On almost every site that sells anything, the last step is a page with a card form on it. Number, expiry, security code, a button. It is so universal that its absence reads as a site that is not finished.

There is no such page here, and it is not an oversight. It is the result of asking a straightforward question — what is the safest way for a small operation to handle a card number — and accepting the answer, which is that it should never handle one at all. This is the reasoning, the mechanics, and the part where the arrangement is worse for you rather than better.

What a checkout page actually is

Strip away the design and a checkout is a data collection point that receives the most valuable string a customer possesses, on a page controlled by the seller, in a browser controlled by nobody in particular.

Done properly, the number never really touches the seller's servers — the field belongs to the payment company, embedded in the page, and the seller receives a token afterwards. Done properly, that is a good design and there is nothing wrong with it.

The catch is the phrase "done properly". A checkout is only as safe as every script running on the page beside it: the analytics tag, the chat widget, the review plugin, the countdown timer someone installed two years ago. A single compromised third-party script on a payment page can read a card number as it is typed, before any encryption is involved, and the page will look and behave completely normally while it happens. That class of attack is the reason checkout pages are audited as heavily as they are.

A form that does not exist cannot be skimmed, cannot be breached, and cannot be quietly modified by a script that was added for something else entirely. That is not a clever security measure. It is the absence of a target.

Large retailers can carry the cost of doing checkout properly — dedicated staff, formal compliance programmes, penetration testing, someone whose entire job is watching what loads on that one page.

A small operation cannot, and the honest position is to say so. The pattern that repeats across breach reports is not a sophisticated attack on a bank; it is a small merchant with an out-of-date plugin, an unattended payment page and no monitoring, quietly leaking card numbers for months before anyone notices.

Given that, the choice is between building a payment page we would have to defend indefinitely and not building one. We did not build one. The card details are entered on the payment company's own page, on their domain, under their compliance regime, and the only thing that comes back to us is a confirmation that money arrived and which order it belongs to.

The result is that the sentence "we do not store card details" is not a promise you have to trust. There is no path by which a card number could reach us in the first place. The same logic drives the decision not to keep a card on file for renewals, set out in why we do not keep your card on file.

How ordering works here instead

The whole sequence, with nothing left out:

  • You pick a plan and open the order window. It asks four things: a first name, a number to reply on, the device it will run on, and which payment route suits you. No address, no account, no password.
  • That summary reaches the desk. It contains your plan, your device and your preferred route. It does not contain a single payment detail, because none was asked for.
  • A quote comes back in writing. The exact figure, the currency, the term it covers and how to pay it. You can read it, question it or ignore it, and at this point you have paid nothing and given away nothing of value.
  • You pay on the payment company's page. Card, Apple Pay, Google Pay, PayPal or cryptocurrency, at the figure you were quoted. What each route does and does not give you back is compared on the payment methods page.
  • The login follows the cleared payment. Sent to the same thread the order was placed in, along with setup steps matched to the device you named. The timeline for that stretch is described in what happens in the ten minutes after you pay.

Four questions, one written quote, one payment, one delivery. That is the entire process, and the reason the device question is in there rather than asked afterwards is that the setup instructions differ by hardware and sending the right ones with the login removes a round trip.

What the arrangement gains you

Step A conventional checkout Here
Asking a question first Not possible — the form does not answer Normal — you are already in a conversation
The price you pay Assembled at the last screen, with additions Quoted in writing before anything moves
Card details Typed on the seller's page Typed on the payment company's page
Stored permission to charge again Usually requested, often pre-ticked None exists
Record of what was agreed An automated email The thread itself, with both sides in it
Backing out After details are entered Before anything is entered at all

The row that matters most is the second one. On a checkout, the final figure assembles itself across several screens and you meet it at the end, next to the button. Here the figure is a sentence sent to you before any decision, and the same figures are published on the pricing page where you can check the quote against them without asking anyone.

What it costs you — honestly

Three real losses, and pretending otherwise would undercut the whole point of writing this.

Speed. A checkout takes ninety seconds at any hour. Here you send an order and wait for a person, and if that person is asleep you wait until they are not. Usually minutes, occasionally longer.

Anonymity. A card form involves no conversation with anybody. Here you give a first name and a contact number, and some people would rather not. It is the minimum needed to send you a login and nothing beyond it, but it is more than a checkout asks.

Familiarity. The pattern is unusual, and unusual is a reasonable thing to be cautious about when money is involved. Being cautious about an unfamiliar payment process is exactly the right instinct — the checklist for applying it is in what a legitimate payment request looks like, and it is fair to hold this site to it.

Checking a payment link is genuine

Because payment happens on a link rather than a form on this site, verifying the link is a step you should take every time — with us and with anyone else. Three checks, in order.

The domain. It must be the payment company's own, not a lookalike carrying extra words. Read the part immediately before the first single slash and ignore everything after it, because that is the only portion that identifies who owns the page.

The connection. HTTPS, with no browser warning. A payment page that trips a certificate warning is finished as far as you are concerned, whatever the explanation offered.

The amount. It must equal the figure quoted in the same conversation, to the cent, in the same currency. A link for a different number is not a rounding difference to be waved through — it is the point at which you stop and ask.

One more, which is really about the channel rather than the link: a genuine payment link continues an exchange you started. A link that arrives unprompted, from a number you did not message, referring to an order you did not place, is somebody else's work regardless of whose name is on it. That pattern and its relatives are covered on our page on paying safely.

The things that cannot happen without a funnel

A checkout is a designed sequence, and sequences get optimised. Some of that optimisation is benign and some of it is the reason people distrust the last screen of a purchase.

Without one, a set of familiar irritations simply have nowhere to live. There is no pre-ticked box adding something you did not choose. No countdown timer inventing urgency. No screen between you and the payment offering a longer term at a better rate. No box quietly enabling automatic renewal. No mailing list opt-in bundled into the same click as the purchase.

None of that is an achievement on our part. Those things exist because a funnel is a place where they can be inserted, and we do not have a funnel. But the outcome for you is the same either way, and it is the outcome rather than the intention that you actually experience.

If you would rather just click a button

That is a legitimate preference and it is worth saying so directly. Some people want to buy something without speaking to anybody, and this arrangement will always be slower and more personal than that.

What we can do is make the conversation short. Send the order with the device named, say which route you want, and the reply comes back with a figure and a link — usually two messages in total. The plans are $69 for one screen, $97 for two and $137 for three, twelve months, one payment, and nothing renews by itself.

If you would rather ask questions before any of that, the desk on the contact page answers on WhatsApp, Telegram and email, and a payment problem gets solved fastest when the first message contains the right six facts — the list is in what to send support so a payment problem is solved in one message.