Secure Credit Card Vault

Secure Credit Card Vault

Purpose

Rental Car Manager (RCM) allows you to securely store your customer's credit card(s) against a booking.

To ensure that this meets the Payment Card Industry (PCI) compliance requirements set out by Visa, Mastercard and other card providers, a tokenized credit card vault is used.  This ensures all card data is stored securely as electronic tokens while the real card data remains remote and secure with our Level 1 PCI compliant service provider. As a merchant this enables you to very cost effectively meet your own PCI compliance requirements set out by your bank or merchant provider.  

Notes on Credit Card Storage
  1. Storing credit cards in Rental Car Manager is OPTIONAL and there is an extra monthly charge for using this Secure Credit Card Vault. For more information about these costs, see the Credit Card Vault Charge section at the bottom of this article or contact RCM Support (support@rentalcarmanager.com).  
  2. Multiple cards may be stored against a single booking.
  3. If you enter credit card data in any other fields that are not secured for credit card entry your data may be automatically masked or deleted when the record is saved. 
  4. Note that viewing of the card details requires the correct permissions on the users records and also authentication against your place of business.   If you are using Two Factor Authentication then you may view card details from any location or device. The following article discusses the security around viewing credit cards in more detail, Restricting Access to the Credit Card Vault.

Adding/Viewing Cards

There are 2 places within RCM from where you can access the credit card vault to either add or view a card.

If you have a payment gateway setup within your RCM system, you can click on the Payment button shown on the Booking Details screen below. Clicking on this button will open the Vault/Payment window. This is discussed in more detail below. If you do not have a payment gateway setup, you will not have this button available on this screen.


The main way that you will access the credit card vault is via the Booking Form.
On the Booking Payment tab of the Booking Form, shown below, there is a VISA icon. Clicking on this icon will open up the screen showing a listing of any cards that have been saved against this booking. You can add a new card to the credit card vault by clicking on the "Add Card to Vault" button.



The Vault/Payment Manager window will open. You can add a new card by clicking on the "Add Card" button shown below.



The secure vault window will be displayed, allowing you to enter the card details, see below. Once you have entered the card details, simply click the Submit button.



You can see the card details on the Vault/Payment Manager window, see below. You can view the card details by clicking on the View button.



You are also able to see the card details from the Booking Payments tab on the Booking Form, see below. You can see that the card number is masked. If you wish to view the card details, simply click on the card number. If the card number is not a hyperlink, this means that your user does not have access to view the credit card information within RCM. For more information about why you may not have access to view the credit cards read the following article Restricting Access to the Credit Card Vault.



Clicking on the card number opens the secure credit card vault window shown below. You are able to remove the card from the vault by clicking on the Delete button.



Credit Card Vault Retention

The tokens in the Secure Vault will be saved for a set retention period after they are entered. After this retention period is up, they will be automatically removed from the vault. To change this retention period, go to System Setup >> System Parameters >> Credit Card Retention Month.

This will be automatically set to 3 months. To change this, click on the red "3 Month", and it will open the page shown below. Here you can change the drop down to any of the available time periods and select "Submit" to save this record.


If the retention period is set to 6 months, then 6 months after they are entered, the cards will be automatically removed from the vault. However, there is a system flag shown below that can be accessed through System Setup >> System Parameters >> Miscellaneous Parameters. If this flag is set to YES, then the removal date of the token will be extended every time it is viewed, such that it will be removed the length of the retention period after the date it was viewed.


Please note: Credit Card Tokens in the Secure Vault can only be held for a maximum of 24 months, so the removal date cannot be extended beyond 24 months after the date they were entered. 
There is an additional cost per month for every card that is stored longer than 3 months, so there will be a cost against cards whose removal date is extended. More information about this is detailed at the bottom of this article.

CVV Retention

The Secure Credit Card vault has a CVV Retention Policy in place which allows you to view the CVV details 50 times before the details are removed. The card details will be retained, but the CVV information will not.

However, this will work differently for any cards that were saved into the vault before March 2023. After the card has been viewed 50 times, the card will be removed from the vault.

Viewing monthly Usage/Costs

As mentioned above, there is a monthly cost involved with using the secure credit card vault. 
The Credit Card Vault Costs report allows you to keep track of the costs incurred. It can be found under the Monthly Financial Reports menu option and the following article describes it in more detail, Credit Card Vault Costs Report.



Credit Card Vault Charge

The following monthly charges will apply if the credit card vault is being used.

You will not be charged for storage of cards for the first 3 months that they are saved within the vault. After 3 months a storage charge will be incurred.



Monthly RCM credit card vault fee - this fee is applied to a standard RCM implementation. If you have a Franchise setup within your RCM system contact support (support@rentalcarmanager.com) to determine what this monthly vault fee will be.
$10.00
Adding a card to the vault
$0.03
Viewing a card in the vault
$0.03
Storage of a card for more than 3 months
$0.01 per card per month

So for example if you add 10 cards and view 25 cards and have 40 cards that have been saved in the vault longer than 3 months your charge for the month will be as detailed below



Flat monthly fee
$10.00
10 cards added
$0.30
25 cards viewed
$0.75
40 cards saved for longer than 3 months
$0.40
TOTAL COST FOR MONTH
$11.45


    Important Articles


      • Related Articles

      • Credit Card Vault Costs Report

        Purpose: As there is a cost involved with the use of the secure credit card vault, the Credit Card Vault Costs report allows you to see what the costs for this usage will be. For more information about the secure credit card vault and the costs ...
      • New - New Credit Card Vault

        The Auric Credit Card Vault will be phased out at the end of December 2022.  This decision has been made as a result of our current supplier for the Credit Card Vault being acquired by a competitor who will no longer offer the same solution.  Rental ...
      • Credit Card Token Migration

        Purpose As Rental Car Manager (RCM) is moving away from the older Credit Card Vault storage solution (Auric Vault) to both an Integration with the Stripe Payment Gateway and a new secure Credit Card Vault, the ability exists within RCM to allow for ...
      • Credit Card Vault Log

        Purpose The Credit Card Vault Log allows you to see which of your operators have been viewing the credit card details that are stored in the secure vault. Every time a credit card is viewed in the secure vault, a record is written to a log with the ...
      • Additional Feature - Display the User that Deletes Cards from the Vault

        RCM now records which user deletes cards from the Secure Credit Card Vault and displays this on the booking form. Cards in the vault can be deleted when you view them if you click the "Delete" button at the bottom on the window. You can view who ...