Page 1 of 1

Credit Card Storage

Posted: Wed Jun 01, 2016 4:14 pm
by dandersonMLT
I have a client which I inherited. Currently they are seeing the following message on their dashboard:
"Your store encryption key is missing or invalid, and you have not disabled storage of card data. You should either set the encryption key or disable credit card storage."

I'm thinking someone might have accidentally enabled the credit card storage checkbox as they did not see this previously.

However, before turning off credit card storage, I want to make sure there isn't a reason they would need to have this enabled.

Is there any good reason to store this data other than recurring billing or saving credit card numbers on file for easy checkout?
I assume they can still process refunds etc without storing this data since all of the transactions go through authorize.net.

I just want to get the pros/cons of storing vs not storing the credit card data so I can explain each to the customer and let them make the appropriate decision.

Thanks

Re: Credit Card Storage

Posted: Thu Jun 02, 2016 2:50 am
by Katie
Is there any good reason to store this data other than recurring billing or saving credit card numbers on file for easy checkout?
I assume they can still process refunds etc without storing this data since all of the transactions go through authorize.net.
A lot of this depends on the gateway. Most gateways require full credit card details and expiration date to do a refund. So in most cases, you will need to store credit card data to do a refund via Able. There are safer alternatives though. Using an Authorize only mode for your payments should reduce the number of refunds for new orders because you can void a new transaction instead. You can also process the refund directly through the gateway and update Able with the information.

In the case of using "stored credit card profiles", which is only supported by Authorize.net CIM, you can still do post-order processing without having Able store the credit card. In the case of any cc being stored with Anet CIM, the gateway is responsible for keeping that sensitive information on their side. So, regardless of you decision to store CC's within Able, any "stored profile" processed via Anet CIM is never stored with us - only Authorize.net

Personally, I believe it's always better to never save credit cards. If you do, make sure that you are satisfying the PA-DSS (PCI) requirements and that you are setting an encryption key.

For more information on PCI - see http://www.ablecommerce.com/Able_Gold_R11_PCI_Guide.pdf

Thanks,
Katie