PCI and Payment Security Overview
InnSyst Effective Date: March 2026
Ensuring the financial security of our customers and their guests is a core priority for our company. This statement applies to the InnSyst platform (hotel.presidiumservices.com) and related services, including any white-label or partner domains powered by the InnSyst platform. All white-label domains operate on the same underlying technology and are subject to the same payment security practices described herein. For a current list of white-label domains covered by this statement, please contact us at [email protected]. Our platform is designed so that cardholder data is handled by secure, PCI-compliant payment providers, not by our own application servers.
Credit Card Data
We do not store full credit card numbers, CVV/CVC, PIN data, or magnetic-stripe / EMV data on our servers.
Card data entered through our platform is encrypted in transit and sent directly to a secure, token-based payment vault or gateway operated by a PCI-certified provider.
Our systems may retain only non-sensitive card references, such as card brand, and limited PAN elements (for example, first 6 digits and/or last 4 digits) together with processor tokens, for identification, reconciliation, and customer service purposes.
We never store sensitive authentication data (including CVV/CVC codes or PINs) after authorization.
Because full PAN and sensitive authentication data are never stored on our application servers, it is not possible for a complete credit card number to be obtained from our database.
How Payment Processing Works
Guests initiate payments through our hotel management platform interface (web or integrated UI).
The payment information is submitted over HTTPS (TLS 1.2+), and card data is handled by the connected PCI-compliant payment service provider using encryption and tokenization.
Our platform receives a token or transaction reference from the provider and stores only that reference plus limited, non-sensitive card details (for example, card type and last 4 digits) for future identification of the transaction.
Where supported, properties can choose whether to store tokenized card details for later use (such as no-show charges or incidentals), or to process a one-time payment without storing any card reference.
Access to Stored Payment Details
Access to payment-related information (tokens and limited PAN elements) in our platform is restricted to authorized property users with appropriate permissions.
We strongly recommend that properties:
Give viewing or charging permissions only to staff who require it to perform their job
Avoid sharing accounts and ensure every user has a unique login and role
Properties can configure user roles and permissions inside the platform to control who can view payment information and initiate charges through integrated gateways.
Encryption and Infrastructure
All guest and payment-related data transmitted through our platform uses TLS/SSL encryption in transit.
Application and database infrastructure are hosted on a leading cloud provider with industry-standard security controls for compute, network, and storage.
Non-sensitive stored data (such as tokens and limited card digits) is protected using encryption at rest and strong access controls.
PCI DSS and Responsibilities
Our payment integrations are designed so that certified payment processors and tokenization providers handle cardholder data in their PCI DSS-compliant environments.
Hotels using our platform remain responsible for:
Maintaining their own PCI DSS compliance for any cardholder data they handle directly (for example, on payment terminals or other systems)
Configuring user access and roles appropriately within our platform
Securing their networks and devices that connect to our platform
We support our customers' compliance efforts by providing secure integrations, limited storage of non-sensitive card elements, and clear controls over access to payment-related data, similar to other leading hospitality platforms.
Contact Information
For questions regarding PCI compliance and payment security, please contact:
InnSyst (Presidium Services LLC) Email: [email protected] Phone: (520) 815-7571
Document prepared: March 2026 Last updated: March 17, 2026