Development Software
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsWeb Site ManagementDevelopment Software

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old January 25th, 2013, 11:55 AM
User6542 User6542 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2013
Posts: 3 User6542 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 42 m 45 sec
Reputation Power: 0
Lightbulb Storing CC Data so that a user can pay anytime like in App Store?

Hi Everyone, I have this huge issue because this is such a complex topic for a beginner like me to understand.

I want my users to be able to place reservations with their account, without having to re-enter their CC details every time. This would work like the app-store, where you press "buy", and after you confirm your order - it's a done deal.

Now, from a technical standpoint (I want my own payment gateway) this shouldn't be an issue if I stored the encrypted CC data in a DB and retrieve it to use with paypal pro.

However from what I read it's always a security issue, and even without that there are apparently strict restrictions and audits required for this to work. For a company located outside of US, this is even more difficult.

I looked into having the payments done in-app using Apples and Android's systems, however apple takes 30% of the cut. If a reservation were ever to come to $1000, it's impossible for this to work.


Honestly, what are my options?

Reply With Quote
  #2  
Old January 25th, 2013, 05:41 PM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,939 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 9 h 13 m 20 sec
Reputation Power: 7053
Use a third party service like Authorize.net's CIM. Do not store the credit card details yourself.

I think you're underestimating the amount of effort and risk involved with storing credit card details. If you are found to be out of compliance, you could face fines of up to $100,000 USD per month.

There are several different levels of compliance that companies must meet depending on how they use credit card details. Using a hosted service like Authorize.net hosted CIM or most of PayPal's offerings (but not PayPal Pro) puts you at the lowest level, which makes it very easy to be in compliance. Storing credit card details yourself puts you at the highest level, which makes compliance very difficult and time consuming.

The document identifying the compliance requirements for the highest compliance level (the one required for you to store credit card details yourself) is about 50 pages long. Among other things, it has requirements like:
* Having designated personnel on-call 24/7 to respond to emergencies
* Having only one primary function per server (ex: you cannot have a web server, database server, mail server, etc. on the same machine)
* Having the ability to quickly roll-back all changes made to your production environment
* Having video cameras monitoring your servers 24/7 and storing the collected video for at least 3 months

(If you use PayPal Pro without storing credit card details, you will be at a middle compliance level.)
__________________
PHP FAQ
How to program a basic, secure login system using PHP

Quote:
Originally Posted by Spad
Ah USB, the only rectangular connector where you have to make 3 attempts before you get it the right way around

Reply With Quote
  #3  
Old January 28th, 2013, 09:02 AM
User6542 User6542 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2013
Posts: 3 User6542 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 42 m 45 sec
Reputation Power: 0
Thanks! Why exactly is using Paypal pro putting me at the middle level?

Reply With Quote
Reply

Viewing: Dev Shed ForumsWeb Site ManagementDevelopment Software > Storing CC Data so that a user can pay anytime like in App Store?

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap