Legal entity : MUCHA JACEK — French sole traderSIREN 109 189 845 · SIRET 109 189 845 00018 · APE 85.59A
Atelier Mucha · LearnTechnical English and Polish · blockchain literacy · Oise, France

HomePolicies › Payment security

Payment security

Version in force as of 4 septembre 2026.

Translation for information only. This is a courtesy translation of the French document « Sécurité des paiements », which is the only binding version. The seller is a French sole trader and the contract is governed by French law. In the event of any discrepancy or difference of interpretation between the two versions, the French version prevails.

This page says exactly who handles your payment details, who does not, and what is checked before an order is accepted.

What the Provider never receives

  • your card number;
  • the expiry date and the security code (CVC/CVV);
  • your personal code, whatever the means of payment;
  • your online banking credentials, including for iDEAL or Bancontact.

That data is entered in a field hosted by the payment service provider, or directly at your bank. It passes neither through this site's servers nor through the Provider's mailbox. Never send it by e-mail or give it over the telephone: you will never be asked for it that way.

What the Provider does receive and keep

  • the order reference and the itemised lines;
  • the amount, the currency and the date of the transaction;
  • the status returned by the payment provider (authorised, declined, expired);
  • the last four digits of the means of payment, where the provider passes them on, solely for accounting reconciliation;
  • your billing details, as you entered them.

Strong customer authentication (PSD2)

Payments are subject to the strong authentication required by Directive (EU) 2015/2366 whenever the issuer requires it: approval in the banking app, a one-time code or biometrics. An unauthenticated payment is declined by the bank, never forced through by the site.

Transport and integrity

  • the whole site is served over HTTPS, with automatic redirection from HTTP;
  • the basket is signed server-side: a total, a quantity or a service identifier altered in the URL is rejected and the payment page returns an error;
  • the price charged is always re-read from the server's catalogue at the moment of payment, never taken from the browser;
  • the transaction status is re-checked server-side on return from the bank, before any order confirmation.

Amounts and double charging

An order below € 200 is collected in full; above that, only a deposit of 30 % is collected at the time of the order. Each order reference can give rise to only one completed collection: reloading the return page does not create a second charge.

Fraud prevention

The Provider may refuse or cancel an order, before performance and at no cost to the client, in the following cases:

  • billing details that are manifestly inconsistent or unusable;
  • a report of non-payment or of a chargeback from the bank or the payment provider;
  • an order covering an activity expressly excluded by the code of practice;
  • repeated payment attempts with declined means.

A refusal gives rise to a full refund of any sum already collected, within 14 days, to the original means of payment.

Disputing a charge

If a charge seems wrong to you, write first to contact@jacekmucha.fr with the order reference: the procedure described on the Complaints and mediation page applies, with an acknowledgement within 2 working days. This does not prevent you from exercising your right to dispute the charge with your bank.

Reporting a fraudulent site

The only sales site operated by MUCHA JACEK is learn.jacekmucha.fr, and the only e-mail address used for invoicing is contact@jacekmucha.fr. Any page or message presenting itself under this name from another address is unconnected with the Provider and can be reported to the address above.

Governing law

This policy is governed by French law.

This document is governed by French law. For any question: contact@jacekmucha.fr.