The Critical Importance of Gratuity Security
Trust is the cornerstone of any financial platform. When guests scan a QR code at their table, they expect bank-grade data privacy and instant payment security.
Core Security Architecture in Naponi
1. Non-Custodial Architecture
Naponi does not hold customer funds in proprietary digital wallets or risk pool accounts. Gratuities route directly to the venue's or employee's registered bank account via secure payment networks.
2. PCI-DSS Level 1 Tokenization
Card details are tokenized instantly using SSL/TLS 256-bit encryption. Card numbers never touch plain-text application servers.
3. Biometric Device Authentication
With Apple Pay and Google Pay, transactions require FaceID or fingerprint verification on the guest's own device, virtually eliminating chargebacks.
4. QR Code Integrity & SSL
Every QR code routes exclusively through HTTPS encrypted domain endpoints with strict CORS and origin protection policies.
Frequently Asked Questions
Does Naponi hold customer credit card numbers on its servers?
No. All card details are processed through PCI-DSS Level 1 certified payment gateways (such as Stripe, PayTR, or Iyzico) using tokenization. Naponi never stores raw card credentials.
Can malicious actors swap table QR stickers with fraudulent codes?
Venues should use durable acrylic table stands or engraved materials and conduct routine visual floor checks. In addition, Naponi displays verified venue names and logos on the tipping screen for customer confirmation.