Get a free website with any plan

See how
HOSTING

PCI DSS and taking online payments

IN SHORT

PCI DSS is the security standard for anyone who stores, processes, or transmits card data. Most online stores stay out of its heaviest requirements by routing payments through a gateway like Stripe or PayPal, since the gateway handles cardholder data and your Flashcloud hosting only ever sees a token or a paid confirmation.

Selling online safely comes down to one idea: don't let raw card numbers touch systems you have to secure yourself. Most stores get there with a payment gateway, plus HTTPS everywhere and up-to-date software.

Let a payment gateway handle cards

The safest and most common setup is to process payments through a gateway like Stripe, PayPal, or a similar provider. The customer enters their card details on the gateway's hosted fields or checkout, the gateway handles the sensitive card data, and your site only ever receives a token or a "paid" confirmation. Raw card numbers are never stored on your hosting.

This is the recommended approach for shared and WordPress hosting, WooCommerce stores included. It keeps the hardest part of payment security, handling and storing cardholder data, with a specialist built and certified for it, and it shrinks your own PCI DSS scope considerably.

Secure the rest of your store

  • HTTPS everywhere. Every page, not only checkout, should load over HTTPS. We auto-issue and renew SSL certificates and redirect HTTP to HTTPS by default. See SSL certificates and Forcing HTTPS on your site.
  • Keep software updated. Your CMS, store platform, plugins, and themes are the most common way stores get compromised. Patch promptly. For WordPress and WooCommerce, see Securing your WordPress site.
  • Strong admin access. Unique passwords and two-factor authentication on every account that can reach your store's admin or the portal.
  • Lean on what we run. ModSecurity WAF, ImunifyAV malware scanning, DDoS scrubbing, and automatic security patching run on every hosting account. They reduce risk, but they don't replace a gateway.

Where PCI DSS fits

PCI DSS (Payment Card Industry Data Security Standard) is the security standard that applies to anyone who stores, processes, or transmits card data. A few points to be clear about:

  • Using a gateway keeps most of PCI scope off your hosting. When card data goes straight to the gateway, your compliance burden is much smaller, usually a simpler self-assessment questionnaire.
  • The merchant certifies, not the host. PCI compliance is something you, the merchant, attest to for your business. Flashcloud does not hold or provide a PCI certification on your behalf.
  • Dedicated Servers provide infrastructure that supports PCI DSS compliance. If your setup requires you to handle card data directly, a Dedicated Server gives you an isolated environment to build a compliant configuration on. Completing the certification is still yours to do.

A safe default

For almost every store: use a reputable payment gateway, keep HTTPS on across the whole site, and keep your software patched. That combination keeps cardholder data off your hosting and your PCI scope small, on any Flashcloud plan.

Common questions

Do I need to be PCI compliant if I use Stripe or PayPal?

You still need to complete a self-assessment, but it's a much simpler one. Since the gateway handles and stores the card data, your PCI scope shrinks considerably and raw card numbers never touch your hosting.

Is Flashcloud PCI certified?

No. PCI compliance is something the merchant attests to for their own business, not something a host certifies on your behalf. Flashcloud does not hold or provide a PCI certification for you.

Can I store customer card numbers on my WooCommerce site?

The recommended setup is to never let raw card numbers touch your hosting at all. Process payments through a gateway like Stripe or PayPal instead, which is the standard approach for shared and WordPress hosting, WooCommerce included.

What do I need to do on my end to keep payments secure?

Use a reputable payment gateway, keep HTTPS on across your whole site, and keep your CMS, plugins, and themes patched. Flashcloud also runs ModSecurity WAF, ImunifyAV malware scanning, DDoS scrubbing, and automatic security patching on every account, though those don't replace a gateway.

What if my setup requires me to handle card data directly?

A Dedicated Server gives you an isolated environment to build a compliant configuration on. It supports PCI DSS compliance, but completing the certification itself is still your responsibility.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.