3 ms·
You are responsible for the security of any information on your system. Thus you should want to be PCI DSS compliant even if it is not a requirement. Take a lo
by trizk 16y ago
You are responsible for the security of any information on your system. Thus you should want to be PCI DSS compliant even if it is not a requirement.
Take a look at PayPal Website Payments Pro.
https://www.paypal-business.co.uk/process-online-payments-with-paypal/index.htm https://www.paypal-business.co.uk/process-online-payments-wi...
Why don't you want to use PayPal. Its a pretty safe path to start accepting payments online and you can use their transparent API so they are not visible. Get an account, read their API docs and security best practices for the language of your choice (and in general). Implement an example from the docs on your server and grow it from there. Don't store credit card data on your server and don't cut corners when checking integrity of communication between you and PayPal.
- notyourwork 16y agoPaypal is expensive and I have had too many problems with them to ever consider using them for my business.
- vog 16y agoAlso note that in general, keeping away dubious companies helps both your own reputation and the society as a whole. And PayPal has gained a lot of bad reputation for several reasons. The Wikipedia provides a good summary of the issues: http://en.wikipedia.org/wiki/PayPal#Criticism_and_limitations http://en.wikipedia.org/wiki/PayPal#Criticism_and_limitation...