Skip to content
TablemarkSign up
Security

What happens to a card number, and what happens to a name.

Two different kinds of sensitive data pass through this service. Neither is treated casually, and neither is described here in language designed to sound impressive rather than be checked.

Connection
HTTPS everywhere
Card numbers
Never stored by us
Payment page
Hosted by our provider
Guest names
Encrypted at field level
Breach notice
Within 72 hours
Currency
USD
Payments

Your card details do not reach our servers.

Card entry happens on a page hosted by our payment provider, which is certified to the Payment Card Industry Data Security Standard. We receive the result of the transaction, not the instrument that made it.

  • What we receive

    Whether the payment succeeded, the last four digits, the card brand, the billing country and the billing name.

  • What we never receive

    The full card number, the expiry date and the security code. We could not store them if we wanted to; they do not pass through our systems.

  • Connection

    Every page on this site, including the payment page, is served over HTTPS with modern TLS. Plain HTTP requests are redirected, not accepted.

  • Card testing

    Payment attempts are rate limited and screened for the patterns used in card testing, which protects both you and the cardholders whose numbers get abused that way.

  • Refunds

    Issued back to the card that paid, through the same provider. We cannot send a refund anywhere else, which is a protection rather than a limitation.

Before you are charged

Every checkout shows all of the following on one screen, before the payment step and with nothing collapsed:

  • The plan name and exactly what it includes
  • The amount, written in USD
  • The billing period, monthly or yearly
  • That it renews automatically until cancelled
  • The date of the next charge
  • How to cancel, in one sentence
  • Any tax that applies where you are
On your statement

Charges appear as TABLEMARK. If a line on your statement is unfamiliar, email support@maburedeai.shop with the date and amount before raising a dispute — we will identify it the same day and refund it if it should not be there.

Cards accepted
VisaMastercardAmerican Express
Guest data

The measures protecting other people's names.

These are the specific controls in place. We do not describe them as unbreakable, because that claim is never true and would tell you nothing useful.

In transit

TLS on every connection, internal and external.

At rest

Encrypted storage, with guest name fields encrypted at field level.

Access

Multi-factor authentication for production, role-based permissions, least privilege.

Logging

Every read and export of a guest list is recorded, and you can inspect that log.

Staff access

Only when you raise a support request that requires it, and it appears in the same log.

Passwords

Salted hashes. We cannot read your password and cannot send it to you.

Backups

Encrypted, cycled out within 35 days, never used to restore records you deleted.

Retention

Hard deletion on your schedule: 30, 60 or 90 days, or 14 days after the event.

Breach notice

You are told within 72 hours of us becoming aware, with what we know at the time.

The legal detail behind all of this.

The privacy policy sets out lawful bases and retention; the DPA sets out our obligations as your processor, including the 72 hour notice and the named sub-processors.

Something not covered here? Ask us directly — we answer security questions in writing, in detail, before you buy anything.