#nikhil_05327
1 messages · Page 1 of 1 (latest)
Hello! We'll be with you shortly. Below are links to other discussions we've had with you in the past week in case you want to review that information. If your question is related to one of these previous discussions, please provide a comprehensive summary of the current state and what you need help with now. We help many users simultaneously, so a summary allows us to resolve your issue as soon as possible.
- nikhil_05327, 5 days ago, 9 messages
- nikhil_05327, 6 days ago, 4 messages
Hi there, is your question related to Stripe integration?
Ok, Stripe won't expose card details to users.
I believe there might be a misunderstanding. My query is regarding the creation of a solution through the integration of multiple gateways for card payment mode. Specifically, in server-to-server integration, if I need to store the card details of the user, am I allowed to do so?
No
why ? , do i need some liscence for this ?
https://stripe.com/docs/security/guide#validating-pci-compliance you'll need to be SAQ D compilant if you want to pass credit card info directly to Stripe. It's highly discouraged.
if i becomes PCI compliant , then can i store card details ?
I'm unable to answer this question, you'll need to check with PCI Security Standards Council directly.
Hey @pseudo elbow so I will give you some context.
We are a payment orchestrator, which means we connect multiple payment gateways/psp on our checkout, and seamless call psp APIs for processing transactions. We are a product like primer.io or corefy, and we connect with multiple connectors (including stripe). Merchants then connect to us via their secret_key and we process txns to stripe through server APIs
does it make the case clear?
Stripe is connected to Primer, Hyperswitch and Corefy under similar model. So I want to know what documents would you need to enable card data handling on behalf of businesses
We are PCI compliant
OK. But still whether you can or you should save the customer's card details in your server isn't a question to Stripe.
If you are SAQ D compliant then you can pass credit card info directly to Stripe .
okay got it, so I need to produce the compliance certificate to stripe and we will be good to go?
https://dashboard.stripe.com/settings/compliance you can configure your PCI compliance here \
Sign in to the Stripe Dashboard to manage business payments and operations in your account. Manage payments and refunds, respond to disputes and more.
yes we are level 1 compliant for PCIDSS and SAQD
https://dashboard.stripe.com/settings/compliance I beleive there's a link in this page for you to get in touch with support to submit your application for passing credit card info directly to Stripe.
Sign in to the Stripe Dashboard to manage business payments and operations in your account. Manage payments and refunds, respond to disputes and more.