Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Securely submit credit card details

Featured Replies

Hi,

 

I have a client who has a guest house and he would like to be able to take a deposit for a room from the webiste I am working on.

 

The actual transaction would be done manually via a credit/ debit card hand terminal so he just wants to allow the guest to securely submit their credit/ debit card details. This then also covers him for loss of keys, damage and smokers.

 

One way I was thinking was that if the mailbox is on the same server as the site then he could access the information from a secure pop3 account?

 

My area is marketing and promotion and I work with developers for the technical side but they are not too sure on this as, of course, it is potentially a big problem if done wrong.

 

The site is being done with Joomla

Hi dpcook.

 

Personally, I would never ever ever, submit unsecure credit card details over the internet. I really wouldn't submit the data to a "Secure" POP3 because what happens if the hotel owners email account is "hacked" (so-to-speak; by which I mean his details stolen through phishing or ect.)? What happens if the details in the email are stolen, and the customer finds they are the victim of credit card fraud? That's one big law suit against him for not have a suitable or secure system in place. Inturn, he could sue you for a system that is unfit for purpose.

Also, the site it's self would not be secure, it makes no difference if the POP3 account is secure, if the site isn't the data could be stolen in transmission. (Which is what I meant by "I would never ever ever, submit unsecure credit card details over the internet"). Really, your client should install a payment gateway like PayPal or Google Checkout and they can look after that kind of thing for him. Besides, Hand held terminals are becoming out dated and it's probably not the best idea for him to process the details on his own whim from his end. It's like ringing up for credit card authorisation, last time I personally saw someone do that in a store for example must of been around 7 years ago. Besides, it could be argued that (although he wouldn't) he could use the details over and over again and "rip off" his customers.

 

However, If you REALLY, want to follow this route then;

> The site will need an SSL certificate with all inbound/outbound traffic encrypted by a 128bit / 256bit system. http://www.verisign.co.uk/ is a good & reputable system.

> Send an email to the owner announcing a new payment.

> Put the credit card details into a on-site MySQL Database using PHP.

> Have a cron tab running that will automatically delete all credit card details in the database after 12 or 24 hours.

 

The method you wish to use is highly unsecure, I would strongly advise against it.

 

EDIT: In agreement with Peartree, You will need to be authorised to hold such data, missed that out from my explanation.

Well for a start you will need to become PCI-DSS L5 certified for storing cardholder data - this in itself costs a hell of a lot of money and has many complex requirements you need to meet... You would also have to have a site audit each year and draw up PCI policies and procedures.

 

L5 certification requires you to hold data on a secure hosting configuration with dedicated firewalls, secure database servers, intrusion detection etc etc as well as SSL certificates.

 

Its never as simple as storing them and processing them if you need to unfortunately - Its much easier if you get a virtual terminal and bill the customer by phone call if the room is damaged.

 

If you need more info feel free to PM me a message :)

  • Author

Hi and thanks for the replies,

 

These are pretty much the answers I was expecting to hear.

 

I just thought it was worth posting the topic; just in case there was a service that I was unaware of.

 

I own a guest house myself and know that many guest house and B&B owners ask for card details to secure a room. This not only ensures they get payment for a no-show but also means that if anyone smokes then they can charge them a fee for having the room cleaned or if someone goes off with the keys. This is normally stated in their terms of any booking.

 

If a company phones up to book a room for an employee, without providing card details, who then ends up smoking in the room (or worse) then this means the room is unusable the following night and you have little hope of receiving any recompense for this as they can argue that they have spoken to the employee who said he/ she wasn’t smoking.

 

I know there are a few third party packages and companies that offer full blown booking systems but not all accommodation owners want on line bookings as this means they are then unable to vet people who may be coming into their home.

 

I promote and design websites for accommodation owners and find the capture of card details to be a common request.

 

I know that, from having spoken to companies such as world pay or streamline that the owner of the terminal can ask for card details as part of a credit / debit card authorisation process. However, the guest house owner is entirely the responsibility for the safety of this information.

 

Therefore, I think I will take heed of the advice and look at, possibly administrative, another solution.

 

I just thought I would reply with the above as many web designers do accommodation websites from time to time and may find it useful.

Tell your client to stop being a cheapskate and get a proper Internet merchant account from a bank rather than risking losing his card machine by using it for false 'cardholder not present' transactions.

 

That, or take a deposit via PayPal and take payment for the balance when the guest is present.

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.