Compliance frameworks, security audits, and quality certifications this company maintains.
Lightspeed Payments is certified to PCI DSS Level 1, the highest tier of the Payment Card Industry Data Security Standard, ensuring that the payment card data processed through Lightspeed's integrated terminals and online checkout is handled in compliance with Visa, Mastercard, and global card network security requirements.
Lightspeed's cloud platform maintains SOC 2 Type II certification, providing independent assurance that the security, availability, and confidentiality controls protecting merchant transaction data, inventory records, and customer information across Lightspeed Retail and Restaurant meet AICPA Trust Services Criteria.
Lightspeed's platform is designed for GDPR compliance for European merchants, with data residency controls, consent management features, and data processing agreements covering the personal data of EU-based merchant customers processed through Lightspeed Retail, Restaurant, and Commerce.
As a Canadian-headquartered company, Lightspeed complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) for the collection, use, and disclosure of personal information of Canadian merchants and their customers processed through Lightspeed's platform.
Lightspeed holds ISO/IEC 27001 certification for its information security management systems, ensuring that the controls protecting Lightspeed merchant data, payment processing infrastructure, and cloud platform operations meet internationally recognized security management standards.
Lightspeed Payments terminals are EMV chip-and-PIN compliant, ensuring that in-person card present transactions processed through Lightspeed hardware meet the global EMV standard for chip card authentication, reducing counterfeit card fraud liability for Lightspeed merchants.
Regulatory
Visa / Mastercard Certified
CertifiedLightspeed Payments is certified as an acquiring payment facilitator (PayFac) by Visa and Mastercard, enabling Lightspeed to onboard merchants for card acceptance without requiring each merchant to establish their own merchant account with a traditional acquiring bank.
Lightspeed's web-based back-office management interfaces and merchant-facing Lightspeed Commerce e-commerce tools are designed to meet WCAG 2.1 AA accessibility standards, ensuring that merchants with disabilities can manage their Lightspeed platform using assistive technologies.
Lightspeed Commerce complies with the California Consumer Privacy Act, providing merchants and their customers with data transparency, opt-out rights, and deletion mechanisms within Lightspeed's cloud POS and payments platform.
Lightspeed is certified to ISO 27018, protecting personally identifiable information processed through its cloud-based retail, restaurant, and golf management platforms in accordance with international privacy standards.