Storing Customer Payment Cards
This document outlines the best practices for securely storing customer credit card information within the HirePOS system. It emphasises the importance of using a PCI-compliant payment provider, such as Pin Payments, to ensure the safety of sensitive data. Additionally, it provides step-by-step instructions for storing, managing, and destroying customer credit card information.
Using a PCI-Compliant Payment Provider
For secure card storage, we recommend utilising a PCI-compliant payment provider such as Pin Payments.
Get started with Pin Payments:
https://pinpayments.com/get-started/hirepos
Why You Should Switch to Tokenised Card Storage:
https://docs.hirepos.com/en/articles/7491073
Pin Payments Overview — learn about the features:
https://docs.hirepos.com/en/articles/2314049
Importance of Secure Card Storage
To protect your business and your customers, "raw" card details should never be stored in HirePOS. This includes notes, comments, custom fields, documents, or any other free-text areas. Cards should only be stored in a tokenised manner via Pin Payments, ensuring that card numbers are not human-readable and that cards can only be charged through the system.
Integration with HirePOS
Pin Payments is heavily integrated with HirePOS, allowing you to securely store tokenised card details directly from the Customer Overview > Credit Card screen, the Payment screen, and remotely via the Customer Information Form. There is no need to open a separate portal.
Conclusion
By following these guidelines, you can effectively manage customer credit card information in HirePOS, ensuring security and compliance with PCI standards.
