[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"questions:item:en:can-i-store-card-details":3},{"id":4,"title":5,"answer":6,"body":7,"category":77,"description":78,"extension":79,"meta":80,"modifiedAt":81,"navigation":82,"pairId":83,"path":84,"publishedAt":85,"question":86,"relatedPath":87,"seo":88,"seoTitle":89,"sitemap":90,"slug":91,"stem":92,"translationSlug":93,"__hash__":94},"questions_en\u002Fen\u002Fquestions\u002Fcan-i-store-card-details.md","Can I Store Card Details","A merchant cannot store full card details — that requires your own PCI DSS certification, and its requirements are out of proportion for an ordinary online store. Details are entered on the certified provider side, and repeat charges use a token.",{"type":8,"value":9,"toc":70},"minimark",[10,13,18,31,35,46,50,61],[11,12,6],"p",{},[14,15,17],"h2",{"id":16},"what-must-not-be-stored","What must not be stored",[19,20,21,25,28],"ul",{},[22,23,24],"li",{},"The full card number, expiry date and cardholder name together.",[22,26,27],{},"The CVC\u002FCVV code — it may not be stored at all, even encrypted.",[22,29,30],{},"Magnetic stripe or chip data, and authentication values.",[14,32,34],{"id":33},"what-may-be-stored","What may be stored",[19,36,37,40,43],{},[22,38,39],{},"The token — an anonymised reference to the card used for repeat charges.",[22,41,42],{},"The last four digits and the card scheme — for your interface and support.",[22,44,45],{},"The operation id and status — for reconciliation and refunds.",[14,47,49],{"id":48},"why-this-is-better-for-you","Why this is better for you",[19,51,52,55,58],{},[22,53,54],{},"A leaked token gives an attacker no means of payment: it is useless outside your store.",[22,56,57],{},"Certification and audits stay with the provider rather than your team.",[22,59,60],{},"The customer does not re-enter the card — subscriptions and repeat purchases keep working.",[11,62,63,64,69],{},"How tokenisation works is covered ",[65,66,68],"a",{"href":67},"\u002Fen\u002Fquestions\u002Fwhat-is-card-tokenisation","separately",".",{"title":71,"searchDepth":72,"depth":72,"links":73},"",2,[74,75,76],{"id":16,"depth":72,"text":17},{"id":33,"depth":72,"text":34},{"id":48,"depth":72,"text":49},"security","A merchant cannot store full card details without PCI DSS certification. What may be stored and how repeat charges work without the details.","md",{},null,true,"question-37","\u002Fen\u002Fquestions\u002Fcan-i-store-card-details","2026-08-17","Can I store customer card details myself?","\u002Fen\u002Frecurring",{"description":78},"Can card details be stored on your own server",{"loc":84},"can-i-store-card-details","en\u002Fquestions\u002Fcan-i-store-card-details","mozhno-li-hranit-dannye-kart","Lwnrus7FjZ-X8QIfcC4GdiFHHPA9t0GQEd4YaMQJFHk"]