My apologies for not being clear.
Rest assured we have had extensive discussions with our CPA, Attorneys, and the cc processor to ensure we are doing the "right stuff". I understand you are trying to counsel me to best practices. I appreciate that.
So just to we're 100% clear. I install, host, and configure the software for the client. The client receives the order, ships from their stock, and bills the consumer. Since the physical server is in a seperate location from the client, they've either got to use Authorize.net or the offline cc module.
Right now they do not want to use Authorize.net because their existing brick and mortar business uses a different solution and they do want to have another. We experienced a problem twice where the middle digit email did not reach them, a total of 3 orders. However once they hit the order volumes they expect we could potentially lose a lot more middle digit emails that would require a lot of embarrassing phone calls to the consumers that purchased.
So what I'm looking to assist them with is finding a way to ensure they they do not lose their customers credit-card information. I am NOT going to circumvent the system by storing the whole number. I'm not taking that liability. So how do I help them with this? That's the advice I really need.
Is there an outside solution that I can easily get them the cc information from their store in a more reliable manner? For example, could use us Authorize.net to securely pass the cc information at the point of order execution and still use their existing cc processor?