the middle of your payouts.
Is my customers' card data safe?
Card numbers never touch our servers. Stripe collects them on its own certified systems and runs the fraud checks.
Who owns my customer list?
You do. Export your customers, orders, and data any time. Nothing here locks you in.

It goes to you, not through us
When someone buys from you, the payment goes straight into your own Stripe account. We never hold your cash and we are not a middleman skimming from the flow. You are the merchant of record, so the funds, the payout schedule, and the customer are yours.
Card numbers never touch our servers. Stripe collects them on its own certified systems, screens each payment with Stripe Radar to catch fraud, and pays out to your bank on the schedule you choose.
11+种支付方式
Stripe认证
Protected, and still yours
The people who buy from you trust you with their details. Here is how we keep that trust from becoming your problem.
Encrypted on the way
Everything between your customers and PersonaCart travels over TLS 1.2 or higher. Checkout, logins, customer details, all of it, encrypted end to end.
Kept apart
Each creator's data sits in its own isolated space. One store can never see another store's customers or orders, no matter what.
Backed up daily
The database is backed up every day to encrypted storage, so a bad day on our side never turns into lost data on yours.
Never sold
We do not sell your data or your customers' data to anyone. We collect the minimum we need to run your store, and we anonymise IP addresses.
Locking the front door
Most break-ins are not clever hacks, they are a guessed password. So the controls that matter most are the ones that stop that.
Two-factor login
Turn on TOTP or email OTP so a stolen password on its own is not enough to get into your account.
Standard sign-in
Logins run through OAuth 2.0, the same flow used by the apps you already trust every day.
Team roles
Adding a helper or a VA? Give them exactly the access they need and nothing more with role-based permissions.
A clear trail
Every important action is logged with a timestamp and the person behind it, so you can always see what changed and when.
您拥有一切
您的内容、客户、业务

您的内容
Every course, download, and file you upload stays yours. We never claim rights to your work, and you can edit or remove any of it whenever you like.
您的客户列表
Your customers are yours, not ours. Export the whole list in one click with emails, purchase history, and engagement, no lock-in.
您的收入
Money lands in your own Stripe account. We take a small platform fee and nothing else, no surprise deductions buried in the fine print.
您的数据
Products, customers, orders, analytics, export all of it any time. You are never trapped here because you cannot leave with your data.
您的品牌
Bring your own domain and your own logo. Customers see your store, not ours, so the brand equity you build stays with you.
您的关系
We run the platform, we do not stand between you and your audience. Talk to your customers directly, on your terms.
What we align with
These are self-declared from how the platform is built and run. They are checked internally, and we are happy to walk through any of them on request.
Everything in transit is encrypted, nothing is sent in the clear.
Card data is handled by Stripe, not by us.
Consent, erasure, and data portability for EU customers.
Access, deletion, and opt-out rights for US state residents.
We build against the common web vulnerability checklist.
Standard, well-tested sign-in flows.
TOTP or email OTP on any account that wants it.
Give teammates only the access they need.
Minimal data, anonymised IPs, and we never sell it.
One store can never read another store's data.
Every important action is recorded with who and when.
The database is backed up daily to encrypted storage.
Want to check any of this for yourself? Contact us and we will share what we can.
基础设施
PersonaCart runs on managed cloud infrastructure with redundancy built in, so a sale can happen at 3am while you sleep and while a server somewhere reboots.
99.9%运行时间
Redundant systems with automatic failover keep your store up. There is no single machine whose bad day takes you offline.
每日备份
Your data is copied every day to more than one secure location, with point-in-time recovery if something ever goes wrong.
全球CDN
Your storefront is served from edge locations around the world, so pages load fast whether a buyer is in Tokyo, London, or New York.
24/7监控
Automated alerts watch the systems day and night, so most issues are caught and fixed before they ever reach your customers.
SOC 2实践
We build to SOC 2 security practices for how data is stored, accessed, and handled across the platform.
定期审计
Security practices are reviewed and tightened on a regular basis as new risks show up, rather than set once and forgotten.
Still have a security question?
Ask it directly. A product specialist will walk you through exactly how any of this works for your store.
Found a bug? Tell us first
If you spot a security hole, please send it to [email protected] before you post it anywhere public. We aim to reply within 48 hours and to fix critical issues within 30 days. Researchers who help us keep creators safe get our genuine thanks.
Please give us the chance to fix it before you share it publicly.