Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

eCommerce Tycoon


You are currently viewing our eCommerce Tycoon as a guest. Please register to participate.
Login



Closed Thread
Receiving credit card details securely
Old 01-08-2008, 05:43 PM Receiving credit card details securely
Junior Talker

Posts: 4
Name: Alan Menzies
Trades: 0
Hi,

I would be most grateful for any suggestions to this scenario:

I have a client that runs a hotel. They want a simple web based form to receive credit card details when people make a booking.

However they do not need (or want) to process the details online - they want to check availability etc. first and then just take a deposit from the card manually.

Is there a secure way to email the CC details from the site to the hotel (e.g. GnuPG), or am I better setting up a database on the server (which is https)?

Many thanks,
Al.
Mingis is offline
View Public Profile
 
 
Register now for full access!
Old 01-08-2008, 06:46 PM Re: Receiving credit card details securely
Skilled Talker

Posts: 59
Name: Dan
Trades: 0
I've done this before and our solution was to use pgp on the server and send the encypted messages via e-mail to the client who had the key to decrypt. Paranoia also led us to remove all sent messages from the server but store the contact details in a database so that if there was a problem we could telphone the customer for payment. This was 1999 though, there are probably better solutions out there nowadays.
Monkey Do is offline
View Public Profile
 
Old 01-08-2008, 09:21 PM Re: Receiving credit card details securely
ADAM Web Design's Avatar
Canadastaninianite

Posts: 5,938
Name: Adam for web page design, not program
Location: Toronto, Ontario, Canada
Trades: 0
The deeper issue here may be what's legal. Look at the laws for your jurisdiction...they may or may not allow storing of credit card numbers or other information. The law on this in Canada, for example, is very grey. It basically is worded in such a way that you "have to take reasonable precautions to ensure that sensitive information is protected" (I got that wording from a civil servant). But what exactly are reasonable precautions? Password protection? PGP? etc.

As far as your specific situation, what you may want to look at isn't actually taking the payment initially, but putting a hold on the card upfront and then collecting the deposit later on the card. The difference between a hold (or an Authorization Only, according to Authorize.Net) is in the steps.

Step 1: Card is checked to see if funds are available.
Step 2: If funds are available, funds are then put on "hold", whereby the funds are allocated to the merchant (in this case, the hotel) but not actually taken off the customer's card. In other words, the transaction isn't actually complete.

Step 3: The hotel checks to see if the room(s) or whatever are available.

If rooms are available, the hotel then completes the transaction and withdraws the funds from the customer's credit card.

If rooms aren't available, the hotel cancels the transaction and for the customer, it's as if the transaction never occurred in the first place.

The advantage of a hold is that the hotel knows the customer can afford to pay for the hotel when they check for availability while the customer doesn't get billed until the hotel confirms availability, so there's no waiting 6 weeks for a chargeback.

Anyway, that's how I'd handle it.
__________________

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
(my blog)


Please login or register to view this content. Registration is FREE
(with proof)

Last edited by ADAM Web Design; 01-08-2008 at 09:22 PM.. Reason: Damn URL.
ADAM Web Design is offline
View Public Profile Visit ADAM Web Design's homepage!
 
Old 01-08-2008, 09:43 PM Re: Receiving credit card details securely
JeremyMiller's Avatar
WT Moderator

Posts: 1,712
Name: Jeremy Miller
Location: Las Vegas, NV
Trades: 0
At the end of November, Authorize.NET released their CIM API. That would probably be great for you here -- you don't store any CC info, but can bill the clients whenever you want.

I wrote a bit of a summary of what it can do, with some notes regarding errors in their documentation at http://www.teratask.com/index.php?pa...horize-net-cim
__________________
Jeremy Miller

Please login or register to view this content. Registration is FREE
JeremyMiller is offline
View Public Profile Visit JeremyMiller's homepage!
 
Old 01-08-2008, 10:19 PM Re: Receiving credit card details securely
ADAM Web Design's Avatar
Canadastaninianite

Posts: 5,938
Name: Adam for web page design, not program
Location: Toronto, Ontario, Canada
Trades: 0
I gotta play with Authorize.Net some more. It's like a roided-up version of the best payment processor here north of the border.
__________________

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
(my blog)


Please login or register to view this content. Registration is FREE
(with proof)
ADAM Web Design is offline
View Public Profile Visit ADAM Web Design's homepage!
 
Closed Thread     « Reply to Receiving credit card details securely
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.15197 seconds with 12 queries