Your account’s data is kept separate from every other SimplePayment account.

How it works

Every request to your data is scoped to your organization. Invoices, clients, and settings are only ever returned for your own account — never another customer’s.

Important behavior and limitations

  • This is application-level isolation, enforced on every request — not a claim that each customer has a physically separate database.
  • SimplePayment doesn’t hold SOC 2, ISO 27001, or PCI DSS certification — it doesn’t need to, because it never touches raw card data. Stripe’s infrastructure is PCI-compliant and handles that directly. See Security for more on SimplePayment’s overall approach to security.

Still need help?

Contact SimplePayment Support and a real person will help you out.

Contact support