Forum Moderators: buckworks

Message Too Old, No Replies

PCI compliance - Phone Orders

How are other e-tailers handling phone orders?

         

LizaJane

9:19 pm on Jun 13, 2010 (gmt 0)

10+ Year Member



Assuming my online website / shopping cart / gateway ect are PCI compliant, how to deal with phone orders? I have come up with 3 ideas. Would either be PCI compliant?

1- Write down the payment info - Enter payment into virtual terminal by end of day - cross shred payment info by end of day.

2- Enter the payment information directly into my merchant accounts virtual terminal as I take the phone order - no CC info written down in house

3- We enter the phone order on-line via our shopping cart while on phone with customer - Again - no CC info written down in house)

How are other e-tailers handling phone orders?

Any help would be appreciated.

wyweb

9:28 pm on Jun 13, 2010 (gmt 0)



Excellent question.

Not just phone orders either. I've had customers wanting to send me their CC number by email as well.

I've only done this once. Customer was insistent/risk of losing fairly large sale, etc... I was uncomfortable with it then and I'm uncomfortable with the idea now.

I have numerous payment methods on all of my sites. There is never any reason for me to handle card numbers personally. My philosophy has always been to direct them to proper payment procedure onsite (except in that one case).

I don't want to be on the list of suspects if their identity gets stolen and CC gets misused.

MrHard

12:22 am on Jun 14, 2010 (gmt 0)



Locking order info in a cabinet only accessible to qualified individuals is PCI compliant, I think.

Rugles

8:46 pm on Jun 14, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Locking order info in a cabinet only accessible to qualified individuals is PCI compliant, I think.


I think you are correct.

Demaestro

8:55 pm on Jun 14, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm not an e-tailer but I have clients that are. What I have done in the past is create a simple form behind a secure login that they can go to. It is tied to the gateway just like the online order form but it allows them to enter product id/sku on the fly without a bunch of "add to cart" logic.

Staff member gets a call for a phone order, they login, fill out the form, enter the CC info and submit and it is treated as any other order from then on, but it is flagged in the DB as being a phone in and it is good to record which employee logged in and did the order.

You can also ask your gateway, I know some have a Phone order form that you can login and submit.