I poked around a bit to see wtf is going on and unintentionally dumped the entire db of 10,000+ credit card numbers, cvv, etc. For ALL of the system's users!
I'm a good person, and I really would rather not use this information incorrectly, so what's the right thing to do that won't land me in jail?
If anyone is wondering the shopping cart service is apparently based in PHP.
Edit: I didn't make it clear enough, this is a service - like shopify - but definitely NOT shopify :) Appears to be locally operated, and has a good number of local clients.