Payment Security
Last updated: June 2026
This page explains how Vunolin handles payments and what we do to keep your money and card information safe. Different rules apply depending on whether you bought through our website, the App Store, or Google Play.
Where your card data lives
Vunolin never stores your full card number or CVV on our servers. Every payment is routed to one of three regulated providers who hold the card data on PCI DSS compliant infrastructure: Paddle, our Merchant of Record, for web purchases, Apple for App Store in-app purchases, and Google for Google Play in-app purchases. We only receive a confirmation token and the parts of the transaction we need to manage your subscription.
Web payments through Paddle
When you pay through our website, your card details are entered into a form served by Paddle and sent directly to Paddle, our Merchant of Record. They never touch our servers. Paddle is a PCI-DSS-compliant payment provider that tokenizes your card, so we never store full card numbers or CVV, and it remits global tax and VAT on each sale.
Web transactions also go through 3D Secure 2, which adds a quick verification step (a code, a fingerprint, or an in-app confirmation from your bank) before high-risk payments are approved. This reduces fraud and protects you if your card details ever leak elsewhere.
If you choose to save a card for faster checkout next time, Paddle stores a token, not the full card number. You can remove the saved card from your account page at any time.
App Store in-app purchases
If you subscribe inside the iOS app, the entire transaction is handled by Apple using your Apple ID payment method. Apple shows you the price, takes payment, and sends us only a receipt that confirms you have an active subscription. We never see your card number, billing address, or CVV. Apple's payment security practices apply on top of ours.
Google Play in-app purchases
Android subscriptions follow the same model as App Store. Google Play handles the payment using the method you registered with Google Pay or your Google account, sends us a verified receipt, and we activate your plan. Card details, addresses, and security codes stay with Google.
Managing your subscription and auto-renewal
Paid subscriptions renew automatically until you cancel. You can see the next renewal date and price on your account page in the dashboard at any time. We do not silently change prices; if a price ever moves, we notify you before the next charge so you can decide whether to continue.
You cancel from the same place you bought: Vunolin's account page for web subscriptions, Apple ID Settings for App Store, and Play Store > Subscriptions for Google Play. Cancellation stops the next renewal; access continues to the end of the paid period.
Encryption in transit and at rest
All traffic between your device and our servers is encrypted with TLS 1.2 or higher. Payment-related fields that we do keep (the billing email, the plan you bought, the transaction reference) are stored with at-rest encryption. Application logs are scrubbed for sensitive values before storage.
Fraud and abuse monitoring
Paddle screens every web transaction in real time and blocks payments that look like card testing, stolen-card use, or other typical fraud patterns, and it supports 3D Secure and SCA for an extra layer of verification. For unusual sign-up bursts or impossible-travel logins, we also rate-limit and may ask for additional verification. If a transaction is flagged in error and you are the real card holder, email us with the transaction reference and we will resolve it quickly.
Reporting a payment issue
If you see a charge you do not recognise, a duplicate billing, or anything that looks wrong, reach us through our contact page. We refund without question when we can confirm the issue. For details, see our refund policy.