Collecting The Last 4 Digits Of A Credit Card

  • Sean
    Asked on December 21, 2018 at 4:26 PM

    I just received an email asking me to stop collecting the last 4 digits of a customer’s credit card in the Subscription Cancellation Form I created because I am not encrypting form data (link to form below). I just turned on encryption for that form. Is this sufficient, or should I remove the last four digit question from my form?

    Why are we asking for the last four digits of the credit card number? Because this form will be used by our customers to cancel a recurring subscription. We will use the information from the form to locate their subscription in Stripe and cancel it. Having the last four digits of the credit card number allows us to validate that we have the correct account in Stripe.

    Jotform Thread 1680898 Screenshot
  • Bitia JotForm Support
    Replied on December 21, 2018 at 4:58 PM

    Due to our PCI certification, we are required to deny the collection of credit card details (this includes but not limited to credit card numbers, expiry dates, cvv or credit card codes) on regular forms.

    However, we have other PCI-compliant ways to do this. All you need to do is choose any of the payment processors available in our platform in order to integrate in your forms. You still won't be able to collect credit card details directly though.

    If you only want to collect your customer's payment details and charge them at a later date, you can take advantage of a feature called "Payment Authorization". To learn more, kindly follow this guide on How to Enable Payment Authorization.

    Thank you.