In the project description, there should be a large, red, bold, huge statement about PCI compliance. Even if you are just passing CC numbers through to your payment gateway and not storing them anywhere, you are still transmitting CC numbers and are therefore required to fall under certain levels of compliance.

Comments

univate’s picture

I don't think this is an issue with pay, this is an issue with the payment gateway being used. Ie: if using pay with paypal WPS (not sure if it is supported) then you wont need to care about PCI DSS compliance.