ParentFull threadrohithkp·Any card details that are being stored in the merchant's database need to be tokenised. It applies to all entities who are retrieving card details from customers, irrespective of PCI/DSS compliance.View on HN