7
9 Comments

How are bootstrapped startups following PCI DSS standards for storing customer card details?

For payments page, we integrate with third party, and make users to go out of our application to be low risk and not worry about PCI DSS standards. But, we want the card details to be stored for the user, which again makes us to follow PCI DSS standards. How are small startups doing it?

on October 6, 2022
  1. 1

    Use Stripe and they'll handle everything, users won't have to enter their card details again and it does everything you need ... no need to worry about PCI or anything.

  2. 1

    I would definitely use Stripe or Paddle and never worry about storing card details. You store a user id for either of these services and there card information is stored there, so you should still be able to get the same UX you are looking for just with out any of the risk.

  3. 1

    What benefit do YOUR CUSTOMERS get from you storing their credit card #? If you don't have a good answer to this question, then, you're setting yourself up to a huge amount of trouble for nothing.

    1. 1

      I basically don't want my users to re-enter card details each time of their purchase. And I would be happy to NOT store any of their credit card info. One other thing out of my plate, makes me worry less.

      1. 1

        Stripe has solutions for that. I'm pretty sure Paypal and other payment gateways do too.

      2. 1

        Save payment details during payment with Stripe. Reuse later.

        We are using this at ExportData

  4. 1

    Your providor should offer tokenisation on the payment gateway to do this.

    1. 1

      What's that? Googling now.