Skip to main content
SunnyDays

Booking & payment · Security

Is my card safe? What do you store?

Card details are entered into fields hosted by the payment processor, embedded in our page as an iframe. The card number never touches a Sunny Days server — it goes from your browser straight to the processor, which returns us an opaque token. This is the Stripe Payment Element pattern and it puts us in PCI DSS SAQ-A, the lightest scope available to a merchant.

We store: the payment token, card brand, last four digits, expiry month/year, the billing postcode/country, and the processor's charge and refund IDs.
We never store: the full card number (PAN), the CVC — ever, by anyone, including the processor after authorisation — or the magnetic-stripe/chip data.

Apple Pay and Google Pay pass a device-specific token rather than your real card number, so they are, if anything, the safer option. They're also the fastest way through checkout on a phone, which is where most of these trips get booked.

More on booking & payment

All 21 help articles

Still stuck? Talk to a person

Email help@sunnydays.thedigitalcarpenter.com — replies within one business day, most inside four hours.

Travelling in the next 48 hours, or travelling now: the urgent line +1 (555) 018-7742 is staffed 24/7 and answered in under three minutes, or we call you back.

Full contact detail, including postal address, is on the contact page. Please never send card numbers by email — we will never ask for one, and we do not need it to find your booking.

Help centre last reviewed 3 August 2026. Our terms of service and privacy policy are the governing documents; where this page summarises them, they win.