Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Saving and restoring Credit Card (cc) info


zlochko

Recommended Posts

Posted

Hallo everyone.

One of my clients for whom I'm building an online store wants his shopping cart to be able to store the credit card information of each user (preferably many credit cards per customer).

Then when the same customer makes another order, previously entered credit card numbers should be presented in a select box with in a masked format (first or last 4 numbers should be 'xxxx'-ed).

 

Now, I've tried everything in my power to distance him from this idea, but he insists and I'll have to find a solution. So my question is pretty basic: Have you stumbled upon such a solutions allready developed in the contributions area. As for me... I was not able to find any, but I just have might searched using the wrong keywords.

 

Thank you.

Zlochko.

Posted
You might take a look at:

 

http://www.oscommerce.com/community/contributions,4157

 

It may have enough to give you some ideas.

 

Thank you very much, but from what I have seen from this package, there is nothing even remotelly close to what I need. Is the link you have provided maybe wrong?

 

Thank you & my appologies if I am wrong in my assumption.

 

Zlochko.

Posted

You should read the TOS from your Merchant Account provider and verify that you are allowed to store CC numbers before implementing.

Posted
wants his shopping cart to be able to store the credit card information of each user (preferably many credit cards per customer).

Then when the same customer makes another order, previously entered credit card numbers should be presented in a select box with in a masked format (first or last 4 numbers should be 'xxxx'-ed).

 

I'm with you on keeping your distance from this. At least set it up to where the customer can have that option. This is probably also a legal matter...be careful.

 

Sorry I couldn't answer the question :-"

Posted
I'm with you on keeping your distance from this. At least set it up to where the customer can have that option. This is probably also a legal matter...be careful.

 

It certainly is a legal matter! ;)

 

We all understand it's hard to convince people that what they're doing is BAD. Make sure your client truly understands what a risk he/she is taking on. Your client is legally responsible for protecting those numbers and can be made financially responsible.

 

Make sure they also realize that some merchant accounts have this exact service available. The merchant actually saves the number and you can make periodic charges on the saved number. This service costs more, and I think the reasons why are obvious. The cost of properly protecting the data is not on your hands, and liability of having that information is not on your hands.

Contributions

 

Discount Coupon Codes

Donations

Posted
We all understand it's hard to convince people that what they're doing is BAD. Make sure your client truly understands what a risk he/she is taking on. Your client is legally responsible for protecting those numbers and can be made financially responsible.

 

While trying to convince him, not to go with the idea because of the legal staff, etc. - I just got one short & very clear reply: That's my problem!

 

Well... since it is... and since I am in no way liable for his decisions, I will go forward with his idea.

But people... anyone... hasn't there been such request as mine today. I simple could not beleave it that legal/or not legal no one has developed such a contribution yet. :-)

 

Anyone else besides kgt's idea?

Posted

If it gets hacked it will come back on you as you were the one to code it. I would ask for written autorization from him outlining the risks and saying you are not liable. Maybe explain to him that customers are very consious of security and want to know that their information is NOT saved and by putting it on the site he will lose sales, not gain more. We don't even have access to our customers CC numbers from our system or our Merchant Account providers web site and they are not stored on our system at any time. I like it that way, it makes me feel safe.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...