Version: 1.0
Publication date: 29.07.2026
Effective date: 29.07.2026
1. General information
PilotShop provides Customers with the option of paying for orders online through a specialised payment service provider.
The Seller is REGIONAL AIR SUPORT S.R.L., hereinafter referred to as “PilotShop”.
This page explains:
- the general manner in which online payments are processed;
- the role of PilotShop and the payment service provider;
- the card information that is not accessible to PilotShop;
- the authentication procedures;
- the fraud-prevention measures;
- the security recommendations addressed to the Customer.
The payment methods actually available, the transaction currency and the total amount are displayed before the order is submitted.
This page supplements:
- Payment Methods and Invoicing;
- the Terms and Conditions;
- the Privacy Policy;
- the Returns Policy and Right of Withdrawal.
2. Payment service provider
Online card payments are processed through: PlatiOnline.ro
When online payment is selected, the Customer is redirected to, or interacts with, the secure interface provided by the payment service provider.
The payment process may involve:
- PilotShop, as the merchant;
- the payment service provider;
- the acquiring bank;
- the card-issuing bank;
- the international card scheme;
- providers of authentication and fraud-prevention systems.
Each participant may process the information required to perform its own role and comply with its legal obligations.
PilotShop does not directly control:
- the bank’s approval or refusal of the transaction;
- the authentication method selected by the issuing bank;
- the card limits;
- the temporary blocking of an amount;
- the fees charged by the Customer’s bank;
- the exchange rate applied by the bank;
- the time required by the bank to release or return an amount.
3. Accepted cards and payment methods
The cards and payment instruments displayed in the provider’s interface at the time of the transaction may be used.
Actual acceptance depends on:
- the type of card;
- the issuing bank;
- online payments being enabled;
- the limits set by the Customer or the bank;
- the transaction currency;
- the country in which the card was issued;
- the outcome of the authentication;
- the anti-fraud checks;
- the rules of the payment service provider.
4. Card data
4.1. Information entered on the payment page
Depending on the payment instrument used, the provider’s secure interface may request the information required to authorise the transaction.
This information may include data such as:
- the card number;
- the cardholder’s name;
- the expiry date;
- the security code;
- the data required for authentication;
- other information requested by the bank or the provider.
This data must be entered exclusively on the secure payment page.
PilotShop does not request that it be sent by:
- email;
- telephone;
- contact form;
- messaging service;
- the order comments field;
- attached documents.
4.2. Information accessible to PilotShop
PilotShop does not receive or store the full card number, the CVV/CVC code or the personal authentication codes used by the Customer.
PilotShop may receive only the information required to manage the transaction, such as:
- confirmation or refusal of the payment;
- the amount;
- the currency;
- the transaction date;
- the transaction identifier;
- the masked final digits of the card, where provided;
- the general type of payment instrument;
- the information required for a refund;
- anti-fraud indicators or technical messages relating to the transaction.
The information received is used for:
- confirming the payment;
- matching the payment to an order;
- financial reconciliation;
- processing refunds;
- preventing fraud;
- handling complaints;
- complying with legal obligations.
5. Payment authentication
Payment may require the Customer to authenticate through mechanisms made available by the issuing bank.
Depending on the bank and the transaction, authentication may involve:
- confirmation in a banking application;
- entering a code received by SMS;
- using a password;
- biometric authentication;
- confirmation through a security device;
- another method established by the payment service provider.
European requirements concerning strong customer authentication are intended to reduce the risk of fraud in electronic payments. In principle, strong customer authentication is based on at least two independent elements, such as something known by the user, something possessed by the user or a characteristic inherent to the person. Payment service providers may also apply exemptions in accordance with the applicable legislation.
PilotShop does not receive the password, code, biometric information or other elements used by the Customer to authenticate within the bank’s system.
6. Payment authorisation and acceptance of the order
The authorisation, reservation or debiting of an amount does not, in itself, constitute acceptance of the order by PilotShop.
The sales contract is concluded only after PilotShop accepts the order, in accordance with the Terms and Conditions.
Situations may arise in which:
- the payment is authorised, but the order cannot be accepted;
- the amount is only temporarily reserved;
- the bank displays the transaction as pending;
- the processor sends confirmation with a delay;
- the transaction is subject to an additional check;
- the bank refuses the payment after the authentication attempt.
If an amount has been collected but the order is not accepted, PilotShop will initiate, as applicable:
- cancellation of the authorisation;
- release of the reserved amount;
- refund of the amount collected.
The time at which the amount becomes available again also depends on the payment service provider and the issuing bank.
7. Payment currency and currency conversion
Online card payments may be made in:
- Romanian lei (RON);
- euros (EUR).
The transaction currency is the currency selected and displayed to the Customer on the checkout page and in the secure payment interface before the transaction is authorised.
Before confirming the payment, the Customer must check:
- the selected currency;
- the total amount;
- the products included in the order;
- any delivery costs;
- any other displayed and accepted costs.
If the currency of the card or bank account is the same as the transaction currency, the payment is processed in the selected currency, without any currency conversion being performed by PilotShop.
If the currency of the Customer’s card or account differs from the transaction currency:
- the issuing bank or payment service provider may perform the currency conversion;
- the exchange rate is set by the institution performing the conversion;
- the Customer may be charged conversion, international transaction or administration fees;
- PilotShop does not set or control the exchange rate or the fees charged by the Customer’s bank.
PilotShop does not convert between RON and EUR after payment has been confirmed and cannot refund differences arising exclusively from:
- exchange-rate fluctuations;
- the rate used by the issuing bank;
- fees charged by the Customer’s bank or payment provider.
Where a refund is made, it is initiated in the currency of the original transaction and to the same payment instrument, subject to the applicable conditions.
If the Customer’s bank converts the refunded amount into another currency, the final amount credited may differ from the amount originally debited due to the exchange rates and fees applied by the bank.
8. Security measures
PilotShop uses a specialised provider to process online payments and configures the integration so that complete card details are not entered in the store’s ordinary forms.
Depending on the service used, transaction security may include:
- encrypted connections;
- authentication of the Customer by the issuing bank;
- transaction monitoring;
- anti-fraud mechanisms;
- restricted access to payment information;
- logging of operations;
- tokenisation or masking of certain data;
- automatic or manual risk checks.
PilotShop uses specialised providers and reasonable technical and organisational measures to protect transactions. However, no method of electronic transmission or processing can guarantee the absolute elimination of all risks.
9. Anti-fraud checks
PilotShop, the payment service provider or the bank may temporarily suspend the processing of a transaction or order where there are indications of:
- unauthorised use of the card;
- significant discrepancies between the order data and the payment data;
- repeated failed attempts;
- duplicate transactions;
- an unusual amount or pattern of behaviour;
- a request made by the bank;
- a technical error;
- a possible breach of the law.
PilotShop may ask the Customer for additional information that is strictly necessary to verify the order.
PilotShop will not request:
- the CVV/CVC code;
- codes received by SMS;
- the password for the banking application;
- the password for the bank account;
- an unmasked photograph of both sides of the card;
- access to the bank account;
- installation of a remote-control application.
If proof of payment is required, the Customer may be asked to provide a document or screenshot in which irrelevant information has been masked.
10. Failed, duplicate or unrecognised payments
10.1. Failed payment
A payment may be refused for reasons such as:
- insufficient funds;
- a transaction limit;
- an expired card;
- a card not enabled for online payments;
- failed authentication;
- incorrectly entered data;
- refusal by the bank;
- an anti-fraud measure;
- a technical error.
Where a payment is refused, PilotShop may not receive the full reason determined by the bank.
The Customer may contact the issuing bank or use another available payment method.
10.2. Duplicate payment
Before repeating a payment, the Customer is advised to check:
- the message displayed on the payment page;
- the confirmation email;
- the order status;
- the bank statement or banking application.
If there are indications of a duplicate payment, the Customer must contact PilotShop and provide:
- the order number;
- the date;
- the amount;
- the transaction identifiers, where available.
The Customer must not send the full card details.
10.3. Unrecognised transaction
If the Customer identifies a transaction that they do not recognise, they must:
- contact the issuing bank without delay;
- request that the payment instrument be blocked, if the bank recommends this measure;
- inform PilotShop, stating the amount, date and available masked information;
- not disclose the authentication codes to anyone.
PilotShop will cooperate within the limits of the information available to it and its legal obligations; however, the investigation of unauthorised card use is carried out primarily by the payment service providers and the issuing bank.
11. Refunds
A refund of an online payment is initiated in accordance with:
- the Terms and Conditions;
- the Returns Policy and Right of Withdrawal;
- the rules governing cancellation of the order;
- the applicable legislation.
As a rule, the amount is refunded to the same payment instrument used for the original transaction, unless the Customer expressly agrees to another method that does not result in additional costs for the Customer.
PilotShop’s initiation of a refund does not mean that the amount will appear in the account immediately.
The final processing time depends on:
- the processor;
- the acquiring bank;
- the card scheme;
- the issuing bank;
- banking days;
- any applicable checks.
The Customer will be informed of the date on which the refund was initiated and, where available, its identifier.
12. Recommendations for protecting the Customer
To reduce risks, the Customer is advised to:
- check the website address before entering any data;
- not access payment links received from unknown sources;
- not disclose authentication codes;
- not allow remote access to the device at the request of an unknown person;
- check the amount, currency and payee before confirming the payment;
- not save card details on public devices;
- use secure passwords and screen-locking methods;
- keep the operating system and browser up to date;
- sign out after using a shared device;
- contact PilotShop directly if a payment message appears suspicious.
PilotShop will not ask the Customer by telephone or email to transfer money to another account in order to “unblock” an online payment.
Any change to payment instructions must be verified using the official contact details published on the Website.
13. Fraudulent messages and phishing
Fraudulent messages may impersonate PilotShop, the processor, the bank or the courier.
A message should be treated with caution if it:
- requests a password or a code received by SMS;
- requests complete card details by email;
- asks the recipient to install an application;
- requests an urgent payment to a different account;
- contains an unusual domain name;
- promises a refund in exchange for card details;
- requests access to the device;
- threatens the immediate cancellation of the order.
A suspicious message may be forwarded to: [email protected]
The Customer must not access the suspicious link or send confidential information.
14. Data processing
For the administration of the payment, PilotShop may process information such as:
- the Customer’s name;
- the order details;
- the amount and currency;
- the transaction identifier;
- the payment status;
- masked information concerning the payment instrument;
- technical data and anti-fraud indicators;
- refund information;
- correspondence relating to the transaction.
Complete card details are processed within the infrastructure of the providers involved in the online payment, not in PilotShop’s ordinary forms.
Further information is available in the Privacy Policy.
15. Contact
For issues concerning an online payment:
REGIONAL AIR SUPORT S.R.L. – PilotShop
- email: [email protected];
- telephone: +40 770 951 700;
- showroom/place of business: No. 24–28 Șoseaua București–Ploiești Road, District 1, postal code 013694, Bucharest;
- business hours: Monday–Friday, 09:00–17:00.
The message should include, as applicable:
- the order number;
- the payment date;
- the amount and currency;
- the transaction identifier;
- a description of the issue;
- a screenshot in which sensitive data has been masked.
The following must not be sent:
- the full card number;
- the CVV/CVC code;
- the password;
- the authentication codes;
- unmasked photographs of the card.