Such a service would act similar to a payment gateway, but not actually authorize or charge the card, and would make our lives easier when it comes to PCI compliance.
Our clients want us to hold onto the card information but not act on it. A month later or so, if the customer doesn't hold up their end, they use the card details to charge the card by entering the information into your standard retail card machine. Now for our clients to become PCI compliant, we, who are storing the credit card information, need to do so in a PCI compliant fashion. As far as I know our options are:
- become PCI compliant ourselves
- get our clients to switch from us as the data-store service to a new service
With either:
2.1: the new service being a paypal or similar, where they would have to authorize and delayed capture the funds (at a significant additional cost to them per month)
2.2: the new service being a remote data store only as described above (at a small additional cost to them per month)
Any insights welcome, thanks.