Results 1 to 9 of 9
  1. #1
    Join Date
    Feb 2007
    Posts
    10
    Plugin Contributions
    0

    Default Does Zencart Database save credit card details?

    Hi,

    I'm using website pro and I'm a UK paypal user.

    Just wanted to confirm whether customers details are stored on the zencart database using this module as the card type, expiry date and partial (8 digits) of the card number is shown on the order page.

    So, is the full 16 credit card number stored or is it just the 8 partial numbers?

    I need this information to complete the Privacy Policy.

    Thanks!

  2. #2
    Join Date
    Jan 2009
    Posts
    2,123
    Plugin Contributions
    0

    Default Re: Does Zencart Database save credit card details?

    Only partial numbers are stored on the ZC database.

  3. #3
    Join Date
    Jun 2005
    Location
    Cumbria, UK
    Posts
    10,262
    Plugin Contributions
    3

    Default Re: Does Zencart Database save credit card details?

    Before you even think about storing CC details - even partial details - make sure you are aware of PCI compliance.
    19 years a Zencart User

  4. #4
    Join Date
    May 2009
    Posts
    12
    Plugin Contributions
    0

    Default Re: Does Zencart Database save credit card details?

    Quote Originally Posted by schoolboy View Post
    Before you even think about storing CC details - even partial details - make sure you are aware of PCI compliance.
    Hi

    Is there any way of NOT keeping any of the CC numbers to avoid the need for PCI?

    Cheers

    Adam

  5. #5
    Join Date
    Apr 2006
    Location
    London, UK
    Posts
    10,569
    Plugin Contributions
    25

    Default Re: Does Zencart Database save credit card details?

    Quote Originally Posted by dashequestrian View Post
    Is there any way of NOT keeping any of the CC numbers to avoid the need for PCI?
    Fear not. Unless Schoolboy has knowledge of some specific change to the PCI requirements, I think you'll find that Zen Cart's core code has been very carefully crafted to ensure compliance.

    And there are Zen Carts out there in the wild that have undergone external auditing to verify their individual compliance.
    Kuroi Web Design and Development | Twitter

    (Questions answered in the forum only - so that any forum member can benefit - not by personal message)

  6. #6
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: Does Zencart Database save credit card details?

    even if you dont store cards,
    If you use a servce such as linkpoint they still require pci complaince
    Zen cart PCI compliant Hosting

  7. #7
    Join Date
    Jul 2005
    Posts
    12
    Plugin Contributions
    0

    Default Re: Does Zencart Database save credit card details?

    It looks like the PCI DSS compliance must have changed as the self-assessment questionnaire now includes an eligibility clause that asks you to confirm that 'Merchant does not store any cardholder data in electronic format' (see attached partial screen shot of the questionnaire).

    Any thoughts/comments anyone?
    Attached Images Attached Images  

  8. #8
    Join Date
    Apr 2006
    Location
    London, UK
    Posts
    10,569
    Plugin Contributions
    25

    Default Re: Does Zencart Database save credit card details?

    Quote Originally Posted by squashrick View Post
    It looks like the PCI DSS compliance must have changed as the self-assessment questionnaire now includes an eligibility clause that asks you to confirm that 'Merchant does not store any cardholder data in electronic format' (see attached partial screen shot of the questionnaire).

    Any thoughts/comments anyone?
    Those questions are not assessing PCI DSS compliance. They're assessing which assessment path must be taken. Most retail stores don't collect or cardholder information electronically. Unless you sign up for a loyalty scheme, you pay your money and walk away with your purchases, so they don't need it.

    Online stores usually have to store some cardholder information. Names and addresses are useful for delivery, and in case of payment or stock query. This doesn't disqualify them from PCI compliance. Just means that they have to take steps to protect that data and therefore the short version of the self-assessment form isn't appropriate.
    Kuroi Web Design and Development | Twitter

    (Questions answered in the forum only - so that any forum member can benefit - not by personal message)

  9. #9
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: Does Zencart Database save credit card details?

    as long as you are NOT using the STOCK CC module ( shouldnt be using this in the first place )
    and you didnt actually hit the store cc details using authorize net ( also NOT advisable ) then you are NOT storing numbers

    therefor the short form is acceptable
    Zen cart PCI compliant Hosting

 

 

Similar Threads

  1. v151 save credit card
    By salvo72 in forum Addon Payment Modules
    Replies: 6
    Last Post: 24 Feb 2014, 11:19 PM
  2. Replies: 5
    Last Post: 29 Nov 2010, 06:28 AM
  3. Can I save Credit Card info for future orders?
    By mitch_h in forum General Questions
    Replies: 1
    Last Post: 22 Jun 2009, 09:46 PM
  4. does zencart authomatically check credit card validity
    By needslotsofhelp in forum Addon Payment Modules
    Replies: 2
    Last Post: 17 Sep 2006, 02:29 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR