How we keep your data safe
Plain answers about how payments and card data flow during bus card recharge.
Card data never touches our servers
Payment card entry happens on a dedicated payment page provided by our payment processor. Your card number and CVV go directly from your browser to the processor over an encrypted connection. We never receive the full card number, and we never store it — not encrypted, not hashed, not anywhere.
What we do store
- The 10-digit Hafilat card number you enter (needed to apply the top up).
- The top up amount and the payment reference from the processor.
- Your email address, only if you provided one for a receipt.
- Standard technical logs (IP, browser type, timestamp) for security and fraud prevention.
Transport encryption
The website is served over HTTPS. All form submissions, including the balance check and the recharge form, travel over encrypted TLS.
What we do not do
- We do not sell your data to third parties.
- We do not display fabricated PCI/SSL/certification badges to look bigger than we are.
- We do not send marketing emails you did not ask for.
If something looks wrong
If you see a charge you do not recognise or receive a message pretending to be us, please contact info@capitalbusreload.org immediately. We will help you check the transaction and, if it is not ours, guide you on next steps with your bank.