Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8333227
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 9, 20262026-06-09T02:57:12+00:00 2026-06-09T02:57:12+00:00

At the moment I’m setting up an online shop (using OpenCart) for a client.

  • 0

At the moment I’m setting up an online shop (using OpenCart) for a client. All the the payments and transactions are carried out via payment gateways (PayPal, etc.), so the website never stores payment information (bank details, card numbers, etc.).

However, my client is still concerned about the safety of customers’ personal details (address, DOB, full name, etc.). I’ve explained to him that using SSL, any data transferred between the client and the server IS encrypted, and that it’s normal not to encrypt personal information on the server (I pointed out that even a company as big as Sony doesn’t).

Obviously encrypting the contents of a MySQL is perfectly possible, but of course you still need to place the key on the server. And if someone gets into the server, they’ll get the key as well and simply decrypt the database content.

So is there anything more I can do with regard to STORING personal info more securely? Are there any “industry techniques” I’m missing. Am I correct in thinking that the industry standard is storing personal info in plain text?

Thanks.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-09T02:57:14+00:00Added an answer on June 9, 2026 at 2:57 am

    Even if you are not strictly required, try to achieve PCI compliance for your scenario. This will give your client peace-of-mind and will require you to follow some industry best-practices. One of the things you will also have to do is get your server scanned–this will establish some basic confidence in your server’s security.

    PCI compliance is not a guarantee of security. It’s basically putting a lock on your door and making sure the windows are closed.

    The most important thing PCI compliance does not and cannot check is whether your webapp itself is vulnerable. If there’s an SQL injection attack vector in your app somewhere (for example) then your data can be stolen even if you encrypt your entire database and lock it in an underground vault. So get automated test coverage of your application that attempts to attack it. Run those tests regularly.

    Some random googled guides to PCI compliance:

    • PCI compliance levels
    • PCI checklist and scanner
    • Official PCI FAQ

    Note very carefully: If at any stage your webservers even touch card data, you are required to be PCI compliant. Just because you do not store CC data does not mean PCI compliance does not apply. The compliance level will be less stringent, but there will still be a compliance level.

    It’s not clear to me whether PCI compliance applies to your scenario. Basically, if customers enter card numbers into paypal’s website directly and you never know the card number, you do not need to be PCI compliant. If however they enter card numbers into your website and your server passes that data to Paypal via an API, you do need to be PCI compliant even if you are not storing the data they enter!

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

At the moment I'm using all sorts of if statements and substrings in order
At moment I want to implement picture upload without using any plug-ins. My upload
At the moment I'm using bat file to launch my jar and set the
At the moment I'm trying to figure out how use default and custom settings
At the moment, I'm fading components in/out at a rate of 0.1 alpha/second .
At the moment I have about 2000 trades which are priced using excel. I
At the moment I am trying to validate a form using PHP. The problem
at the moment we're using SVN (yeah, I know that's shame :)) and we're
At the moment I am using this to call the TabHost activity to change
Ignoring price for the moment, would using Unity for a 2D game be better

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.