Booking & payment · Security
Is my card safe? What do you store?
Card details are entered into fields hosted by the payment processor, embedded in our page as an iframe. The card number never touches a Sunny Days server — it goes from your browser straight to the processor, which returns us an opaque token. This is the Stripe Payment Element pattern and it puts us in PCI DSS SAQ-A, the lightest scope available to a merchant.
We store: the payment token, card brand, last four digits, expiry month/year, the billing postcode/country, and the processor's charge and refund IDs.
We never store: the full card number (PAN), the CVC — ever, by anyone, including the processor after authorisation — or the magnetic-stripe/chip data.
Apple Pay and Google Pay pass a device-specific token rather than your real card number, so they are, if anything, the safer option. They're also the fastest way through checkout on a phone, which is where most of these trips get booked.
More on booking & payment
Still stuck? Talk to a person
Email help@sunnydays.thedigitalcarpenter.com — replies within one business day, most inside four hours.
Travelling in the next 48 hours, or travelling now: the urgent line +1 (555) 018-7742 is staffed 24/7 and answered in under three minutes, or we call you back.
Full contact detail, including postal address, is on the contact page. Please never send card numbers by email — we will never ask for one, and we do not need it to find your booking.