Merchants often misunderstand what data they are allowed to save. This answer clarifies the "Do's and Don'ts" of data storage to prevent severe security violations.
Merchants often misunderstand what data they are allowed to save. This answer clarifies the "Do's and Don'ts" of data storage to prevent severe security violations.
No, you must never store full credit card numbers (PAN) or CVV codes on your own systems. Doing so would make you fully liable for PCI compliance and require a complex security audit.
Instead, you should follow these guidelines:
Do Not Store: Raw credit card numbers or security codes (CVV).
Store Only: The Payment Token returned by the 4Geeks API. You may also store the last 4 digits of the card for display purposes so customers can identify their payment method.
For recurring billing (like in a SaaS platform), you should use the stored Token to initiate future charges. When a customer signs up, you tokenize their card via the API, save the token in your database, and use that token for all subsequent automatic payments.