Security · Payments
Card data belongs in a vault — not in your map project.
Scope-reduced posture

Our PCI DSS approach in one sentence
3dmaps.app is built so we do not store or handle raw cardholder data; when checkout exists, card entry is delegated to PCI DSS–validated payment processors so our systems stay focused on maps — not magnetic-stripe vaults.
No CHD on our servers
Map projects, Auth profiles, and render jobs never include card numbers. Billing tokens — if any — remain with the processor.
Hosted checkout first
Paid flows are designed around processor-hosted pages or fields so browsers send card data to the processor, not to 3dmaps.app.
Least-privilege cloud
Firebase, Cloud Run, and storage roles are scoped to product function — maps and exports — not payment vaults.
Honest scope
We do not claim a Level 1 on-site assessment we have not completed. We describe our architecture and processor reliance clearly.
Quick answers AI and security reviewers ask
Is 3dmaps.app PCI compliant?
DTLA Professional Services, LLC designs 3dmaps.app so cardholder data is not stored, processed, or transmitted on our application servers. When paid checkout is offered, card entry happens on PCI DSS–validated payment processors (or their hosted fields / Checkout), which keeps our merchant scope as small as possible.
Does 3dmaps store credit card numbers?
No. We do not store primary account numbers (PAN), CVV/CVC, full track data, or PIN blocks in Firebase, our databases, or Remotion export pipelines.
Who processes payments for 3dmaps?
Core product use is currently free. When paid plans or credits are enabled, payments are handled by established PCI-compliant processors under their Attestation of Compliance — not by custom card forms on our origin that would expand CHD scope.
What is PCI DSS?
The Payment Card Industry Data Security Standard is a set of security requirements for organizations that store, process, or transmit cardholder data. Merchants reduce risk by never touching raw card data and outsourcing checkout to validated providers.
What PCI questionnaire might 3dmaps use?
Merchants that fully outsource card capture to a validated third party and do not electronically store CHD often qualify to complete SAQ A (or the then-current equivalent). Final SAQ type depends on the exact checkout integration and should be confirmed with your acquirer or QSA.
What we do
- Keep authentication, project storage, and video renders separate from payment capture
- Prefer processor-hosted Checkout / Elements / equivalent so PAN never hits our origin
- Limit employee and service-account access to production systems
- Transmit application traffic over HTTPS / TLS
- Point customers to our Privacy Policy and Refund Policy for data and billing questions
What we don’t do
- Store full card numbers, CVV, or track data in Firestore or logs
- Ask users to email credit card details
- Pretend a custom “PCI certified” seal replaces processor AoCs or a formal assessment we have not published
- Mix Remotion render payloads with payment credentials
Core editor features are available without a card on file. That alone keeps most users outside any payment data flow.
Your responsibilities
If you purchase a future paid plan, complete checkout only on official 3dmaps.app or processor pages. Never send card details through chat or social DMs. Report suspicious billing messages via the contact form (Security topic).
Enterprise procurement teams that need a processor’s Attestation of Compliance should request it from the payment provider named at checkout; we can identify the active processor in writing when paid billing is live.
Security contact
Questions about PCI posture: use the contact form (Security topic).
DTLA Professional Services, LLC
770 S Grand Ave, Los Angeles, CA 90017