Deleting Stored Credit Card Numbers

Erin F. shared this question 2 months ago
Answered

How do we delete stored credit card numbers out of the system? We don't wish to store them in the system to begin with, and are concerned that there is no way to remove them.

Comments (4)

photo
1

There is no way to delete the card info.

If you use Global Payments (Open Edge) as your merchant credit card processing through IO, you can recharge a customer's credit card. A whole credit card number is not saved, but Global Payments does save a "token" so that a card can be recharged or credited as well.

photo
1

I understand why the option is there that wasn't my question. We don't recharge customers cards, and we never will. It doesn't seem like a great idea to keep this data in our system *forever*. There are policies in PCI compliance that this would violate, making every IO user that uses Global Payments out of compliance automatically. This should be an option.

photo
1

The Tokens are only good for so long, let's say you have a token and try to recharge the same card 6 months later, that token may have already expired with Global and it won't go through. So even when the CC information is saved this does not mean that it will work due to the token expiring. I hope this helps.

photo
1

It does not, as it does not solve the request. I am contacting Global Payments and working with them to determine how this should be possible. The information should not remain in the system.

photo
1

Global Payments says that this is something that IO is responsible for and they have no control over what IO stores on their website. This is an issue.

photo
1

I will put this in with a developer and see what can be done!

photo
1

The developer has turned on the setting that save the token, this will no longer save them.

photo
1

This change did nothing. token is still being saved for all CC payments.

photo
1

Do you have a lead where this change didn't work?

photo
1

Each and every lead that has received a credit card payment since this "change" was made. The most recent being Walnut Capital Management. Do you need me to send a link or are you able to access it?

photo
1

I have let the developers know.

photo
photo
1

Per Developer:

As noted before, updating this setting stops Cards from being stored going forward. The one in question was created on February 5, 2024 1:13:11 PM when the payment was taken on lead https://rental.software/account/#/leads/23311077 at that same corresponding time.

If they want, I can remove this one from being displayed, as well as any others, but again turning the setting off just prevents new ones from being saved. Those that were already save prior are still going to show.

photo
1

The event I am referring to was created on March 12 and payment was made on March 12, so maybe you’re looking at one of our older events with the same client? I understand how technology works enough to know not to look at events that were created before the change was made. Each and every credit card payment that has been made since these changes were implemented have still stored the credit card token in the system. Try to give me a little more credit than this.

photo
1

The lead you gave us was lead 39980001 and it was a copied lead which copied the payment info as well, please let us know if this continues with new leads going forward.

photo
Leave a Comment
 
Attach a file