15 ms·
Indian online merchants cannot store credit card information from 2022
- teleforce 5y agoKudos to Indian govt, this should be the default for any e-commerce websites. I have to resort to PayPal to avoid my credit card being stored in the e-commerce merchant sites but some of sites do not support PayPal. It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account.
- seesawtron 5y ago>It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account. If you are in the EU, in my experience with the GDPR, this is not allowed. The e-commerce merchant must allow users to have the option to remove this information. PS: I had to file a formal complaint against a telecom company to have this resolved.
- pmontra 5y agoUnless they have to store those details for N years because of local laws. Obviously they could hide old cards in the UI and/or implement a soft delete.
- vivekv 5y agoIndian merchants have to support UPI - another payment mechanism which is secure. I tend to use that in most places so that I dont have to store my card details.
- rg111 5y agoDo you have to use your cellphone number to avail UPI services? If that is the case, then it is not for me.
- illegalmemory 5y agoI have created UPI ID directly with bank and there is no need of any third party app. It can be used to transfer money directly without sharing bank and card details.
- captn3m0 5y agoYou can receive money over UPI without a smartphone. But sending money actively (as a customer) from a personal bank account is not possible afaik.
- samarthr1 5y agoWhat no? My business, and my family business both run off the ability to make upi payments by just giving a UPI Id, amount and everything your pin. Quite often, i settle accounts with my friends over UPI. One of them pays for coffee, and i just upi him his share. And we work with our own personal savings accounts.
- echlipse 5y agoYou need to have a bank account to use UPI. Banks require a phone number afaik.
- rg111 5y ago
- mkbkn 5y ago> It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account. Strange. Amazon India allows deleting the stored card details.
- konschubert 5y agoBe careful if you pay with PayPal in foreign currency, they have super-bad conversion rates that they try to trick you into accepting. You can turn this off if you can see through their dark patterns. But as a rule of thumb, PayPal is a scammy company that I now try to avoid where I can.
- blntechie 5y agoI have been burned couple of times by them. I thought it's a genuine and useful feature. First, they offered a poor conversion rate. Second, they said they will charge in INR and hence no further markup by banks which was an outright lie as they charged in INR from PayPal Singapore which applied foreign markup anyway by the bank. So I paid double markup. It's basically a scam.
- pronlover723 5y agopaypal is worse than credit card for me. For one the paypal always shares your paypal email address where as when I pay with credit card I always give a different email address to every merchant.
- oefrha 5y agoDoes PayPal still share email addresses? I accept donations on PayPal for my open source projects, and starting from a few months ago I can no longer see people’s email addresses, which have been replaced by links to an internal chat system.
- usr1106 5y agoWhy I needed to change the email address I use for paypal repeatedly. Now I have mostly stopped to use paypal. It's full of dark patterns like making authorization recurring without giving me an option. Need to cancel authorization for future payments manually afterwards. I guess in the wost case this could be racy, another payment before I cancel.
- zerocount 5y agoI agree. I had to do the PayPal thing with my Visible phone service because I couldn't delete an old card. Luckily PayPal doesn't require me to have anything linked just to have an account. Why do companies want to store this data any way?
- _hyn3 5y agoHow would recurring transactions or metered billing work? Does this only apply to merchants or providers that are not PCI-DSS compliant and cannot safely store cardholder data?
- jetsetgo 5y agoIt won't. Like it should be. No one should be able to take your money without your consent.
- deleted 5y ago[deleted]
- LammyL 5y agoThis change just says that only the card issuer or card network can store the card number (PAN). Everyone else in the processing chain can only store card tokens. This isn’t a surprising change and was always going to be the future of PCI compliance.
- option_greek 5y agoThere is no exception for recurring payments. Also unfortunately this applies to all online merchants and Payment aggregators regardless of size and certifications. So as it stands a separate auth is needed for each transaction which is completely regressive and precludes a lot of convenience use cases. My guess is that they are doing this to make Upi more convenient in comparison. But I won't be surprised if its just another short sighted we know it all mentality decision from the regulator who has a history of u-turns. Edit: Looks like they do allow card tokenization (not part of original proposal) which should address a lot of use cases Here is the commentary about the original proposal: https://www.businessinsider.in/finance/banks/news/rbi-wants-you-to-memorise-all-your-debit-and-credit-card-numbers/articleshow/81186570.cms https://www.businessinsider.in/finance/banks/news/rbi-wants-... Here is the one after push back from industry (Which allows tokenization): https://timesofindia.indiatimes.com/business/india-business/e-tailers-cant-store-your-card-data-says-rbi/articleshow/85581684.cms https://timesofindia.indiatimes.com/business/india-business/...
- 5y ago
- blueblisters 5y agoIs the RBI deliberately trying to handicap credit cards in India? The decision to make recurring payments impossible, followed by having to enter card information every time I do an online transaction is making for a very frustrating experience. The justification for these decisions is always "consumer interest" but how is making consumers jump through hoops to do transact online in consumer interest? I wish the industry was more co-ordinated in lobbying against these crazy policies Edit: A couple of replies below that say they don't mind authorizing subscriptions/recurring charges every time. I respect that view but I think people underestimate how much friction it adds if a business needs to ask your for permission every time to renew. Consumers are forgetful. They may not be available to authorize a payment when it's time to renew. Subscriptions reduce transaction costs, give businesses a predictable stream of income and allow consumers continued access to services without having to remember to renew it. If you don't believe me, just look at the data and anecdotes posted by tech journalists and software devs on twitter - it's a shitshow. If a businesses make cancellation hard, the right policy would have been to allow consumers to "stop" charge from the card issuer's website or app - not ask consumers to approve a charge everytime it happens.
- deleted 5y ago[deleted]
- paxys 5y agoIf you'd bother to read the article (or heck the first two lines of the article) you'll see that this rule does not mean you'll have to re-enter your credit card info on every order.
- kranner 5y agoFrom the HN guidelines: > Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that."
- vlovich123 5y agoI would love to be able to have to proactively authorize every single recurring purchase via a tap on my phone. If I have enough that I’m being overwhelmed there’s a good chance I’m not tracking my purchases very well and there could even be fraud I’m missing. There’s some use-cases maybe where automatic billing is required but the vast majority would do better to need to prompt the user.
- neya 5y agoThis is actually a good thing. Think of it like Apple's email masking service - Merchants can only store a tokenized version of your credit card instead of the real card details. I say this is a good thing after having worked with many E-Commerce shops in India as a consultant. Most of them barely know a thing about security, let alone about PCI DSS compliance. I have worked with shops that stored the entire credit card number in PLAIN TEXT!. Not just credit cards, even their users' passwords. This also explains why many of them got and still get hacked from time to time. Even credit card processors got hacked due to this. Lot of shitty ones in the Indian market actually. The root cause of this, not to cause language flame wars here, but is most of the shops use script kiddos with just basic PHP knowledge. Bare minimum, they're recent fresh college grads who just know how to consume data from a form using PHP using GET and POST, that's it. Most of the code I've worked with just consumes this directly instead of stripping/processing it and end up introducing SQL injection attacks. Atleast, if they used a framework, this would be provided by default for free, but many of the developers hardly know about even MVC. (As an aside) - As a personal mission, I started touring around the country teaching college kids for free about basics of web development, security, etc. But, still, I have a long way to go. Well folks, that's it for today's note on why this was a good move. Have a nice day! Edit: Some of the recent hacks that were not made public widescale like they should've been: 1. Domino's Pizza India (Yes, the international pizza chain) 2. BigBasket (Largest online grocery ordering App) 3. PayTm (One of the largest, if not the largest digital payments app in India)
- paxys 5y agoThat's a weird generalization. Yes there are terrible, insecure e-commerce sites in India, the same as there are in the USA and everywhere else on the planet. India is also the top 7-8 e-commerce market in the world. Large local apps in the space have valuations in the tens of billions of dollars, and all major global players like Amazon and Walmart are involved in the country as well. These $100B in annual sales aren't processed by script kiddies, it's a very large and mature industry.
- deathtrader666 5y agoYes, but large valuations don't correlate with better security practices.. Obviously the person above isn't talking about Amazon or Walmart when referring to "script kiddies". Of the nearly 45-50 contract jobs I've seen, a lot of them use pirated WP or Magento plugins, and plain text storage of sensitive content.
- noduerme 5y agoSo, in the early days of online retail, I built shopping carts that stored credit card numbers in the business's database and connected directly with a credit card gateway (not a provider like Stripe). By around 2006 it became clear that this was insanely dangerous to do. Every merchant could not be storing a database of their customers' credit card numbers. I don't know if it's actually illegal to do online card processing this way in the US now, but no card company would work with you if you did. So my takeaway from this is that, the fact that card companies are still accepting "card not present" style transactions from online retailers in India means they have been willing up to this point to tolerate a large amount of fraud and hacking in order to tap the market. The logical next step for them is to limit the number of data sources storing the card numbers and customer data themselves. Whether this comes in the form of a government decree or the slow moving of the card companies away from accepting these kinds of transactions, the change is inevitable. Local hosting and locally managed databases are no place for credit card numbers to be stored.
- beebeepka 5y agoConvenience Vs security. All in all, looks like a good thing
- Abishek_Muthian 5y agoGreat, I'd also like if the merchants were forced to not message via WhatsApp; From couriers to securities every business in India expects that you have WhatsApp and are willing to communicate with them through it.
- wtmt 5y agoI just tell all of them that I don’t have or use WhatsApp, and that’s true. They wouldn’t be able to send anything over WhatsApp since my number was never registered with that platform. Those who want my business will have to abide by my preferences.
- Abishek_Muthian 5y agoI've had customer service personal change their tone towards me after I tell them that I don't use WhatsApp and requested them to send an email instead, They seem to take it as a personal insult (or) Couldn't believe that someone couldn't have WhatsApp.
- diebeforei485 5y agoSomething I learned in college - not all countries have the same laws as the US where it's easy to dispute a charge and the burden of proof is with the merchant. If India is one of those places where the burden of proof is on the customer, and it's difficult to dispute charges, it makes sense to tokenize things.
- mwnn 5y agoYes. On forums and online IM groups you'd find plenty of people suggesting "raise a chargeback" without realising it means nothing in India. It's just a gesture. Merchant can just deny the charge back and that's it, your credit card provider is done you are charged.
- vivekv 5y agoThe burden of proof in India is with the merchant. Proof of transaction has to be provided (invoice etc.,)
- frupert52 5y agoThe rules around chargebacks et al are dictated by the card scheme and remain the same regardless of country the merchant is operating in or car holder is transacting in. How this translates on the ground would be the primary point of difference to other countries.
- flak48 5y agoI've filed a chargeback before in India, the burden of proof was on the merchant at that time. Maybe I got lucky with my card issuer.
- ratww 5y agoDifferent banks/card issuers have different rules too.
- unmole 5y agoDisputing transactions is very simple in India. The transaction notification email/sms itself usually contains a URL to dispute the transaction.
- nicolinox 5y agoI found the approach of disposable virtual card numbers (Visa and Mastercard) that Revolut is giving to each app owner for free is amazing. This number (always different) can be autopopulated from a browser plugin during checkout from the PC and has a very smooth user experience. I don't need to take a card out of my wallet or open the smartphone app to do this. I am happy and regulator is happy too, in this case.
- supernova87a 5y agoI'm interested to know what level of "cannot store" the info is implemented? Or is it mediated by a 3rd party company / algorithm that sanitizes the data but to a certain amount that some association can still be done? For example, can the customer's credit card be anonymized but still tracked to know that the same credit card is used on 2 different transactions, for example? E.g. if I wanted to give the customer only 1 special offer per credit card number, is that possible for the retailer to tell? Or is it even more sanitized such that every single transaction gets a different hashing? How do refunds get issued if the number can't be stored and presumably you don't want the retailer to have the backwards decoding to be possible?
- vinay_ys 5y agoFor card-linked offer constructs you can infer the issuer based on first 4 digits (bin number) and actually store last 4 digits and name on card.
- niyaven 5y agoDisclosure: I work for a fintech in India, specialized in card payment. It seems here people see this rule as "merchants can't store card numbers any more". This is actually a lot more than that, this is the new rule: you cannot store card numbers for recurring payment. Even if you are PCI-DSS compliant. Even if you are audited by the RBI. Even if you're sponsored by a bank. The only way to store a Visa number is to use the Visa tokenization service. Now if you know a bit of the card payment industry, you will know that you need the card number just to process the payment, the refund, etc. So you still have to store the card number. And you can. You just can't use it for recurring payment any more. My personal take: Giving full control to Visa and Mastercard over their card numbers for recurring payment seems to be a nice transfer of power to these two giants. But the time scale has been very short (a few months only). So practically, most recurring card payments will stop working or be illegal in two weeks. This is will more or less break existing subscriptions working with cards. India (the RBI at least) has been in a campaign for independence in the payment infrastructure. American Express[0], Diners[1], Mastercard[2] have been banned in India. Diners' ban has been lifted now, but still. Rupay is a failure with a market share of 0.34%[3] (in comparison UPI is at 37.73%), in spite of having ZERO MDR on debit transactions[4]. This change is not for the sake of security. You can have the best firewalls, cutting-edge HSM, security team and pass 12 audits a year. You will be allowed to save these card numbers but you won't be able to authorized to use it for recurring payments. This is just a move against cards, and to promote UPI instead. By making recurring card payment a hindrance, more people will transition to UPI. [0] https://www.americanexpress.com/en-in/company/notice/rbi-important-update/index.html https://www.americanexpress.com/en-in/company/notice/rbi-imp... [1] https://www.reuters.com/article/india-banking-american-express/rbi-bans-amex-diners-club-from-issuing-new-cards-for-violating-data-rules-idINKBN2CA26T https://www.reuters.com/article/india-banking-american-expre... [2] https://westfaironline.com/138440/mastercard-banned-from-new-card-issuances-in-india/ https://westfaironline.com/138440/mastercard-banned-from-new... [3] https://www.npci.org.in/PDF/npci/statics/RETAIL-PAYMENTS-STATISTICS-Nov-21.xlsx https://www.npci.org.in/PDF/npci/statics/RETAIL-PAYMENTS-STA... [4] https://economictimes.indiatimes.com/opinion/et-editorial/stop-discrimination-against-rupay/articleshow/87724175.cms?from=mdr https://economictimes.indiatimes.com/opinion/et-editorial/st...
- spikengineer 5y ago
- kgdinesh 5y agoI see the US Model as "Optimistic". Let the transactions through and fight back fraud with a strong chargeback mechanism. Whereas the Indian Model is "Pessimistic". Put in as much checks as possible to reduce the rate of fraud before the transaction has even completed. Thoughts?
- aniforprez 5y agoI love it. The optimistic model forces me to be hyper aware of all my banking activities and know when fraud happens retroactively. All the Indian regulations mean I effectively don't have to worry as much unless something serious happens. CC stolen? I don't care they won't have the pin or the secure pin used for online transactions so it's useless and I can just close the card on the banking website. Mobile phone stolen? They won't have the pin to do UPI transactions so they can sell my phone but not have access to any of my banking activities. It's a total Erin. This new regulation helps prevent my card info from getting leaked by all these cheap sites with intern developers
- 2Gkashmiri 5y agoyesterday saw a family member get an sms "your jio mobile e-kyc is pending. please call 6006xxxxxx number to get your e-kyc done so that there is no disruption to your service". this came after trai decided to https://telecom.economictimes.indiatimes.com/news/trai-pushes-for-e-kyc-for-existing-mobile-users-too/56736637 https://telecom.economictimes.indiatimes.com/news/trai-pushe... this means, anyone who read the news understood this was going to happen and scammers put their numbers and sent out sms. any unsuspecting user would just call them whereby they would ask their aadhar card, pan card, otp and you are fucked.
- alkonaut 5y agoI always enter my card details (unless direct bank transfer is available, which is becoming pretty popular lyckily). But I never found the idea that a saved credit card number (23 digits) would make a shopping experience so much convenient than having to enter it. A typical checkout still has me entering my address, choosing between 5 different delivery options, agreeing to various terms and so on. The payment step is just a minor step along the way. I wonder if this entering of payment info is feeling more inconvenient to people who have become used to not having to do it, for example because they have used Amazon (I still never ordered anything there because they don't have a functioning operation where I live).
- martinald 5y agoYou probably don't want to use bank transfers, depending on your jurisdiction. Using any sort of visa/masterdcard/amex gives you some protection via chargebacks. In the UK (and I think many other places), paying with a credit card over £100 gives you enormous additional protection (the credit card company is also liable for any problems). So if someone goes bankrupt, the credit card company has to make you whole. This is super helpful if eg you can't do a warranty claim on a product because the supplier went bankrupt. The credit card company has to resolve it (which generally means a full refund). Paying with bank transfers completely negates all this protection. Merchants love it for this reason (and lower fees), but as a consumer it offers no benefits and a lot of drawbacks.
- korginator 5y agoThe real story is far less sensationalist than the title on HN, "Indian online merchants cannot store credit card information from 2022". Reading through the actual notification titled "Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services", it is clear that the directive is a well deserved push away from Card on File (CoF) where the actual card details are stored by merchants, towards CoFT which is a lot less vulnerable. In fact this is exactly what Apple Pay, Google Pay, and several others are already doing worldwide.
- Tempest1981 5y agoSounds prudent, but can the government actually enforce this? How?
- vivekv 5y agoMastercard is banned in India because they violated local data storage rules https://www.livemint.com/news/world/us-trade-officials-called-india-s-mastercard-ban-draconian-report-11632042319884.html https://www.livemint.com/news/world/us-trade-officials-calle...
- deanc 5y agoThe sooner we move everything to one-time tokens (apart from subscriptions) the better. It's absolutely a ridiculous security model we have in place at the moment. I pay absolutely everything I can with Apple Pay now. I also would like to be able to use one-time disposable cards (without an additional fee) in Europe (ala privacy.com) but I have yet to find such a service.
- _chompsky 5y agoPardon me if I’m incorrect, but isn’t this like one of the best use cases of Stripe? Stripe usually takes care of CC/ACH information and tokenizes it, only passing the tokens to the merchant instead of the merchant having to store the CC information. Maybe this would be a good way to start a payments company boom in India?
- option_greek 5y agoThere are already several (razorpay, paytm, payu) that do exactly that. They do charge 2% flat fee which is still high by Indian standards (comparing to cash and upi). So merchants do try custom solutions with bank gateways to reduce the fee.