Web Design Forum: Storing customers Card or bank account details. - Web Design Forum

Jump to content

WDF
WDF Premium Memberships Reseller Hosting
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Storing customers Card or bank account details. Rate Topic: -----

#1 User is offline   Jambo 

  • Forum Newcomer
  • Pip
  • Group: Members
  • Posts: 17
  • Joined: 23-February 10
  • Reputation: 0

Posted 20 May 2011 - 09:34 AM

I have recently agreed to perform research into the feasibility of a very large website project for a client. To cut to the chase in order for it do what the client requires i believe it will need to store customer payment details on the website, such as card details or bank account numbers. Firstly i was very skeptical and now after reading up a lot of information i have come to the conclusion this should not be done. Despite this, if the site was to be hosted on a dedicated server with an SSL certificate and a database that stored this information with encryption, would it be possible and worth creating it from a security and legal point of view? I'm still very skeptical.

Now this next bit may sound a bit weird but i'm afraid the clients idea is to remain secret. Just bear with it. Now the reason i believe storing the payment information on our own server is the only way to achieve what they want is that; this information, only at the clients request, will be entered on different websites and a monthly direct debit will be set up from the clients account to the other sites. The amount, what company etc will all be at the clients discretion we will just streamline the signup process.

Is there a third party system that already exists that could take the clients payment details, store them securely, then allow access to them in order for us to sign them up to other sites?

Is this legal? Should this be done?

I'm very skeptical about this and sure lot's of people will have some strong opinions, so please share.
0

#2 User is online   BlueDreamer 

  • Web Guru
  • Group: Moderators
  • Posts: 5,804
  • Joined: 23-October 07
  • Reputation: 202
  • Gender:Male
  • Location:Northampton (where?)
  • Experience:Advanced
  • Area of Expertise:Web Developer

Posted 20 May 2011 - 10:00 AM

Many payment gateways offer this sort of service, the big advatage is that customers card details are not stored on your server, making things much more sercure.
0

#3 User is online   Spitfire 

  • Mighty Pirate™
  • PipPipPipPip
  • Group: Members
  • Posts: 890
  • Joined: 05-February 11
  • Reputation: 189
  • Gender:Male
  • Location:Berkshire
  • Experience:Web Guru
  • Area of Expertise:Web Developer

Posted 20 May 2011 - 10:37 AM

You're right to be sceptical. These days you'll need to confirm to PCI DSS standards so even having SSL and encryption isn't enough:
http://en.wikipedia....rd#Requirements

If you want my opinion, it's a lot more hassle than it's worth. Get a 3rd party (that's PCI DSS verified) to do it.
0

#4 User is offline   Jambo 

  • Forum Newcomer
  • Pip
  • Group: Members
  • Posts: 17
  • Joined: 23-February 10
  • Reputation: 0

Posted 20 May 2011 - 12:37 PM

Thanks for the feedback, could you recommend a 3rd party service that actually does this? I have looked around but have not found anything.
0

#5 User is online   BlueDreamer 

  • Web Guru
  • Group: Moderators
  • Posts: 5,804
  • Joined: 23-October 07
  • Reputation: 202
  • Gender:Male
  • Location:Northampton (where?)
  • Experience:Advanced
  • Area of Expertise:Web Developer

Posted 20 May 2011 - 01:24 PM

Here's a few...

Worldpay - http://www.worldpay....=recurring&c=UK
Sagepay - http://www.sagepay.com/token-system
Secure Trading
- http://www.securetra...kenisation.html
- http://www.securetra...g-payments.html

This post has been edited by BlueDreamer: 20 May 2011 - 01:25 PM

0

#6 User is offline   Jambo 

  • Forum Newcomer
  • Pip
  • Group: Members
  • Posts: 17
  • Joined: 23-February 10
  • Reputation: 0

Posted 21 May 2011 - 03:21 PM

View PostBlueDreamer, on 20 May 2011 - 01:24 PM, said:




Thanks for the links, i'll have a read, hopefully find a solution.
0

#7 User is offline   Jambo 

  • Forum Newcomer
  • Pip
  • Group: Members
  • Posts: 17
  • Joined: 23-February 10
  • Reputation: 0

Posted 25 May 2011 - 07:36 AM

One question, if we were to only store bank account details, not card details, Would this regulation not apply? Are there any other laws of regulations that would?

http://en.wikipedia....rd#Requirements

Obviously i understand from a technical standpoint the risks would be the same.
0

#8 User is offline   Dx3webs 

  • Dedicated Member
  • PipPip
  • Group: Members
  • Posts: 156
  • Joined: 07-August 10
  • Reputation: 9

Posted 25 May 2011 - 10:32 AM

Hi there,

I would have thought that if you wish to store any kind of banking related information you would be wise to treat yourself as requiring type 4 compliance. Even if you are using a 3rd party gateway you will need type 1 compliance.

the best explanation on this I have seen so far is here

http://www.crucialwe...pliant-hosting/
0

#9 User is offline   ZetaPrints 

  • Forum Newcomer
  • Pip
  • Group: Members
  • Posts: 28
  • Joined: 31-January 11
  • Reputation: 2
  • Gender:Male
  • Experience:Advanced
  • Area of Expertise:Entrepreneur

Posted 31 May 2011 - 10:10 AM

View PostJambo, on 21 May 2011 - 03:21 PM, said:

Thanks for the links, i'll have a read, hopefully find a solution.


Here are other payment processors you may want to check out. I do not know for sure if each one still works and if they serve your exact need.

2CheckOut
authorizenet
BTClick&Buy
CCAvenue
CCBill
CCNow
ClickBank
Gate2Shop
Google Checkout
iBill
iKobo
InstaBill
Jettis
Kagi
Moneybookers
MultiCards
NoChex
PartyKey
PayDirect
Pay-Line
Paymate
Paypoint
ProPay
Reg.Net
RegNow
RegSoft
Share*It
Skypay
SWREG
Verotel
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users