Security, Compliance, and Support
Answers to common questions about PayNowPro, PowerTranz, compliance, support, and data ownership.
This page gives a high-level overview for customers and prospective customers. Your order form, service agreement, data processing agreement, and the applicable PowerTranz terms control if they differ from this page.
PayNowPro and PowerTranz responsibilities
PayNowPro uses PowerTranz, formerly known as First Atlantic Commerce (FAC), for payment-gateway services. PayNowPro supports the integration layer and its own services. PowerTranz is the appropriate source for payment-processor, gateway, card-data, tokenization, PCI DSS, and processor-attestation questions.
For a question that concerns how card payments are processed, collected, transmitted, tokenized, or stored, contact PowerTranz through your merchant, acquirer, or PowerTranz account contact. For questions about your PayNowPro integration, account, API, or service, contact the support channel provided with your service.
PCI DSS and payment security
Is PayNowPro PCI DSS compliant?
PCI DSS obligations depend on the services used, the payment flow, and each party's role. Using PayNowPro does not by itself make a merchant PCI DSS compliant.
PowerTranz is responsible for the PCI DSS status, attestations, and processor documentation that apply to its payment-gateway services. Request the relevant evidence directly from PowerTranz, your acquirer, or the merchant relationship that provides your PowerTranz service. PayNowPro can explain the integration flow and identify the PayNowPro components in scope, but it does not issue PCI DSS attestations on PowerTranz's behalf.
Does PayNowPro store card details?
Your integration should minimize the cardholder data it handles. The configured PowerTranz payment flow determines where payment details are collected, transmitted, tokenized, and stored. Confirm the data path for your implementation with PowerTranz before going live.
Do not send sensitive authentication data, such as a card verification value (CVV/CVC), to PayNowPro unless the documented payment flow explicitly requires it. Never store sensitive authentication data after authorization.
Does PayNowPro use tokenization?
Tokenization is a PowerTranz payment-gateway capability. PowerTranz determines how a token is created, scoped, stored, and reused for the configured payment flow.
For tokenization availability or behavior—including use across environments, currencies, merchants, or payment methods—contact PowerTranz through your merchant, acquirer, or PowerTranz account contact. PayNowPro can help you identify the integration path that uses the applicable PowerTranz capability.
Compliance documentation
What security or compliance documentation is available?
PayNowPro can provide information about the PayNowPro integration and its operational responsibilities, subject to applicable confidentiality requirements. For payment-processor evidence, including PCI DSS attestations or PowerTranz gateway-security documentation, contact PowerTranz, your acquirer, or the merchant relationship that provides your PowerTranz service.
For a PayNowPro integration review, send your request through the support channel provided with your service. Include the requested due date, the legal entity being assessed, the products in scope, and any required non-disclosure agreement.
Can you complete our security questionnaire?
PayNowPro can review reasonable questions about the PayNowPro services you use. Responses are limited to information we can verify and may require a confidentiality agreement.
Direct questions about PowerTranz, First Atlantic Commerce, PCI DSS attestation, gateway controls, tokenization, or payment processing to PowerTranz or the relevant acquirer. PayNowPro does not complete those questions or make attestations on PowerTranz's behalf.
Service availability and support
Is there a service-level agreement (SLA)?
Any availability target, service credit, support-response target, maintenance window, or other service-level commitment must be stated in your executed agreement or service plan. This page is not an SLA and does not create a service-level commitment.
If you are evaluating PayNowPro, ask your account contact for the service terms that apply to your proposed plan. Existing customers should refer to their order form or service agreement.
How do I get technical support?
Send PayNowPro integration, account, API, or operational questions through the support channel provided with your service. To help us investigate quickly, include:
- Your organization name and the email address associated with your account
- The production environment affected
- A description of the issue and the time it began, including the time zone
- Relevant request IDs, payment or subscription IDs, and non-sensitive logs
- The impact on your customers or business operations
Do not include full card numbers, CVV/CVC values, passwords, API keys, or other secrets in a support request.
Send PowerTranz payment-gateway, processor, tokenization, card-data, or gateway-attestation questions to PowerTranz through your merchant, acquirer, or PowerTranz account contact.
How are urgent issues escalated?
For a suspected production incident affecting PayNowPro, use the urgent or incident channel included in your service plan and clearly state that the issue affects production. Include the business impact, scope, start time, and any mitigation already attempted.
For an incident involving PowerTranz gateway processing or the underlying payment processor, follow the escalation process provided by PowerTranz, your merchant, or your acquirer. PayNowPro will coordinate on integration issues where appropriate, but PowerTranz owns its gateway and processor incident response.
Data ownership and access
Who owns the data in our account?
As between you and PayNowPro, you retain your rights in the business and customer data you submit to PayNowPro, subject to the applicable agreement and law. You are responsible for ensuring you have an appropriate legal basis to collect, use, and share that data.
PayNowPro processes data only as needed to provide, secure, maintain, and support its service, and as otherwise permitted by the applicable agreement and law. PowerTranz processes payment data under its own terms, privacy documentation, and payment-gateway obligations.
Can we access or export our data?
Available PayNowPro data-access and export options depend on the products and integrations you use. Contact PayNowPro support with the data types, date range, and format you need. We will confirm the available option and any applicable identity-verification, security, retention, or contractual requirements.
For payment-gateway or processor data held by PowerTranz, contact PowerTranz, your acquirer, or the merchant relationship that provides your PowerTranz service.
What happens to our data when the service ends?
PayNowPro retention, deletion, and return procedures are governed by your agreement and applicable law. Before ending service, contact PayNowPro to plan exports, credential rotation, webhook changes, and any required transition steps.
PowerTranz retention, deletion, and return procedures for payment-gateway data are governed by your PowerTranz, acquirer, or merchant agreement. Direct those questions to the relevant PowerTranz relationship.
Contact us
Contact PayNowPro through the support or account channel provided with your service for integration, API, account, and PayNowPro service questions. Contact PowerTranz, your acquirer, or your merchant relationship for payment-gateway, processor, card-data, tokenization, PCI DSS, and PowerTranz-attestation questions.