Credit card numbers

A number of measures are used in QuickFill to ensure the security of credit card numbers in your database.

  1. Credit card numbers and user passwords in the database are encrypted. Even if your database files are stolen, the thief will not be able to extract credit card numbers from the raw files, nor will they be able to extract user passwords.

  2. Access to the credit card number is controlled by user. Only those users that have the "View and adjust credit card numbers" box checked on the 'Users' definition screen can see the full card number on the lookup screen. Other users will see a series of asterisks followed by the last four digits of the card number.

    You must define one or more user names and passwords to make this feature effective. If you have not defined any user names and passwords then access to your database will be unrestricted and everyone will be able to see the full credit card numbers. You might consider that this is acceptable in a small office where all employees are trusted, but consider the consequences if your QuickFill computer is stolen. The thief will be able to run QuickFill and will have access to the names and credit card numbers of all of your subscribers.

  3. The order adjustment screen omits the credit card number field if the user does not have the right to "View and adjust credit card numbers".

  4. Subscription summary reports include the full credit card number only if the user that created the report has the right to "View and adjust credit card numbers".

  5. Batch reports include only the last four digits of the credit card number in the payments section.

  6. Files created by the QuickFill Subscription Export include only the last four digits of the credit card number, unless the user that ran the report had "view and adjust credit card numbers" rights and specifically requested full credit card information when running the export.

  7. The QuickFill ODBC driver outputs only the last four digits of the credit card number in all cases (the ODBC driver does not utilize user names and passwords).