SchedulingKit
PCI DSS Compliance

Appointment Payments and PCI DSS

Collect appointment payments and deposits through connected payment providers. SchedulingKit's Stripe flow uses Stripe Elements to collect payment details. Stripe's Level 1 service-provider certification does not replace your business's own PCI DSS responsibilities or validation requirements.

Using a payment provider reduces direct card handling but does not transfer all PCI responsibilities. Collect appointment payments and deposits through connected payment providers. SchedulingKit's Stripe flow uses Stripe Elements to collect payment details. Stripe's Level 1 service-provider certification does not replace your business's own PCI DSS responsibilities or validation requirements.

What PCI DSS Requires

PCI DSS addresses protection of payment-card data. Outsourcing card collection and processing can reduce the scope of your payment environment, but merchants retain responsibility for the security of their payment setup and their service providers. Your applicable assessment and validation requirements depend on the integration and the requirements of your acquirer or payment provider.

PCI Security Standards Council →

How SchedulingKit Supports PCI DSS

Tokenized Payments via Stripe

In the Stripe booking checkout, card details are collected by Stripe Elements. SchedulingKit uses the resulting payment references to associate the payment with the booking. This reduces direct card-data handling while leaving applicable merchant PCI responsibilities in place.

No Card Data Storage

For Stripe booking checkout, raw card details are submitted from Stripe Elements to Stripe. SchedulingKit keeps payment and booking references. PayPal and Square use their own payment flows; they are separate providers.

Secure Checkout Experience

The Stripe booking flow renders a Stripe Payment Element in the booking page and confirms payment through Stripe.js. This reduces direct handling of card details; you must still assess and meet the PCI requirements applicable to your own payment setup.

Automatic Receipts & Invoicing

Booking and invoice records track payment status and payment-provider references. Clients can receive invoice messages and payment links. An ordinary invoice email is not an end-to-end encrypted receipt; use the provider payment flow rather than sending card details by email.

Refund Management

Authorized team members can request refunds for eligible transactions from the dashboard without re-entering card information. Stripe refunds use the original payment reference and are subject to the remaining refundable amount and provider processing status.

Payment Dispute Handling

Manage Stripe disputes in the Stripe dashboard. Use the relevant booking and payment records to assemble evidence, and submit it through the provider before its response deadline. The card issuer decides the dispute outcome.

Frequently Asked Questions

Set Up Your Appointment Payment Flow

Choose a payment provider and a plan with online payments, then confirm the PCI responsibilities and validation requirements that apply to your setup.

Free forever plan available • No credit card required