Security & payments

Protected payments, clearly explained

Online card details are entered with the connected payment provider. Basildon Delivery does not collect or store full card numbers or card security codes.

Compliance status last confirmed: July 2026.

PCI DSS compliant

Basildon Delivery has completed and attested its applicable PCI DSS Self-Assessment Questionnaire (SAQ A), passed the required external vulnerability scan, and had its compliance confirmed through Worldpay.

PCI DSS compliance is an ongoing responsibility. Assessments, scans, technical controls, and evidence are maintained and renewed as required.

Hosted card entry

Where a shop offers online card payment, customers complete card entry on a secure checkout hosted by the shop's connected provider, currently Worldpay or Mollie.

The provider processes the card payment and pays the shop. Basildon Delivery manages the order workflow and receives only the payment status and references needed to operate and support the order.

Practical website safeguards

  • HTTPS protects information sent between the browser and the website.
  • Secure session settings, CSRF protection, and login controls help protect accounts and actions.
  • Role-based access limits sensitive shop, rider, customer, and operational information.
  • Private configuration and protected-upload controls keep sensitive system material away from public pages.
  • External vulnerability scanning provides an independent technical check.

ICO registered data controller

Mr Mark Crosby, trading as Basildon Delivery, is registered with the Information Commissioner's Office as a data controller.

ICO registration reference: ZC157278.

ICO registration supports transparency and accountability for personal-data handling. It is separate from PCI DSS compliance and is not an ICO endorsement or security certification.

What shops remain responsible for

Each participating shop connects and operates its own supported payment-provider account. The shop remains responsible for its customer payments, refund decisions, account security, provider terms, and any security obligations that apply to its own systems and processes.

What our compliance wording means

We use “PCI DSS compliant”, not “PCI DSS certified”. PCI Security Standards Council recognises official assessment and attestation documents as evidence of validation; it does not issue a general compliance certificate or authorise a PCI DSS logo as a merchant compliance badge.

Learn more from PCI Security Standards Council and Worldpay SaferPayments.

Questions or security concerns

If you have a payment-security question, spot something unexpected, or need help with an order payment, please use our contact and support page. Do not include card details in your message.