Live data from Hacker News

Indian online merchants cannot store credit card information from 2022

rbi.org.in

81–90 of 157 posts

Re: Indian online merchants cannot store credit card information from 2022

#81
post #37
post #23

Earlier quoted context omitted.

Do you have to use your cellphone number to avail UPI services? If that is the case, then it is not for me.

Just to clear things up since some of the other comments seem unsure or have partial information, UPI requires a cell phone, a cell phone number and the bank account linked with the cell phone number. It cannot be used from a computer (IMPS, which is like UPI’s cousin with a slightly more cumbersome interface, can be used from a computer). The primary form of UPI usage is from smartphone apps (provided by banks or by…

Thanks.

But if one just needs to send or receive money does one need to share one's cell phone number to this 2nd party?

Re: Indian online merchants cannot store credit card information from 2022

#82

Earlier quoted context omitted.

I have created UPI ID directly with bank and there is no need of any third party app. It can be used to transfer money directly without sharing bank and card details.

You can receive money over UPI without a smartphone. But sending money actively (as a customer) from a personal bank account is not possible afaik.

What no? My business, and my family business both run off the ability to make upi payments by just giving a UPI Id, amount and everything your pin. Quite often, i settle accounts with my friends over UPI. One of them pays for coffee, and i just upi him his share. And we work with our own personal savings accounts.

Re: Indian online merchants cannot store credit card information from 2022

#83
post #73

Earlier quoted context omitted.

"such that US companies have to care about PCI more than Indian companies." If you think about the social security number system, paper checks or credit cards with magnet strips I think you'll notice that other countries sometimes have stricter and more advanced security regulations.

Yes, of course. I would expect the US to be ahead of some countries in some places, and behind some countries in some places. My point is that it's perfectly plausible that in this very particular area India could be worse than the US just as, say, the EU is generally ahead of the US. And, in different areas India could be way better than the US; this isn't "good countries" and "bad countries", it's "different countr…

I miss-understood your initial comment then, apologies! You have a good point.

Re: Indian online merchants cannot store credit card information from 2022

#84
post #81
post #37

Earlier quoted context omitted.

Just to clear things up since some of the other comments seem unsure or have partial information, UPI requires a cell phone, a cell phone number and the bank account linked with the cell phone number. It cannot be used from a computer (IMPS, which is like UPI’s cousin with a slightly more cumbersome interface, can be used from a computer). The primary form of UPI usage is from smartphone apps (provided by banks or by…

Thanks. But if one just needs to send or receive money does one need to share one's cell phone number to this 2nd party?

You don't need to - you can also share your unique UPI ID which is text like username@bankcode

Re: Indian online merchants cannot store credit card information from 2022

#85

Kudos to Indian govt, this should be the default for any e-commerce websites. I have to resort to PayPal to avoid my credit card being stored in the e-commerce merchant sites but some of sites do not support PayPal. It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account.

paypal is worse than credit card for me. For one the paypal always shares your paypal email address where as when I pay with credit card I always give a different email address to every merchant.

Does PayPal still share email addresses? I accept donations on PayPal for my open source projects, and starting from a few months ago I can no longer see people’s email addresses, which have been replaced by links to an internal chat system.

Re: Indian online merchants cannot store credit card information from 2022

#86

Is the RBI deliberately trying to handicap credit cards in India? The decision to make recurring payments impossible, followed by having to enter card information every time I do an online transaction is making for a very frustrating experience. The justification for these decisions is always "consumer interest" but how is making consumers jump through hoops to do transact online in consumer interest? I wish the indu…

Yes this is stupid and it has caused me a lot of trouble since this all started. I am now seriously thinking of leaving this country and going to NZ or Canada (something which I did not want to do because of my parents). Doing business in India is so frickin hard, especially after GST. I have to spend so much time on accounting nowadays and it's getting harder and harder every day (even though all the ads say otherwi…

> Doing business in India is so frickin hard, especially after GST. I have to spend so much time on accounting nowadays and it's getting harder and harder every day (even though all the ads say otherwise).

Why are you having to spend so much time? I mean all the popular accounting suites already support GST and automate most of the compliance. The rules haven't materially changed so, why is it getting progressively harder?

> I almost got my Digitalocean account suspended few months back because the credit cards won't bill anymore.

Why won't they bill anymore? After I enabled international transactions on my card, I haven't faced any problems with DO or AWS.

> If it were not for Stripe Atlas

If you have a Delaware C Corp, why are you even bothered by RBI rules? None of the limitations of the Credit cards or PayPal apply to you anymore.

Re: Indian online merchants cannot store credit card information from 2022

#87
post #30

Earlier quoted context omitted.

That's a weird generalization. Yes there are terrible, insecure e-commerce sites in India, the same as there are in the USA and everywhere else on the planet. India is also the top 7-8 e-commerce market in the world. Large local apps in the space have valuations in the tens of billions of dollars, and all major global players like Amazon and Walmart are involved in the country as well. These $100B in annual sales are…

> That's a weird generalization. Yes there are terrible, insecure e-commerce sites in India, the same as there are in the USA and everywhere else on the planet. I don't have the experience to know if this is actually the case, but it seems completely plausible that different countries have different regulations (or enforcement thereof) such that US companies have to care about PCI more than Indian companies. > These…

> I don't have the experience to know if this is actually the case, but it seems completely plausible that different countries have different regulations (or enforcement thereof) such that US companies have to care about PCI more than Indian companies.

Or maybe even different companies forcing users to accept credit cards in different ways.

A handful providers I had to integrate with in my career (in LatAm and Germany) had this rule where you couldn't have the numbers going trough your system unless you got PCI certification. You had to use an iFrame, or redirecting to their website where the form was served.

Sometimes the APIs were there, in public, but even if you used a valid credit card number it would deny verification unless your merchant account was pre-authorised.

Re: Indian online merchants cannot store credit card information from 2022

#88
post #81
post #37

Earlier quoted context omitted.

Just to clear things up since some of the other comments seem unsure or have partial information, UPI requires a cell phone, a cell phone number and the bank account linked with the cell phone number. It cannot be used from a computer (IMPS, which is like UPI’s cousin with a slightly more cumbersome interface, can be used from a computer). The primary form of UPI usage is from smartphone apps (provided by banks or by…

Thanks. But if one just needs to send or receive money does one need to share one's cell phone number to this 2nd party?

GP here. No, you don’t necessarily have to share your cell phone number as the sender or as the receiver. But take note of the details below.

UPI assigns/allows one or more Virtual Payment Address (VPAs) for each account, which looks kinda like an email address. The default VPA is usually phone-number@bankname, but you can (and should) disable that default VPA (mainly because UPI also has a payment request mode where anyone can request anyone else for money and there are plenty of scams with that and enumerable phone numbers). Instead, create the VPA as some-random-name@bankname (assuming nobody else has taken that). The sender and the receiver would know the VPA of the counter-party as well as the full name of the person (the name gets displayed before confirming a payment, and is helpful to know that it’s going to the right person).

Also note that while some banks allow only one VPA for an account, some banks allow several VPAs for the same account (think of them as similar to what email aliases are for the same email account). So you could have mybusiness@bankname for your clients to send business payments, mybigdinnerparty@bankname for your friends to send their share of the dinner party bill, and so on — all linked to your name and the same bank account.

Re: Indian online merchants cannot store credit card information from 2022

#89
post #55

Disclosure: I work for a fintech in India, specialized in card payment. It seems here people see this rule as "merchants can't store card numbers any more". This is actually a lot more than that, this is the new rule: you cannot store card numbers for recurring payment. Even if you are PCI-DSS compliant. Even if you are audited by the RBI. Even if you're sponsored by a bank. The only way to store a Visa number is to…

> Rupay is a failure with a market share of 0.34%[3] (in comparison UPI is at 37.73%), in spite of having ZERO MDR on debit transactions[4].

Rupay's failure is because of zero MDR, not in spite of it.

Re: Indian online merchants cannot store credit card information from 2022

#90

I see the US Model as "Optimistic". Let the transactions through and fight back fraud with a strong chargeback mechanism. Whereas the Indian Model is "Pessimistic". Put in as much checks as possible to reduce the rate of fraud before the transaction has even completed. Thoughts?

I love it. The optimistic model forces me to be hyper aware of all my banking activities and know when fraud happens retroactively. All the Indian regulations mean I effectively don't have to worry as much unless something serious happens. CC stolen? I don't care they won't have the pin or the secure pin used for online transactions so it's useless and I can just close the card on the banking website. Mobile phone st…

yesterday saw a family member get an sms "your jio mobile e-kyc is pending. please call 6006xxxxxx number to get your e-kyc done so that there is no disruption to your service". this came after trai decided to https://telecom.economictimes.indiatimes.com/news/trai-pushe...

this means, anyone who read the news understood this was going to happen and scammers put their numbers and sent out sms. any unsuspecting user would just call them whereby they would ask their aadhar card, pan card, otp and you are fucked.

Post reply on HN