PDA

View Full Version : PCI Compliancy


Venka
12th March 2009, 15:19
Hello,

Our new site is just up and there are a few issues.

Due to PCI complicancy our web developers tell us that pre-orders are going to be very difficult due to the fact we cannot hold CVV numbers.

Sometimes we features items on our site which are Out of Stock at that moment but will be in stock in let's say 14-21 days. Now in the past we didn't take funds when the items were not in stock, we would only take the money when the stock came in.

Now apparently this is a grey area. I have spoken to Streamline and they cannot give me a definate answer. Protx say as they are PCI compliant, CVV details cannot be held. Our web-developers say CVV details cannot be held, but when asked why Marks and Spencer, Amazon etc do, we get the answer it's cos they're bigger, not really helpful answer.

However, I have just pre-ordered something at Amazon so obviously the do hold my CVV details.

Anybody else have experience with this and any suggestions how to get around it. I understand that this is not a law but if you are found by your payment provider to hold details such as CVV numbers, you can receive a fien of $50 per held credit card number.

Photo
12th March 2009, 15:34
Can you use a "DEFERRED" payment from your cart and then just release it in your Protx VSP admin area when you ship the order?

KateCB
12th March 2009, 16:30
We advise the customer that we are debiting their card with a £1.00 holding fee at the time of order; this generates an authorisation number at Protx which we the use to debit the card once the goods are available for dispatch.

We don't keep ANY card data after the £1.00 has been debited and hae been doing it this way for 8 years. DPA approved!