TPLby SORVYRA Back to TPL

Checkout safeguards

Payment Security & PCI Checkout Statement

This statement explains how payment-card information is handled when purchasing a TPL subscription or marketplace product.

1. Hosted checkout redirect

TPL uses Flutterwave Standard, a secure hosted-checkout redirect gateway. When a customer continues to payment, TPL creates the order on its server and redirects the customer to an HTTPS checkout page hosted by Flutterwave.

2. Card information

Customers enter payment-card information directly into Flutterwave's hosted checkout. TPL and SORVYRA do not collect, transmit, process, or store complete card numbers, card verification values (CVV), card PINs, or one-time authentication codes on SORVYRA systems.

3. PCI DSS payment processor

Flutterwave states that its payment-gateway processing environment is PA DSS and PCI DSS compliant. Payment-card processing is performed within Flutterwave's payment environment. Learn more from Flutterwave's published security information.

4. Server-side verification

A browser redirect alone does not grant paid access. After checkout, TPL independently verifies the transaction with Flutterwave and checks the transaction reference, currency, amount, payment status, and purchased product before activating a subscription or delivering a digital purchase.

5. Records retained by TPL

For fulfillment, reconciliation, fraud prevention, and customer support, TPL may retain non-sensitive transaction information such as the order reference, Flutterwave transaction identifier, product, amount, currency, payment status, and timestamps. TPL does not retain complete card details.

6. Payment support

For payment questions, contact accounts@sorvyra.com or review our Refund Policy. Never send complete card details, passwords, or authentication codes.

Last updated: August 19, 2026