# Yes that's expects when you send credit card number directly. You shouldn't do that to avoid exposing to PCI DSS
# https://stripe.com/docs/security/guide Integration security guide Ensure PCI compliance and secure customer-server communications.