Betalingssikkerhed
Payment security
Last updated 13 August 2026
This page sets out what happens to your card details when you buy from us, what we can see, what we store, and what we are responsible for. It is written so you can check the claims rather than take them on trust.
We never see your card number
Card details are entered with our payment provider, in a field served by them, and are transmitted directly to them. They do not pass through this website, are not logged by it and are never written to our database. Nobody at unika:k ApS can read your card number, and nobody here could tell it to you if you asked.
1. The connection
- Every page on unikakceramics.shop is served over HTTPS with TLS. There is no unencrypted version of this site.
- We send Strict-Transport-Security with a two-year max-age and includeSubDomains, so a browser that has seen this site once will refuse to load it over plain HTTP afterwards.
- We also send X-Content-Type-Options: nosniff, X-Frame-Options: DENY so the site cannot be framed by a third party, a strict Referrer-Policy, and a Permissions-Policy that switches off camera, microphone and geolocation entirely.
- You can verify all of this yourself: any browser will show the certificate, and the response headers are visible in developer tools.
2. What we store, and what we do not
| Data | Stored by us? | Why |
|---|---|---|
| Card number (PAN) | No | It never reaches our servers. |
| Expiry date | No | Same. |
| CVC / security code | No | Never stored by anyone after authorisation — storing it is prohibited under the card network rules. |
| Cardholder name | No | We hold the delivery name you type, which is a different thing. |
| Last four digits and card brand | Only if the provider returns them with the receipt | To match a payment to an order when you contact us about it. |
| Name, email, telephone, delivery address | Yes | To pack and send the parcel and to meet Danish bookkeeping law. See the privacy policy. |
| What you ordered and what it cost | Yes | It is the record of the contract, and the basis of any later complaint. |
3. PCI DSS
The Payment Card Industry Data Security Standard applies to anyone who processes, transmits or stores cardholder data. Compliance is shared between the payment provider and the merchant, and the split here is:
- Our payment provider is PCI DSS Level 1 certified and is responsible for the capture, transmission and storage of card data. The card entry field is served by them.
- We are responsible for not undermining that: serving the checkout over TLS, not intercepting or logging the card field, keeping our dependencies patched, and restricting who can reach the order records. Because no card data touches our systems, our obligation is the lightest of the PCI merchant categories rather than the heaviest.
We take no card payments by telephone and we will never ask you to email or text us a card number. If anyone claiming to be us does, it is not us.
4. Currency, tax and what appears on your statement
- Everything on this site is priced in Danish kroner (DKK), including 25% Danish moms. The currency is stated in the header of every page, in the basket and again on the details page.
- You are charged the total shown before you continue to payment — goods plus delivery, moms included. Nothing is added afterwards.
- No surcharges. We add no card fee, no handling fee, no service fee and no charge for choosing one card over another. The price is the price.
- Your statement will show DAYCUP alongside the amount in DKK. If your card is not in kroner, your own bank sets the exchange rate and may add its own fee — that is between you and your bank, and we neither receive nor control it.
5. Cards we accept
- Dankort
- Visa
- Mastercard
- American Express
Card payments in the EU are subject to strong customer authentication, so your bank may ask you to confirm the payment in its app or by a code. That step happens between you and your bank; we are not part of it and see only whether it succeeded.
6. Refunds
- Refunds are returned to the card that paid. We cannot send a refund to a different card or to a bank account — the payment rails do not allow it, and it is a common fraud pattern.
- We issue refunds within 14 days of accepting a withdrawal or a complaint. How long the money then takes to appear is up to your bank, typically three to five working days.
- There is no fee for a refund and we never withhold a “restocking” charge.
- Your two rights, in full: 14-day right of withdrawal and two-year right to complain.
7. If you do not recognise a charge
Email support@unikakceramics.shop or call +45 23 76 94 18 with the date and amount before you raise a chargeback. We can usually identify the order within a few minutes and, if it is not yours, we will refund it immediately and tell your bank so. A chargeback works too — it is your right and we will not contest a genuine one — but it takes weeks rather than minutes.
8. How to tell a real email from us
- We only ever write from support@unikakceramics.shop. Anything from another domain is not us, however similar it looks.
- We never ask for a card number, a CVC, a PIN, a bank password or a one-time code — not by email, not by text, not on the phone.
- We never send a link asking you to “re-enter payment details to release your parcel”. Courier fee texts of that kind are always fraudulent.
- If something looks wrong, do not click it. Forward it to support@unikakceramics.shop and we will confirm whether it came from us.
9. Fraud and card testing
Automated attempts to test stolen card numbers against small merchants are constant, and we take our share of the defence: the order endpoint validates every request server-side regardless of what the browser did, forms are rate-limited and bot-checked, and our provider applies its own fraud screening before authorising a payment. We may cancel and refund an order that fails those checks. If that happens to a genuine order of yours, get in touch and we will sort it out.