Assuming my online website / shopping cart / gateway ect are PCI compliant, how to deal with phone orders? I have come up with 3 ideas. Would either be PCI compliant?
1- Write down the payment info - Enter payment into virtual terminal by end of day - cross shred payment info by end of day.
2- Enter the payment information directly into my merchant accounts virtual terminal as I take the phone order - no CC info written down in house
3- We enter the phone order on-line via our shopping cart while on phone with customer - Again - no CC info written down in house)
How are other e-tailers handling phone orders?
Any help would be appreciated.