Skip to content

Secure Payments

Secure Payments — Starck Gallery

Starck Gallery · Alicante, Spain

Your paymentsat
are fully secure

Every order placed on Starck Gallery is processed through a secure Shopify platform, certified to the highest international standards. Your peace of mind is part of the experience.

PCI DSS Level 1 SSL / TLS 256-bit 3D Secure / SCA GDPR Compliant SOC 2 Type II

The standards that protect
every transaction

Shopify is a payment platform certified by the world’s most rigorous security organizations. These certifications are verified annually by independent auditors.

Payment Certification

PCI DSS Level 1

The highest certification for card payment processing. Shopify holds this certification and renews it annually through an independent external audit. No credit card data is transmitted through or stored on our servers.

Level 1 = more than 6 million transactions audited annually.
Data encryption

256-bit SSL/TLS

Every page is protected by an SSL certificate with 256-bit TLS encryption—the same level used by banks. The padlock 🔒 https:// is proof of this. Shopify automatically manages and renews these certificates. Your data is unreadable to third parties, even on public Wi-Fi.

TLS 1.3 Protocol: Your information cannot be intercepted while in transit.
Independent Audit

SOC 2 Type II

Independent auditors certify that Shopify meets strict standards for security, availability, and privacy—over a continuous period of several months, not just at a single point in time. The SOC 3 report (public version) is available to everyone.

Report produced by an external accredited organization — Shopify has no influence over it.
European Directive

3D Secure & PSD2

The PSD2 directive requires strong customer authentication (SCA) for all online purchases in Europe. Shopify natively supports the 3D Secure 2 protocol: Visa Secure, Mastercard Identity Check, and Amex SafeKey. Your bank verifies your identity via text message, push notification, or fingerprint.

If a 3DS transaction is fraudulent, the bank is liable—not you.
Data Protection

GDPR Compliant

Shopify is fully compliant with the GDPR. As a merchant based in Spain, Starck Gallery complies with all requirements: data minimization, the right of access, the right to be forgotten, and full transparency regarding data processing.

Your data is never sold to third parties. It is used solely for the purpose of processing your order.
Encryption at rest

AES-256

Shopify protects stored data using the AES-256 standard, which is used by governments and militaries around the world. The data remains unreadable even if someone gains physical access to the servers. A dual-key system (symmetric + asymmetric) is used.

Your data would remain unreadable even in the event of a physical breach of the servers.

What happens
when it's time to pay

From the moment you click "Order" to the confirmation, here's exactly how Shopify protects every step of the way—automatically and seamlessly.

1

Secure connection

Opening an encrypted tunnel

As soon as you access the checkout page, your browser and Shopify’s servers establish an encrypted connection using the TLS 1.3 protocol. All data exchanged is encrypted with a 256-bit key—without this key, it is just a random string of unreadable characters.

HTTPS requiredTLS 1.3256-bit
2

Bank Data Isolation

We never receive your bank details

When you enter your card number, this information is sent directly to Shopify’s PCI DSS-certified servers—it never passes through our own systems. Starck Gallery never sees your full card number; we only see the last 4 digits for reference purposes.

TokenizationPCI IsolationZero Merchant Access
3

Risk Analysis

Real-time fraud detection

Shopify analyzes every transaction using fraud detection algorithms. Dozens of indicators are checked in milliseconds: address-country consistency, browsing behavior, IP history, and CVV matching. Suspicious transactions are flagged or blocked before they even reach your bank.

Anti-fraud AICVV verificationIP analysisRisk score
4

Strong authentication — Europe

3D Secure: Your bank verifies your identity

For shoppers in the European Union, the PSD2 directive requires two-factor authentication. Your bank sends you a one-time code (via SMS, push notification, fingerprint, or facial recognition) that only you can verify. Also known as: Visa Secure, Mastercard Identity Check, or Amex SafeKey.

Visa SecureMastercard Identity CheckAmex SafeKeyPSD2 / SCA
5

Secure confirmation

Payment processed & order confirmed

Once your bank has authorized the transaction, Shopify sends us a simple payment confirmation that does not include any banking information. You will receive a confirmation email. We will begin preparing your artwork immediately.

Confirmation emailNo banking information stored

Pay in your own language—
, just like you’re used to

Starck Gallery accepts all of the payment methods listed below, which are secured by the Shopify Payments infrastructure. Click on your country to see the available options.

🇫🇷France

Shopify Payments available — all of these payment methods are accepted at checkout

🇧🇪Belgium

Shopify Payments available — Bancontact natively integrated

🇳🇱Netherlands

Shopify Payments available — iDEAL natively integrated (accounts for 70% of online payments)

🇪🇸Spain

Shopify Payments available — Klarna available for Spanish customers

🇩🇪Germany

Shopify Payments available — Giropay and Klarna natively integrated

🇬🇧United Kingdom

Shopify Payments is available — Klarna is very popular in the UK

🇨🇭Switzerland

Shopify Payments is now available — TWINT, Switzerland’s leading digital wallet, is natively integrated

🇱🇺Luxembourg

Shopify Payments available — all international cards and digital wallets accepted

🇨🇦Canada

Shopify Payments available (Shopify's own payment solution) — Interac natively integrated

🇺🇸United States

Shopify Payments available — Shop Pay Installments (4 interest-free payments) included

At
, safety isn't justan option—it's our standard

0

Stored data

We never store your banking information. It doesn't even pass through our servers.

256

Encryption bits

The same level as global banks. Every connection, every transaction, without exception.

1

PCI DSS Compliance Level

The highest certification for payment processing. Renewed annually through an independent audit.

2FA

Authentication

In Europe, your bank verifies your identity using 3D Secure. Only you can authorize the payment.

Back to top