Do I need PCI compliance if I use a hosted checkout for food orders?
Updated 6 October 2026
Yes, but only the simplest kind. With a hosted checkout such as Stripe Checkout, card details are typed on the provider's page, so you qualify for the simplest questionnaire, SAQ A.
- PCI rules apply to anyone who stores, processes or sends card data. Compliance is shared between you and the payment provider.
- Stripe Checkout shows the card fields on Stripe's own domain, so card data never touches your servers.
- SAQ A is for merchants who fully outsource card handling and never store or process card data themselves.
- Since 31 March 2025 you also confirm that your site is not susceptible to attacks from scripts.
Online payments to your own account
Online payments go through your own payment account, with card and UPI on Stripe outside India, or Razorpay or Easebuzz in India. Money settles to you, with 0% Menuthere commission.
Next questions
Sources (3)
- Stripe security guide, Stripe, read 30 September 2026
- PCI compliance guide, Stripe, read 30 September 2026
- Important updates for merchants validating to SAQ A, PCI Security Standards Council, read 30 September 2026
