Kim, thanks for the tip on the module working in 'f', and thanks rstevenson for the tip on the Ceon module. I'll look now into both possibilities.
Just like Kim, we delete the credit card information from the database, (in our case, minutes after we receive the order). That's in addition to the fact that the numbers are not all included in the db to start with, and that we don't keep the information anywhere in written format because we destroy it.
If there is no information to steal, no information can be stolen.
We have decided to process manually credit cards because that has proven to allow us to avoid fraud very effectively. In around 40000 transactions in the last 4 years, we've had only 1 in which somebody used a stolen credit card and we were not able to detect it before we processed the card. We've had many cases, (around 1 in every 2 to 3000 transactions), in which we have been able to detect fraud and that has really confirmed to us we are doing the right way.
Not only have I heard horror stories in regards to Paypal and other 'automatic', 'secure' gateways, but we ourselves once upon a time used to receive payments through Paypal. Guess what! After 6 or 8 months we decided to not use it because of the problems that it was generating, not to mention the cost, and the lack of control.
If you wish more background information about merchant problems with PayPal, just do a search in Google.
Having said that, every method to charge cc has its own problems. In fact, we may even consider using PayPal again because we are thinking of having also an ebay shop. It's usually a matter of balance, and seeing pros and cons. But I still think we are grown up people, and that we are entitled to decide which risks to take, or which assurances to obtain based on our information and reasoning. Isn't that on what our civilized world is supposed to be based on?
I also agree that everybody should try to be PCI complying, among other things because it adds stability to our businesses. However, there are many means to attain that result.
Sorry if I may have sound wordy in this reply. I understand I may have said in my first message something that may have contradicted some people's believes. I hope I haven't sounded too emotional in this replay, and that I haven't offended anyone. However, please understand that these things need to be said and discussed.
One last thing. I really think it is paramount to contribute financially to the community of Zen Cart developers. We all run our business using one of the best e-commerce solutions around and it's the least we can do. I'll make sure that we always donate, and that we are not within the 499 out of 500 that never contributes (I've just read at the Ceon's site: "Only 1 in 500 people donate towards our software, so it would be greatly appreciated - Thanks!"). I imagine the statistics are similalr for Zen Cart, which is really, really sad and unfair, and at the end, very, very bad for our business as well. :shocking: