Privacy, Security & Cookies


Privacy, Security & Cookies
Your Personal Information.
We don't sell or make your information available to anyone, ever, under any circumstances.
 
What are cookies?
A cookie is a small file which is placed on your computer's hard drive. Online shops like Foldabox are allowed to use 'strictly necessary' cookies without consent, otherwise online shops like ours would not work. For example, a cookie is used to track what you put in your Shopping Cart. If we did not use a cookie, your Shopping Cart would be empty when you reached Checkout.

If you have any technical queries or need any clarification, please contact us and we will be happy to answer any questions or provide additional information.

Security of your Financial Information
All transactions are processed through SagePay’s secure server. We do not keep or store any financial information in any format whatsoever, under any circumstances. Foldabox is PCI DSS Compliant. We have taken all the necessary steps to ensure that your credit card information is secure.

Our Payment Service Provider is SagePay, the largest independent payment service provider in the UK. SagePay provides a secure payment gateway (Level 1 PCI DSS), processing payments for over 24,000 online businesses, including ours. Thousands of businesses outsource their transaction security to SagePay, whose top priority is to ensure that transaction data is kept totally secure at all times.


Transaction security
All transaction information passed between our site and SagePay’s secure server is encrypted using 128-bit SSL certificates. No cardholder information is ever passed unencrypted and any messages sent to our servers from SagePay are signed using MD5 hashing to prevent tampering. You can be completely secure in the knowledge that nothing passed to SagePay servers can be examined, used or modified by any third parties attempting to gain access to sensitive information.

Encryption and Data Storage
Once on the SagePay systems, all sensitive data is secured using the same internationally recognised 256-bit encryption standards used by, among others, the US Government. The encryption keys are held on state-of-the-art, tamper-proof systems in the same family as those used to secure VeriSign's Global Root certificate, making them all but impossible to extract. The data held by SagePay is extremely secure and SagePay are regularly audited by the banks and banking authorities to ensure it remains so.

Links to banks
SagePay has multiple private links into the banking network that are completely separate from the internet, which do not cross any publicly accessible networks. Any cardholder information sent to the banks and any authorisation message coming back is secure and cannot be tampered with.

Employee access
No individuals within SagePay are able to decrypt transaction information or cardholder data. Their systems only allow access to their most senior staff and only in extenuating circumstances (such as investigations of Card Fraud by the Police). Your transaction information and customer card information is secure even from their own employees because their systems never display full card numbers, even on administration screens. For further information on SagePay's security, please click on this link: http://www.sagepay.co.uk/policies/security-policy