1099-K forms and card security
Last updated September 13, 2026
Because LakeOps Payments charges go to your own Stripe account, any Form 1099-K comes from Stripe, and because customers type card details on Stripe’s hosted page, card numbers never reach LakeOps — which is what keeps it in the lightest PCI category, SAQ A.
Two questions come up every January and every time a customer asks whether it is safe to pay online: who sends the tax form for card payments, and where card numbers go. Both have short answers, and both answers are the same shape — the payments are yours, on your Stripe account, so the paperwork and the card data sit with Stripe.
Form 1099-K comes from Stripe
LakeOps does not issue 1099-Ks. Every LakeOps Payments payment is a charge on your own Stripe account, with you as the merchant, so Stripe is the one that reports those payments to the IRS and sends you any Form 1099-K. You will find it in your Stripe dashboard, which is also where you confirm your tax details if Stripe asks.
- What Stripe reports is the gross it processed on your account — before refunds, Stripe’s fees and the LakeOps fee. Your bookkeeper reconciles it against your books; the export your bookkeeper wants is the other half of that.
- Checks, cash and anything else you record by hand never went through Stripe and are not on it.
- Stripe’s dashboard lists its own fee and the LakeOps fee against each payment, which is what your bookkeeper needs to get from the gross to what reached your bank.
- Form 1099-K is a United States form. A Canadian Stripe account does not get one — ask your accountant what applies.
Whether a 1099-K is issued, and for what threshold, is set by the IRS and applied by Stripe. If a figure on it looks wrong, Stripe is the one to ask.
Card numbers never reach LakeOps
When a customer presses Pay, or saves a card for next time, LakeOps sends them to Stripe’s own hosted payment page. They type the card number, or choose their bank, there — on Stripe, not on a LakeOps page. What comes back to LakeOps is:
- whether the payment worked, and Stripe’s reference for it;
- for a card: the brand and the last four digits, so the receipt can say which card;
- for a saved card: its expiry month and year, so the customer can see which card is on file.
That is all. There is no screen anywhere in LakeOps where anybody types a card number — not your office, not ours — and so nothing to steal from LakeOps that could be used to charge a card.
PCI compliance
PCI DSS is the card industry’s security standard for anyone who handles card data. Because LakeOps uses Stripe’s hosted payment page and never receives card data, it falls in the lightest self-assessment category, SAQ A. You do not need to fill anything in for LakeOps.
Your own Stripe account is separate: Stripe may ask you, as the merchant, to confirm your PCI compliance there. If you also take cards some other way — a terminal in the office, card numbers over the phone — that is outside LakeOps entirely.
Cards on file
A saved card is stored by Stripe, on your Stripe account. LakeOps keeps the customer’s authorization — the exact words they agreed to, and when — and Stripe’s reference to the card. Removing the card removes it from your Stripe account too. See keeping a card on file.
Still stuck? Ask us — or go back to the help center.