We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Giving card details in writing

2»

Comments

  • I think you are being a little too cautious.

    Agreed, there is always a risk in having this sort of info stored - especially if you don't know how securely it is being held. It is also true that card scheme regulations do not permit a retailer to store the 3-digit code (CVV2/CVC2) in any form whatsoever once they have used it to make a transaction, so that is a consideration.

    However, what you are being asked to do is provide enough information to make a card-not-present transaction in a way that gives the retailer some confidence that you are indeed the person authorised to use the card?

    If you'd telephoned the retailer and done the transaction that way (with the same information) would that have made you feel more or less secure? In essence it's no different and the retailer could still be storing it all in paper form.

    You could have done it online with the same information and, whilst secure processing systems might prevent data-transmission being intercepted, you still have no idea what happens to your data once the retailer has it.

    Why don't you call them up and explain your concerns about the CVV2 value being stored beyond the transaction and see if they can reassure you about their security.
  • Deastons wrote: »
    But if there's fraud on my credit card and they find out it's because I emailed all the info, would I even be covered then??

    By BACS there's no protection.

    If I call them and give the info, what's stopping them just writing it all down then anyway?!


    I'm sure its probably fine but I'd be cautious that's all. By protection I was meaning if they company went bust etc but it that seems unlikely from what you have said since.


    Cant recall hearing about a company wanting paid in that way in recent times, doesn't mean it doesn't happen, its just unusual. Which you know yourself as you are questioning it.
  • I thought I'd just add as someone with experience in the accommodation business (hotel bookings etc) it sounds very much like a Credit Card Authorisation Form is what you've been asked to complete.

    As Terry Towers says its a customer not present transactions - also called MOTO or Mail Order Telephone transaction. Where the business manually keys in the details into the terminal (be it a physical terminal (like a card reader in a shop made by ingenico) or onto a screen like Stripe payments).

    Such forms are used for the business as proof the card holder authorised the transaction when they weren't there to check the signature/pin. Such as if you booked a hotel room but you weren't staying at the hotel and it was a gift for family. You'd want to pay for the room and cover the incidentals. So the hotel has evidence to counter a charge back claim you might raised later you'd need to send in the form and it often now done by Email, though fax is still very common as is post.

    My advice is to print out and post it in, as the best way forward.

    (Its no different to how we all used to place orders from the back of a catalogue) I think its just that because its over email instead its caused you to feel extra cautiious because of phishing etc...)
  • eDicky
    eDicky Posts: 6,835 Forumite
    Ninth Anniversary 1,000 Posts Name Dropper
    makeni555 wrote: »
    it sounds very much like a Credit Card Authorisation Form is what you've been asked to complete.
    It does. The UK Passport Office takes payment in this way, without option, when renewing a passport from outside of the UK in many countries. From my experience the form is not sent off by mail by the consular service or its agent, the speed indicates electronic transfer.
    Evolution, not revolution
  • Deastons
    Deastons Posts: 464 Forumite
    makeni555 wrote: »
    Such forms are used for the business as proof the card holder authorised the transaction when they weren't there to check the signature/pin. Such as if you booked a hotel room but you weren't staying at the hotel and it was a gift for family. You'd want to pay for the room and cover the incidentals. So the hotel has evidence to counter a charge back claim you might raised later you'd need to send in the form and it often now done by Email, though fax is still very common as is post.

    You're correct - it is a credit card authorisation form.

    I know I'm labouring the point now, but from your comment about using it as evidence that I authorised the transaction, that would assume they would store the form. The form asks me to give my CVC number which merchants are not allowed to store - and that's the bit that has made me suspicious.
  • Deastons
    Deastons Posts: 464 Forumite
    However, what you are being asked to do is provide enough information to make a card-not-present transaction in a way that gives the retailer some confidence that you are indeed the person authorised to use the card?

    I guess you're right, but it was the need for the CVC2 and a signature which made me cautious. That seems to be every bit of info short of my PIN.
  • blitzboy
    blitzboy Posts: 477 Forumite
    edited 2 November 2018 at 5:14PM
    I had this with a hotel booking. I just made sure I dated the form and then emailed it to them so that I could prove exactly what I sent to them and when, rather than a paper copy with no proof of sending.


    And of course I paid by credit card for the extra protection it gives compared to a debit card!
  • Deastons wrote: »
    The form asks me to give my CVC number which merchants are not allowed to store - and that's the bit that has made me suspicious.
    Deastons wrote: »
    I guess you're right, but it was the need for the CVC2 and a signature which made me cautious. That seems to be every bit of info short of my PIN.

    Quite so, and you are right to be concerned about the possible retention of the CVV/C2 - but not necessarily suspicious. You should air your concerns about this with the retailer, but I don't think you need to shy away from the transaction entirely.

    You could ask to do the transaction by telephone (giving the CVV/C2 verbally) and agree to also provide the form with your personal details but with the card details omitted and a note referencing the telephone transaction. Trouble is, you still have no guarantee that they are not recording and retaining the CVV/C2 when you call them.

    If your concern is that a subsequent fraud arising out of the misuse of the details you provided might make your card issuer disinclined to help you, then I think you need not worry.
This discussion has been closed.
★ ★ ★ Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 355.6K Banking & Borrowing
  • 254.8K Reduce Debt & Boost Income
  • 456.1K Spending & Discounts
  • 248.2K Work, Benefits & Business
  • 605.7K Mortgages, Homes & Bills
  • 179K Life & Family
  • 263.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.