Off Grid ArmoryCustomer policies
TermsPrivacyReturns & refundsSecure checkoutStore

Production payment environment

Secure Checkout Statement

Payment-processing details for retail transactions conducted at shopoffgridarmory.com.

GatewayAuthorize.NetWebsitewww.shopoffgridarmory.com

Complete card numbers and CVVs are transmitted directly to Authorize.Net for tokenization and are not stored by Off Grid Armory’s website or order database.

01

Where this checkout is used

The secure checkout is used for eligible retail products offered through www.shopoffgridarmory.com, including firearms, ammunition, suppressors/NFA products, optics, and accessories.

Permit to Carry class registration is handled separately at offgridarmory.us and is not part of this retail website checkout.

02

How a card payment is processed

  1. The customer signs in and provides order, contact, billing, fulfillment, and required FFL/SOT information.
  2. The checkout loads Authorize.Net Accept.js from Authorize.Net’s production service.
  3. Card details are transmitted directly from the customer’s browser to Authorize.Net and exchanged for a temporary, one-time payment token.
  4. The website backend receives the token, not the complete card number or CVV.
  5. The backend rechecks the signed-in customer, inventory availability, item pricing, tax, shipping, and the disclosed 3% card processing fee.
  6. The one-time token and verified order total are submitted to Authorize.Net for authorization and capture. Approved transaction details and limited masked card information are recorded with the order.
03

Information Off Grid Armory does and does not retain

May be retained

Customer and order details, transaction identifier, authorization result, payment status, amount, card type, and masked account information such as the last four digits.

Not retained by the website

The complete card number, complete magnetic-stripe data, or CVV/security code.

04

Website and transaction protections

  • HTTPS is enforced and the domain uses HTTP Strict Transport Security.
  • A Content Security Policy restricts browser scripts, frames, forms, connections, and other resources.
  • Anti-framing, content-type, referrer, permissions, and cross-origin protections are applied by the website.
  • Payment requests must originate from the website, use the expected content type, remain within size limits, and contain an Authorize.Net token rather than raw card details.
  • Inventory and prices are verified server-side before charging, and inventory is reserved during the transaction.
  • Payment credentials and database service credentials are maintained as protected server-side environment secrets.
05

Compliance scope

Authorize.Net tokenization is designed to reduce direct handling of cardholder data. The merchant’s final PCI DSS validation requirements and processing scope are determined by Authorize.Net, the acquiring bank, the payment processor, and applicable card-network rules.

06

Payment questions

Customers should contact Off Grid Armory promptly regarding an incorrect amount, duplicate transaction, unrecognized charge, or receipt issue at [email protected] or (218) 657-2264.

Off Grid Armory27110 206th St, Shevlin, MN 56676

TermsPrivacyReturns & refundsSecure checkout