Payment Security and Site Security
How we protect your payment details and personal data, and what you can do to keep your account and your business safe.
Security matters more when the order is a commercial machine and the buyer is a business. This page explains, in plain terms, how payments and data are protected on coffeemachinehq.com, what we do and do not hold, and how to tell a genuine message from us apart from a fraudulent one. It complements our Privacy Policy, which sets out the legal detail of how we handle personal data.
Encryption in transit
Every page on this website is served over HTTPS, secured with TLS. That includes ordinary browsing pages, not just the checkout — so the pages you view, the searches you run, the details you type into forms and the credentials you use to sign in are all encrypted between your browser and our server.
You can confirm this yourself. Your browser will show a padlock or a similar indicator in the address bar, and the address will begin with https:// and the domain coffeemachinehq.com. Click the padlock to inspect the certificate. If you ever see a certificate warning, an address that is not coffeemachinehq.com, or a checkout page served without HTTPS, stop and do not enter any details — then tell us.
We keep the server software, the WordPress and WooCommerce platform, and the plugins and themes we rely on up to date, and we apply security patches promptly. Administrative access to the site is restricted to the people who need it and protected by strong authentication.
Card details are handled by our payment provider
We do not see, process or store your full card details. When you reach the payment step, your card data is passed directly to our payment provider through their secure hosted fields or hosted payment page. The card number, expiry date and security code go from your browser to the provider — they do not land in our shop database, and they are not written to our server logs.
What we receive back from the provider is a result: whether the payment was authorised, an identifier for the transaction, and limited information such as the last four digits and the card type so that our team can match a payment to an order and process a refund. That is enough to run the shop and nowhere near enough to make a payment.
Where a payment method supports saving a card for future use, what is stored is a token held by the payment provider, not the card number itself. A token is meaningless outside our account with that provider.
PCI DSS compliance
The Payment Card Industry Data Security Standard (PCI DSS) is the security standard that applies to organisations handling card data. Card data on this site is processed by our payment provider, and it is the provider that carries the PCI DSS compliance obligation for the storage, processing and transmission of that data. They are assessed against the standard by the card schemes and their assessors.
Our own responsibility is to keep it that way: to integrate with the provider in a manner that keeps card data out of our environment, to secure the website that hosts the checkout, and to control who has access to our systems. Payments are also subject to Strong Customer Authentication under UK payment services rules, which is why your bank may ask you to approve a payment in its app or by a one-time code. That step happens between you and your bank; we neither see nor store the code.
Your account and password
If you create an account with us, you are responsible for keeping your login details confidential and for activity carried out under your account. A few practical points make a real difference, particularly for business accounts where several people may be involved in ordering.
- Use a long, unique password for this site and never reuse a password from another service — reused passwords are the single most common cause of account takeover.
- A password manager is the easiest way to keep long, unique passwords without having to remember them.
- Do not share account logins between colleagues. If several people need to order, ask us about setting up separate access.
- Change your password immediately if you suspect it has been exposed, and if a member of staff with access leaves your business.
- Sign out when using a shared or public computer, and avoid entering payment details over untrusted public Wi-Fi.
- Keep your own devices patched and protected — we cannot secure your session if the device it runs on is compromised.
We store account passwords as salted cryptographic hashes, never as readable text. That means nobody at Coffee Machine HQ can look up your password — if you lose it, we can only help you reset it. Password reset links are sent to the registered email address and expire after a limited period.
How we protect your personal data
Beyond payments, we hold order and account information: names, contact details, delivery and installation addresses, site access notes, order history and correspondence. We treat that as data to be protected, not data to be spread around.
- Access to order and customer data is limited to staff who need it to fulfil orders, provide support or manage accounts.
- Administrative accounts use individual credentials and multi-factor authentication where available.
- Data is held on infrastructure with physical and network security controls, and backups are taken and protected.
- We collect only what we need for the order and keep it no longer than we need it or than the law requires — retention periods are set out in our Privacy Policy.
- Suppliers who process data on our behalf, such as our hosting and payment providers, are bound by written agreements requiring appropriate security measures.
- We do not sell your personal data.
No system can be guaranteed impenetrable. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office in line with the UK GDPR and, where the risk is high, tell you directly.
Recognising phishing and fraud
Criminals impersonate suppliers, especially where invoices are involved. Business customers are targeted with fake invoices and bank-detail change requests — often well written and well timed. It is worth knowing what we will never do.
- We will never email, call or message you to ask for your full card number, security code, PIN, or your password.
- We will never ask you to approve a payment or move money to keep an account safe.
- We will never send an unexpected message telling you our bank details have changed. If you receive one, treat it as fraudulent until you have verified it by calling us on 01706 216822 using the number on this website — not the number in the message.
- We will not pressure you to act immediately, threaten to cancel an order within minutes, or demand payment by gift card, cryptocurrency or an unusual method.
- Genuine links from us go to coffeemachinehq.com. Check the full address carefully — lookalike domains use extra words, hyphens or different endings.
If a message looks wrong, do not click the links or open the attachments. Go to coffeemachinehq.com directly in your browser and sign in to your account, or contact us using the details published on this site. Suspected phishing can also be forwarded to the National Cyber Security Centre’s Suspicious Email Reporting Service, and fraud can be reported to Action Fraud. If you think a card has been compromised, contact your bank first — they can block the card straight away.
Reporting a security concern
If you believe your account has been accessed without permission, you have received a message impersonating us, or you have found a vulnerability in this website, tell us at sales@coffeemachinehq.com or 01706 216822. Please include what you saw, when, and any headers, screenshots or steps needed to reproduce the issue.
We welcome good-faith reports from security researchers. Please give us a reasonable opportunity to investigate and fix an issue before disclosing it publicly, and do not access, alter or delete other people’s data, degrade the service, or run destructive testing while investigating. We will acknowledge your report and keep you informed of the outcome. Written reports can be sent to Unit 8-12 Bentwood Road, Carrs Industrial Estate, Haslingden, Rossendale, BB4 5HH.
Seen something suspicious?
Report a suspected phishing message, an unexpected change of bank details, or a possible account compromise. We would much rather check something harmless than miss something real.
