Simple clear advice in plain English

How safe are your credit card details online?

We reveal how secure your credit or debit card details are when you shop online

image-of-the-ca-investigates-logo
Follow Computeractive staff on their Twitter pages

Shopping online has a number of benefits and is becoming increasingly popular. However, surveys are finding that many people are scared about using their credit or debit card online.

When we investigate frauds, such as the Zavvi Direct scam we uncovered in June 2008, all the victims who contacted us were deeply concerned that their credit or debit card details had been compromised and would be used for other frauds, but this was not the case.

So we wanted to find out why, by taking a look at what happens to your card details when you shop online.

Gateway to the bank
It may surprise people to know that many genuine online retailers never see their customers’ card details. It depends on how they set up their online payment system once they have been authorised by an acquiring bank to take card payments.

This acquiring bank, sometimes called the merchant bank, is the organisation that carries out the checks on companies applying to take card payments.

There are currently nine in the UK, including Barclays Merchant Services and Lloyds TSB Cardnet. Once approved, the retailer then chooses a payment gateway; the merchant account is useless without one. Sometimes the acquiring bank will have its own payment gateway that the retailer will use, but they can choose their own.

Payment gateways, or portals as they are sometimes known, such as Secure Hosting and Protx (now called Sage Pay), connect the retailer’s website with the acquiring bank.

Many online shoppers will be familiar with those names and others such as Worldpay. Essentially these companies are the middlemen in the online payment process. It is at this point that online retailers differ in the way payments to them are processed.

The online store can choose to host a payment page on its own computers and transfer the card data to the payment gateway as many of the major retailers do. But this isn’t always the case.

Jonathan Rodger of Secure Hosting explained: “We handle the technical side of the payment process. Online retailers are allowed to store people’s card data except the CV2 number (the three-digit security code on the back of the card) but if they do there are a lot of obligations they have to meet.

“Any company processing, storing, or transmitting cardholder data should be PCI (Payment Card Industry) compliant ­ – this is a security standard run by the finance industry. They must have a secure server and it is their responsibility to ensure the card data is encrypted when they send it to us.

“However, a lot of retailers, particularly smaller ones, don’t want this responsibility and we can do this for them. When the customer goes to the online checkout to make a payment they are transferred to the secure servers of a payment gateway, such as Securehosting, where the retailer’s payment forms are hosted.

“Card details are then input here. People may not realise this as we can set up the payment page so that it looks just like part of the retailer’s website.”

You can look at the address bar once you are about to enter your card details and if this method is being used, you will see that you have been directed to a payment gateway’s site.

Reader Comments

lost mail

I have had cheque books 'lost' in the post and mail lost. This was before the recent strike so there is some postal employees who must be liable for this missing post. A cheque book can be felt and thus identified from the outside of its envelope. The temptation for some must be great as they work in the postal service and these days the old standards seems to have gone. The old days gave an excellent service and twice daily deliveries. Now mail is over a week and one never knows when it is going to arrive, if at all. Thank goodness for email otherwise my business would be in serious trouble.

Posted by douglas, 08 Oct 2009

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Credit card illustration

Mesh gets caught in administration

Unknowingly, Nick Chumbley got caught up with a company facing the wall. Unless he paid for his PC by credit card, he will have to join the queue of creditors

Make your own animations illustration

Create a stop-motion cartoon

Stop-motion animation can unleash your inner Nick Park. We show you how to bring static objects to life by making your own Wallace and Gromit-style video

fraud

Zavvi Direct fraudsters jailed

Two gang members involved in £250,000 online scam receive two-year sentences

Question & Answer

Q.How do I store musician and other information about...

> Read the answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Best deals on the web

img

Sony Vaio VPCF23P1E/B

£679.98- Buy it now

img

Apple MacBook Pro (MC724LL/A)

£999.99- Buy it now

img

Dell Vostro 1540 (n0215401)

£249.00- Buy it now

Great benefits for subscribers!

Most popular articles

soca

RnBxclusive users busy deleting download history says SOCA

Since law-enforcement agency has taken down a site alleged to illegally host RnB music, downloaders have been busy trying to delete their online footprints

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

Router

A device used to connect more than one computer or other device to the internet.

Great shopping deals from Computeractive