August 31, 2026
A catch-up update since July 5: safer payment provider credentials, protected login emails, and a wide range of payment, refund, and booking reliability fixes.
Since our July 5 update, we've shipped a steady stream of improvements focused on security and reliability rather than one headline feature. This note summarizes the customer-visible changes that have accumulated into the current release.
Payment providers
- Once you save a Stripe, PayPal, Przelewy24, Tpay, eService, or other gateway's credentials, ServEase never displays that saved key or secret again, even to admins. Editing a provider's other settings no longer requires re-entering credentials.
- A dedicated Replace credentials action lets you swap a provider's credentials for a new set without affecting anything else on the provider.
- Switching a connected online provider to an offline method (cash, bank transfer, cheque) now properly clears the old provider's stored credentials, with a warning before you save.
See Payment gateways.
Account and sign-in security
- Customer and employee login email addresses are now protected — they can only be changed by the account holder from their own profile, not from a customer or employee record in the admin app. This prevents one business from accidentally redirecting a shared login identity that belongs to someone with accounts at multiple ServEase businesses.
- Strengthened multi-factor authentication enforcement for email/magic-link sign-in.
- Suspended and deactivated accounts now reliably stay locked out across sign-in, email verification, and payment-return flows.
See Customer detail and Employee detail.
Payments, refunds, and billing — more reliable
A broad set of correctness fixes across the payment and refund pipeline:
- Refunded and partially refunded charges are now correctly reflected in outstanding balances, and payment status can no longer be edited in a way that creates a mismatch with actual refunds.
- Fixed several rare timing issues where a delayed notification from a payment provider (including Przelewy24 and eService) could incorrectly reopen an already-settled charge, mark a successfully paid order as failed, or misdirect a refund — refunds are now guaranteed to only ever affect the payment they were authorized for, and can no longer be sent twice or lost if the server is interrupted mid-refund. Also fixed a Przelewy24 refund amount rounding issue.
- Fixed an issue where a customer's store credit could be applied incorrectly when multiple charges happened for the same customer at nearly the same time.
- The Add Charge screen in Transactions no longer offers a discount code for a charge linked to a booking — discount codes are only for standalone charges. See Transactions page.
- Discount codes with a maximum-discount cap are now applied correctly everywhere, including charges created directly (not just through a booking).
Bookings
- Bookings with an outstanding balance no longer incorrectly display as fully paid or confirmed — status now reflects the charge being fully settled.
- Bookings on a subscription or membership plan can no longer be created without a real, active subscription behind them.
- Fixed an issue where some trial/introductory-offer-priced bookings could be incorrectly blocked at checkout.
What's new for administrators
- Manage payment provider credentials more safely with the new Replace credentials flow
- Customer and employee login emails are protected from admin-app edits
- Stronger account security around sign-in, MFA, and suspended accounts
- Numerous payment, refund, and billing reliability fixes
- More dependable subscription/membership booking and charge-settlement status
- Ongoing bug fixes and platform stability improvements