4 ms·
You're not explicitly mentioning it but this means the PSPs are sending each other the raw credit card data right?
by Griffinsauce 5y ago
You're not explicitly mentioning it but this means the PSPs are sending each other the raw credit card data right?
- g_p 5y agoThis seems to be the case - another comment in this thread links to https://stripe.com/docs/security/data-migrations/exports https://stripe.com/docs/security/data-migrations/exports, which appears to suggest that the data is exchanged to another PCI-DSS provider via PGP-encrypted JSON-dump. That JSON-dump includes the card number, expiry, and billing address.
- mrweasel 5y agoI believe so, either that or there's an additional level of tokenization between them and the company doing the actual integration with the credit card companies. Most people don't realize is that paying with credit cards mean dealing with as many as four companies. The store, obviously, then the payment service provider, an acquirer and then the actual credit card company (and then maybe your bank). The acquirer is normally pretty invisible. Some companies acts as both PSP and acquirer, but some PSP also use the same acquirer, or support multiple. In the later case, you can actually switch PSP, but keep the acquirer. In these cases I would guess that you could avoid doing having to transfer raw credit card data between PSPs.