Your Security Is Our Priority
RiseUp Payments provides software, payment integration, merchant dashboard, onboarding, and support services. We use practical security practices designed to protect platform access, payment status data, merchant configuration, and integration workflows.
Our security approach focuses on access control, secure configuration, encrypted transport, limited data handling, monitoring, incident response, and trusted third-party payment providers.
Platform Role Clarification
RiseUp Payments is a software integration layer and merchant dashboard. We help businesses connect payment events to checkout records, customer activity, reporting, and GoHighLevel workflows.
RiseUp Payments Provides
- Payment integration software
- Merchant dashboard access
- Transaction status tracking
- GoHighLevel payment status sync
- Onboarding and technical support
RiseUp Payments Does Not Provide
- Banking services
- Lending services
- Remittance services
- E-wallet or stored-value accounts
- Custody or holding of customer funds
Security Program
Our security practices cover people, process, technology, and third-party dependencies. We aim to keep the platform reliable without overstating certifications or controls that are not currently claimed.
Risk-Based Controls
We apply practical controls for authentication, access permissions, platform configuration, and integration workflows based on operational risk.
Monitoring
We use logging and review practices to help detect errors, suspicious activity, webhook issues, failed sync attempts, and integration problems.
Incident Response
Potential security or platform issues are reviewed, prioritized, investigated, and addressed based on severity and customer impact.
Secure Development
Changes to payment-related functionality are reviewed carefully because checkout, payment webhooks, and GHL sync are treated as critical infrastructure.
Key Controls
Encryption in Transit
Platform pages, dashboard access, webhooks, and API communication are served over HTTPS/TLS where applicable.
Access Control
Merchant dashboard and admin access are restricted by authentication, role separation, and least-privilege practices where supported.
Infrastructure
RiseUp Payments is hosted on managed cloud infrastructure with production access limited to authorized personnel.
Backups & Recovery
We maintain backup and recovery practices for important platform data and operational continuity.
Vulnerability Management
We review framework, dependency, server, and application updates and prioritize fixes that affect security or payment reliability.
Secrets Management
API keys, webhook secrets, OAuth tokens, and integration credentials are handled as sensitive configuration values with restricted access.
Payment Provider Security
Payment processing is handled by approved third-party payment providers such as Xendit and supported payment partners. These providers are responsible for securely handling sensitive payment authentication, cardholder data, payment channel authorization, and payment network requirements.
- RiseUp Payments does not store full card numbers.
- RiseUp Payments does not store CVV or card security codes.
- RiseUp Payments does not store bank login credentials or wallet passwords.
- Payment status and transaction references may be stored for reporting, reconciliation, workflow sync, and support.
- Available payment channels depend on payment provider approval, merchant verification, and channel availability.
GoHighLevel Integration Security
RiseUp Payments connects with GoHighLevel to support payment status updates, transaction synchronization, workflow triggers, and customer-related business processes.
- Access is based on merchant authorization and integration setup.
- OAuth tokens and integration credentials are treated as sensitive configuration.
- Only the data needed to support payment status sync and related business workflows is processed.
- Merchants remain responsible for configuring their workflows, customer notices, consent settings, and GoHighLevel access permissions.
- Integration availability may depend on GoHighLevel APIs, provider uptime, account permissions, and third-party platform changes.
Best Practices We Follow
Data Minimization
We aim to process only the data needed to provide the service, troubleshoot issues, maintain records, and support payment workflows.
Vendor Due Diligence
We rely on reputable third-party providers for payment processing, hosting, business automation, and infrastructure services.
Change Management
Payment logic, webhook handling, checkout flow, and GHL sync changes should be reviewed and tested before production deployment.
Separation of Duties
Production access and sensitive platform changes are limited to authorized personnel and handled with caution.
Compliance & Regional Alignment
Philippine Data Privacy Act
Our privacy and security practices are designed to support responsible data handling aligned with the Data Privacy Act of 2012 where applicable.
Card Payments & PCI Scope
Cardholder data is handled by approved payment providers. RiseUp Payments does not store full card PANs, CVV, or card authentication credentials.
Data Locations
Cloud providers, payment providers, and connected software platforms may process data in or outside the Philippines based on their infrastructure.
Policies & Transparency
Our Terms of Service, Privacy Policy, and Security page are intended to clarify platform roles, merchant responsibilities, payment processing relationships, and data handling practices.
Report a Security Issue
If you discover a vulnerability, suspicious activity, unauthorized access, or potential security issue related to RiseUp Payments, please contact us promptly so we can review and address it.
How to Contact Us
Email [email protected] with a clear description, affected page or endpoint, reproduction steps, screenshots if available, and your contact details.
What We Do
We review reports, assess severity, investigate the issue, and prioritize fixes based on risk, impact, and operational urgency.
Security FAQ
Do you store full card numbers?
No. Full card numbers, CVV, and card authentication data are handled by approved payment providers such as Xendit.
Do you hold customer funds?
No. RiseUp Payments does not hold, receive, store, or custody customer funds. Payment processing is handled by third-party providers.
Who processes payments?
Payments are processed by approved third-party payment providers such as Xendit and other supported payment partners where applicable.
What data do you store?
We may store merchant configuration, customer contact details, transaction references, payment status, timestamps, and integration logs needed for the service.
What happens during provider downtime?
Payment availability, checkout redirects, webhooks, and status sync may be delayed or unavailable until the affected third-party provider restores service.
How do I report a security issue?
Send details to [email protected] with the subject “Security Issue Report” so we can review it quickly.