Pure Bliss Jewelry Security Policy
June 3, 2010
Credit Card Transactions
- Pure Bliss Jewelry (hereafter “PBJ”) places the security of its customers’ data at the highest priority. PBJ does not willingly or intentionally share or sell its customers’ credit card or invoice data. PBJ keeps this data for the shortest amount of time possible to complete the transaction, then deletes it. NO CREDIT CARD DATA IS STORED.
- PBJ accepts customer credit cards (VISA, Mastercard, Discover, and Diners Club) using either of three methods: a handheld mechanical imprint device (sometimes called a “knuckle buster”), or in speaking with a customer on the phone and receiving their credit card data orally, or via the mail in a sealed envelope. The data in all cases is then electronically submitted to Nationwide Payment Solutions, 400 Technology Way, Scarborough, Maine 04074, using a Trans 330 credit card terminal, inputing the data manually in response to the machine prompts. The batch is then automatically transferred by Nationwide at the end of each day.
- Once PBJ has completed the transaction with the customer, the data is blacked out. and the receipt stored in a hidden, anonymous container until the end of the fiscal year. It is occasionally necessary to review these customer receipts, but the credit card data is unavailable to PBJ. Any time a customer wishes to pay using a credit card, the data must be taken anew. Furthermore, the 3-digit security code on the back of the credit card is kept on a separate slip of paper from the credit card imprint itself, and is not denoted as such.
Security on the Pure Bliss Jewelry Website
- PBJ does not have a shopping cart at present on its website. It does not accept credit card transactions through the website (http://www.pureblissjewelry.com). It does not currently use PayPal or other payment method on the website. Customers may email PBJ directly from the website, however,
- Customers should be aware that the PBJ policy is to NEVER encourage or accept credit card data in an email to PBJ or its sole proprietor, Kelli Peduzzi. All credit card data must be submitted in person through the manual transaction described above, or orally via telephone, or in a stamped envelope through the U.S. Postal Service or other commercial mailing service (UPS, FedEx, etc.). If a customer provides credit card data via an email, it is WITHOUT express consent of PBJ or its employee and at the customer’s own risk.
- PBJ makes sure that its sole employee and any future employees regularly reads the security policy, understands it, and undertakes any necessary education to understand changes in security policy methods.
- This policy is kept on file at PBJ’s office at 114 Academy Street, Poughkeepsie, New York 12601. It is reviewed annually and updated as necessary. It is available for review by any of PBJ’s customers, vendors, and support services. It is posted clearly on the PBJ website on its own page titled “Security Policy”.
|
|