If this gets any traction I will need to fight even harder to opt out.
I yearn for the day I can have one off transaction codes.
If this gets any traction I will need to fight even harder to opt out.
I yearn for the day I can have one off transaction codes.
If you as a retailer have your checkout page set up properly, the actual card data never hits your server.
But if I only supplied a token. with a value I determined I would not have to worry.
You mean the username and password for the site you've logged on to? ;-)
A temporary card number can be configured with a fixed value you specify; most banks provide the service for free.
You can also buy a Visa or AmEx gift card, and use that.
Most of the major sites do store cards information and they go through the annoying PCI DSS compliance to be allowed to do just that.
The extra $16k of float that Stripe requires is not worth it for me. This is why we have credit card numbers come to our server.
We're working to speed this up for other countries!
We have those (at least in America), and have for many years. Services like "ShopSafe".
They also create many hassles and headaches. Can make returns difficult, validation difficult (please show the card used, what, it's a virtual card?), and the rigor may not be great (reoccurring charges on "invalidated" numbers, etc).
I have never seen a service like that - so (I think) it is mainly on your side of the pond.
For debit cards, the dispute process is called Reg E and the consumer is out the money for a month or more until decided in their favor. So there's risk in storing a debit card number.
- not 100% true- see "fraud Liability Shift topics" Your card Issuer gets it if it's an EMV (ie chip was dipped) card-present transaction, merchant gets the liability if it was online or over the phone-Exception being if 3DS is used. Fraud is ultimately payed for either by your bank or by the merchant.
I hardly ever use cash anymore so my bank statements have a lot of action going on.
How closely do you monitor those?
It doesn't truly benefit you, hurts the merchant, increases prices for everyone.
People love zero liability so that's where we are and we all have to pay for it.
edit: for clarification, yes for in store, my card is the same card and I cant easily generate a new number to swipe at a POS, but online & via app I manage 1-time payments (generated card number shuts off after successful charge) or 'Merchant Locked' card numbers that will only work at that merchant and which I can shut off any time.
With this i'm much more comfortable giving out my CC to a shady/basic website if i'm concerned. (ie buying mulch from the company's barebones website)