Need to collect Credit Card Numbers for use in a separate software to process payments

  • MWiede79
    Asked on February 9, 2021 at 4:46 PM

    We got a notification that we could not collect credit card numbers in an authorization form that we created due to suspicious phishing activity. Our form is called WDPS - New Authorization From under the account for MWiede79.

    We are NOT making payments through this form and are NOT needing to authorize the card number - it is simply an authorization form so that we can collect payments through our 3rd party preschool software. We are only collecting the card number & exp. date so that we can key it into our preschool software which handles the credit card charges.

    Please advise us on what we need to do in order to prevent our account from being suspended.

    Thank you -

    Anna Hazelrigg

  • jonathan
    Replied on February 9, 2021 at 8:26 PM

    Hi Anna,

    We apologize for inconvenience. I understand that you intend not to use the form for payment purposes but for authorization process only.

    But please note that there were plain text fields in your form that capture credit card account data (i.e. card name/number, expiry date). These options on your form were not PCI compliant.

    1612920120 60233538a2339 zzz 2021 02 10 Screenshot 10

    The form also violate the Terms of Use.

    Due to our PCI certification, we are required to deny the collection of credit card details on regular forms.

    However, we have other PCI-compliant ways to do this. All you need to do is choose any of the payment processors available in our platform in order to integrate in your forms. You still won't be able to collect credit card details directly though.

    If you only want to collect your customer's payment details and charge them at a later date, you can take advantage of a feature called "Payment Authorization". To learn more, kindly follow this guide on How to Enable Payment Authorization.

    I recommend you immediately remove those credit card fields in your form to avoid getting the account and forms disabled due to suspicious phishing form.

    Please let us know if you need further assistance.