So long as the actual details do not pass thro your server then you do not need to be PCI compliant.
You might want to double-check that with your merchant account provider. PCI compliance is not just about "sensitive" cardholder data like the card number, it also includes personal information like their name and address. Besides the danger you may be prevented from accepting credit cards through your site, it's also just good practice to ensure you're compliant so that you have a decent security system in place.
So how does this work if you bill someone against their credit card every month? Are you saying you can simply quote a security code provided during a previous transaction and hence don't need to store card information?
So how does this work if you bill someone against their credit card every month? Are you saying you can simply quote a security code provided during a previous transaction and hence don't need to store card information?