Storing customers Card or bank account details.
#1
Posted 20 May 2011 - 09:34 AM
Now this next bit may sound a bit weird but i'm afraid the clients idea is to remain secret. Just bear with it. Now the reason i believe storing the payment information on our own server is the only way to achieve what they want is that; this information, only at the clients request, will be entered on different websites and a monthly direct debit will be set up from the clients account to the other sites. The amount, what company etc will all be at the clients discretion we will just streamline the signup process.
Is there a third party system that already exists that could take the clients payment details, store them securely, then allow access to them in order for us to sign them up to other sites?
Is this legal? Should this be done?
I'm very skeptical about this and sure lot's of people will have some strong opinions, so please share.
#2
Posted 20 May 2011 - 10:00 AM
#3
Posted 20 May 2011 - 10:37 AM
http://en.wikipedia....rd#Requirements
If you want my opinion, it's a lot more hassle than it's worth. Get a 3rd party (that's PCI DSS verified) to do it.
#4
Posted 20 May 2011 - 12:37 PM
#5
Posted 20 May 2011 - 01:24 PM
Worldpay - http://www.worldpay....=recurring&c=UK
Sagepay - http://www.sagepay.com/token-system
Secure Trading
- http://www.securetra...kenisation.html
- http://www.securetra...g-payments.html
This post has been edited by BlueDreamer: 20 May 2011 - 01:25 PM
#6
Posted 21 May 2011 - 03:21 PM
BlueDreamer, on 20 May 2011 - 01:24 PM, said:
Worldpay - http://www.worldpay....=recurring&c=UK
Sagepay - http://www.sagepay.com/token-system
Secure Trading
- http://www.securetra...kenisation.html
- http://www.securetra...g-payments.html
Thanks for the links, i'll have a read, hopefully find a solution.
#7
Posted 25 May 2011 - 07:36 AM
http://en.wikipedia....rd#Requirements
Obviously i understand from a technical standpoint the risks would be the same.
#8
Posted 25 May 2011 - 10:32 AM
I would have thought that if you wish to store any kind of banking related information you would be wise to treat yourself as requiring type 4 compliance. Even if you are using a 3rd party gateway you will need type 1 compliance.
the best explanation on this I have seen so far is here
http://www.crucialwe...pliant-hosting/
#9
Posted 31 May 2011 - 10:10 AM
Jambo, on 21 May 2011 - 03:21 PM, said:
Here are other payment processors you may want to check out. I do not know for sure if each one still works and if they serve your exact need.
2CheckOut
authorizenet
BTClick&Buy
CCAvenue
CCBill
CCNow
ClickBank
Gate2Shop
Google Checkout
iBill
iKobo
InstaBill
Jettis
Kagi
Moneybookers
MultiCards
NoChex
PartyKey
PayDirect
Pay-Line
Paymate
Paypoint
ProPay
Reg.Net
RegNow
RegSoft
Share*It
Skypay
SWREG
Verotel
Help

















