Preno is committed to helping you reduce the risk of sensitive guest card information being exposed. This article explains how card data is stored, how long it remains accessible, and what happens to card details entered into unsecured fields.
How cards are stored
Payment cards in Preno are securely stored and tokenised in your chosen payment gateway — Preno never holds the raw card number. Often, payment cards are used one-off. You can also choose to link a card to a guest profile in order to charge the card again for their returning stay.
How long cards remain accessible
To reduce your business risk and exposure in the event of a security breach, Preno automatically clears the stored card token based on the following criteria:
Unlinked cards:
Card can be accessible until 10 days after checkout date
Card can be accessible until 10 days after cancellation date
Cards linked to a guest profile:
Card can be accessible until the card expires
We recommend only linking a card to a guest profile if the card is intended to be re-used in the future.
Clearing card data means the token is no longer retained. The last four digits of the card number on the guest's profile remain for historical reporting purposes.
This applies to your account if you are using a payment gateway such as Stripe, or the Reveal Stored Cards feature in Preno.
Card details entered into notes
Booking notes and Guest notes are unsecured fields and are not a safe place to keep card details. Any credit card information stored in these fields is automatically scrubbed 30 days after checkout.
Scrubbed card information will appear as <Redacted>.
If you need to keep a card on file, store it securely against the booking through your payment gateway rather than in a note.
