Privacy Policy

Security with guarantee:
The security of your personal data and the protection of your privacy are our top priority. We have taken all the precautions so that you can feel completely safe when visiting our Blitheluna homepage and also use the latest SSL encryption for payment processing.

Security at Stripe
Find out how Stripe manages security.

Stripe was audited by an auditor with PCI certification. At the end of this audit, we obtained Level 1 PCI service provider certification, the highest level of certification in the payments industry. In order to ensure this high level of security at Stripe, we have adopted the best security tools, as well as the most effective practices in this area.
HTTPS and HSTS for secure connections
Stripe requires the HTTPS protocol for all services using TLS (SSL), including our public website and the Dashboard to ensure secure connections:
• Stripe.js is only accessible via the TLS protocol.
• Stripe’s official libraries connect to Stripe’s servers via the TLS protocol and check TLS certificates on each connection.
We regularly check the details of our deployment, including the certificates we process, the certification authorities we use and the encryptions we support. We use HSTS to ensure that browsers interact with Stripe exclusively via HTTPS. Stripe is also included in the preloaded HSTS lists of Google Chrome and Mozilla Firefox.

Encrypting of data and sensitive communications
All credit card numbers are encrypted AES-256 of data at rest. Decryption keys are saved on separate machines. None of Stripe’s internal servers and daemons can obtain the credit card numbers in clear text, but they can issue a request for the cards to be sent to a service provider on a static whitelist. Stripe’s infrastructure for storing, decrypting and transmitting credit card numbers operates in a separate hosting environment and does not share credentials with Stripe’s main services, including our API and website.

Vulnerability reporting and rewards program
By submitting a security bug or vulnerability to Stripe via HackerOne, you acknowledge that you have read and accepted the program’s terms of use. Please refer to our HackerOne policy for more information on how to participate in our bug bonus program.