Payment and PCI Notice
Payment processor roles, card data, PCI responsibility, refunds, and chargebacks
| Term | Meaning |
|---|---|
| Legal Owner | ENTERACT LLC |
| Product | Prehoos |
| Effective date | June 28, 2026 |
1. Overview
This Payment and PCI Notice explains payment-related responsibilities for Prehoos. It should be read with the Terms of Service, Privacy Policy, Billing and Cancellation Policy, and any payment processor terms.
2. Prehoos role
Prehoos may provide payment-related workflows such as folio records, POS-related records, invoices, receipts, payment status, payment links, payment references, refunds, and reconciliation tools. Unless expressly stated in a signed agreement, Company is not a bank, card issuer, acquiring bank, payment processor, money transmitter, escrow provider, or financial institution.
3. Third-party payment processors
Payments may be processed by third-party payment processors selected by Company or Customer. Payment processors have their own terms, privacy policies, fees, settlement rules, supported countries, prohibited business rules, chargeback rules, KYC requirements, fraud controls, and technical limitations. Customer is responsible for reviewing and complying with those requirements.
4. Cardholder data
Customer must not enter raw payment card numbers, CVV/CVC codes, PINs, magnetic stripe data, chip data, or sensitive authentication data into Prehoos notes, guest profiles, support tickets, custom fields, chat messages, or any unapproved field. Where payment card processing is supported, Customer should use approved payment processor fields, hosted payment pages, tokenization, or other secure payment flows made available by the payment processor.
5. PCI responsibility
PCI DSS responsibilities depend on the payment architecture used by Customer, the payment processor, and Prehoos configuration. Customer is responsible for determining and meeting the PCI obligations that apply to its business, including staff training, device security, network security, payment terminal security, card data handling, incident response, and processor requirements.
Company may provide tools designed to reduce direct handling of card data, but Company does not guarantee that Customer use of Prehoos makes Customer PCI compliant. Customer should consult its payment processor, acquiring bank, QSA, or PCI adviser for compliance guidance.
6. Refunds, reversals, and chargebacks
Customer is responsible for refunds, reversals, cancellations, no-show fees, deposits, chargebacks, payment disputes, guest complaints, and settlement reconciliation related to Customer hospitality operations. Prehoos records may assist with reconciliation, but Customer must review payment processor records and bank records as the source of settlement truth.
7. Taxes and payment records
Prehoos may support tax, invoice, receipt, folio, and accounting-related workflows, but Customer remains responsible for tax configuration, tax reporting, legal invoice requirements, local hotel taxes, VAT/GST/sales tax, occupancy tax, withholding, and accounting treatment.
8. Fraud and unauthorized transactions
Customer is responsible for implementing operational controls to reduce fraud, including staff permissions, manager approvals, refund controls, cash controls, payment terminal controls, guest verification, and review of financial alerts and audit logs. Company is not responsible for losses caused by Customer staff, guest fraud, stolen credentials, social engineering, payment processor decisions, or Customer failure to use available controls.
9. Security incidents involving payments
Customer must promptly notify its payment processor, acquiring bank, and Company if it suspects unauthorized access to payment information, cardholder data, payment credentials, or payment systems. Customer should not send raw card data to Company support.
10. Contact
Payment-related questions may be sent to support@prehoos.com. Legal notices may be sent to legal@prehoos.com.
