Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

CV2 number


awren

Recommended Posts

Posted

Hi There,

 

My client is asking for the CV2 number to be added to the payment field, im aware there is an contribution for this but I need to be sure from you guys if you can have this installed if you are from the United Kingdom? as I thought having this information stored on your database is illegal.

 

Please can someone educate me on this as im not sure whats right or wrong.

 

Many thanks in advance

 

Angi

Posted

1) yes it is

 

2) it also will be in the T&C of the cc suppler

 

3) there are tones on this in the forum

Posted

The general rule about CVV is that you can ask for it .. but you can not store it.

 

Ie. you can not write it down and especially you can not store it in the db.

 

The CVV is supposed to only be used in real time.

 

Ie. If you get it from the customer over the phone then its supposed to keyed into the pos machine and processed directly.

 

Ie. if you collect CVV online then its supposed to only be used in real time to verify the transaction through a payment gateway .. and not stored in any way or form.

Posted

Thanks for getting back to me, if that's the case do you know if the contribution does this or does it store the information on your database? as currently is does not say and I dont want to install it if it keeps the information.

 

Many thanks

 

Angi

Posted
Thanks for getting back to me, if that's the case do you know if the contribution does this or does it store the information on your database? as currently is does not say and I dont want to install it if it keeps the information.

 

Many thanks

 

Angi

 

The cvv/cvv2 add-ons/replacments for the standard cc module all store the cvv/cvv2 code in clear breach of Visa and Mastercards Rules.

 

 

Its very important to note that the rules and regulations are very different in regards to the credit card number itself and in regards to the 3 digit CVV/CVV2 security code.

 

 

The only way to accept and use CVV/CVV2 security codes online without breaching the Visa/Mastercard rules is to use a real time online payment gateway service.

 

(The gateway do not save/store the CVV/CVV2 codes they are only used in realtime communication to get an auth-code)

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...