A
A
Alexander Maslov2014-03-07 11:46:52
Payment cards
Alexander Maslov, 2014-03-07 11:46:52

Is it possible to store credit card data on the server?

For example, in order to withdraw money to users? If not, then why and where can I read about it? What are the potential problems? Is there a difference whether to store data on a server in the Russian Federation or outside?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
A
Andrew, 2014-03-07
@drakmail

Without any problems, you can store and process only the PAN mask.
If you want to store full card data (without cvc, cvv - no one will allow you to store this, even with a certificate), you need to have a PCI DSS certificate.
You can also store data only in certain places - there are hostings specialized for this business, but they cost a lot of money. There are no such hosters in Russia.
Passing certification is a huge (sorry) crap. Firstly, it also costs money (100+ tr.), secondly, your application will be attacked and checked for all possible vulnerabilities, you must log all user actions and a bunch of other things. Plus, if you fail the certification, then re-passing is also paid.
Google about pci dss

V
v_prom, 2014-03-07
@v_prom

Look for privacy laws. Most likely it is possible, only with the consent of users.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question