Are there any remote credit card data stores that do not manage / process payments, just store data?

Such a service will act similarly to a payment gateway, but will not actually allow or charge a card, and will make our life easier when it comes to PCI compliance.

Our customers want us to keep information about the card, but not act on it. After a month or so, if the customer does not delay their goal, they use the card data to charge the card by entering information into a standard retail machine. Now, in order for our customers to become PCI compliant, we who store credit card information must do so in accordance with PCI. As far as I know, our options are:

  • become compatible with PCI.
  • make our customers switch from us as a data warehouse service to a new service

Via:
2.1: the new service is paypal or similar, where they will have to authorize and postpone fundraising (with significant additional costs per month)
2.2: the new service is a remote data warehouse only as described above (for a small additional fee for them per month)

Any ideas are welcome, thanks.

+4
source share
2 answers

I believe that the agreement governing these retail card machines is very specific regarding how the data can be stored. I am sure that your client will violate their consent to use this machine if they do what you described.

If you are not actually processing transactions yourself, I do not know that you should be a PCI complaint. This is a voluntary industry standard, not a law. Of course, if you do not follow it, you are not allowed to participate in the long-term storage of customer information if you want to do business in the payment card industry ...

Ask for a copy of your client terminal agreement. I am sure that he says very specific things about the electronic storage of customer information.

This is a really bad idea. The obligations associated with this are enormous (millions of dollars, if you have a small-scale breach, as a rule). PCI approval will cost you at least $ 50k, probably a lot more, especially if you don't have a team that previously had embedded systems.

You need to find an existing processor that provides a remote data warehouse for your client. Providers I have worked with in the past have included MyBillingTree.com and Profitstars . The latter is a larger, more professional outfit, but they are still reselling someone else api. Any major provider of enterprise payment solutions should have this opportunity. Do not go with PayPal, they are usually overrated and have limited flexibility. If your volumes are not ridiculously low, any of these companies will indicate a competitive rate to you, possibly much better than the saber-terminal that your client already has.

You do not have to perform authorization and capture delays. With the profitstars API, you can start the pre-authorizer, return the saved token representing a set of customer information, and (provided that you have the correct client authorization), use this to start transactions for arbitrary amounts later.

+2
source

Fast forward to 2014. Spreedly is a service that stores cards and processes pci compliance for you. You get a token, which you can later use to indicate a card. They do not process payments directly, you use their api to process payments on various third-party gateways.

+1
source

All Articles