Security
Payment Security
A plain description of how your card details are handled when you buy from this site, what reaches our systems, and what never does.
Last updated 11 August 2026
Summary
- Every page on this site is served over HTTPS with modern TLS.
- Card details are entered on a payment page that meets the Payment Card Industry Data Security Standard.
- Your full card number never reaches our servers, our database, our logs or our staff.
- We keep only the card type and the last four digits, so we can match a payment to an order and to a refund.
- Refunds are always returned to the card that paid.
Encryption in transit
The site is served exclusively over HTTPS. Requests to the insecure port are redirected, HTTP Strict Transport Security is enabled, and the connection uses TLS 1.2 or 1.3 with forward secrecy. You can confirm this yourself: your browser will show a padlock and the certificate for jdapdarel.shop.
Every form on this site — checkout, contact, wardrobe consultation, the email list — is submitted over the same encrypted connection.
PCI DSS compliance
Any business that processes, transmits or stores cardholder data must comply with the Payment Card Industry Data Security Standard. Compliance is a shared responsibility between the merchant and the payment provider.
Our side of that is deliberately small, because the safest way to hold card data is not to hold it:
- The card form is hosted and served by our payment provider on their PCI DSS Level 1 certified infrastructure, not by us.
- Card details go from your browser to the provider directly. They do not pass through our application.
- We receive a token and a result. The token identifies the transaction; it cannot be reversed into a card number and it cannot be used to charge you again outside the original order.
- Our own systems are therefore out of scope for cardholder data storage entirely, which is the outcome the standard is trying to produce.
What we store, and what we never store
| Data | Do we hold it? | Why |
|---|---|---|
| Full card number | Never | It never reaches our systems |
| Security code (CVV/CVC) | Never | Nobody may store it after authorisation |
| Expiry date | Never | Not needed to fulfil or refund an order |
| Card type and last four digits | Yes | To match a payment to an order and to a refund |
| Billing name and address | Yes | Order records and tax requirements |
| Transaction token and amount | Yes | To issue refunds and reconcile accounts |
What we do hold is covered by our privacy policy, including how long we keep it and how to ask for a copy or a deletion.
Cards we accept
- Visa
- Mastercard
- American Express
- Discover
All charges are made in US Dollars (USD). If your card is denominated in another currency, your bank sets the exchange rate and may add its own fee. Neither is charged by us and neither is visible to us.
Fraud prevention
Card verification and address verification checks run on every transaction. Our forms are protected against automated abuse, and we monitor for card-testing patterns — repeated small authorisations across many card numbers — and block them.
Occasionally a legitimate order is held by these checks. If that happens we call or email you rather than cancelling silently, and we do not charge you while an order is held.
A charge you do not recognise
Charges from this site appear on your statement under a descriptor that includes Weekwear. If you see something you do not recognise, call us first at +1 818 835 3868 during Monday to Friday, 9:00–18:00 US Eastern Time or email support@jdapdarel.shop.
We can identify a charge from the amount, the date and the last four digits within minutes, and if it is not yours we refund it immediately and without argument. Calling us is faster than a chargeback, which typically takes weeks.
If your card has been used fraudulently anywhere, contact your card issuer as well — they can block the card and stop further use.
Reporting a security problem
If you believe you have found a vulnerability in this site, email support@jdapdarel.shop with the subject “Security” and enough detail to reproduce it. We will acknowledge within two business days and keep you updated until it is resolved.
Please do not test against live customer orders, do not run automated scanning that degrades the service for others, and do not access data that is not yours. Report it and we will fix it.