Discussion about this post

User's avatar
Steel City's avatar

I have about 15 years of experience in card processing. The one piece of advice I'd give you is to ensure you have an SLA in the contract that guarantees how quickly you'll receive your vaulted cards back if you leave a service. Some processors outright refuse to return cards, and others will bog you down with a lot of overhead. A few processors will require that you demonstrate PCI DSS compliance before they return the cards, but this is also incorrect. The processor has no liability for what happens once you receive your cards. Their liability ends at delivering the cards in a PCI-compliant manner. (Ideally you're having the cards move from one vaulted solution to another, but in the worst case, you don't want to lose the cards and subscribers, so holding them in a non-compliant manner is better than losing the subscriber base entirely.)

Feel free to reach out to me if I can provide any guidance.

Expand full comment
1 more comment...

No posts