Stripe pci dss compliance through Website x5? 
Autor: Daniel B.
Besucht 257,
Followers 2,
Geteilt 0
Dear Website X5 Team,
Website X5 is improving with every new version and the Stripe intergration is great, as Paypal is going downhill for me. I wanted to ask if the implementation between Stripe and Website X5 is PCI DSS compliant, meaning that the transactions go through Stripe and Stripe only?
As I am a small business, I certainly don't want the hassle of complying with extra regulations due to dealing with credit cards, so I am looking for a payment gateway that complies with the regulations and I am left alone in peace.
Thank you in advance,
Daniel
Gepostet am

Olá amigo!
Estou no Brasil e fiz testes, funcionam perfeitamente! Vale lembrar que a primeira transação demoram 30 dias para repassar seu dinheiro, então vale a pena fazer um teste de um valor mínimo o mais rápido possível - uma dica.
O que mais gostei do Stripe é que eles não são um banco, eles recebem e na data explícita já transferem pra sua conta em banco.
Saudações e boa sorte!
Autor
Yes, I heard Stripe is good, but I want to make sure I don't need to fill out any required SAQ documents, or do audits as a merchant...
Hello,
the Stripe implementation is compliant: our servers initiate the order and receive information about its completion, but the data about payment methods is only received by Stripe.
I remain available.
Autor
Thank you for the quick reply Eric. So does this mean that I (as merchant) am not liable for PCI DSS? Is Website x5 and Strip jointly liable?
The reason I am asking is that I had to cancel my Paypal account and integration as they wanted me to fill out questionaires and undergo compliancy. I am looking for the easiest way forward for my small business. Thank you, Daniel
Hello Daniel,
the specifics depend on your business' transaction volume, you can check out this as a reference:
https://stripe.com/guides/pci-compliance#step-by-step-guide-to-pci-dss-compliance
Autor
So, after having chatted with Stripe as well, to those small business owners like me who knew nothing of PCI DSS compliancy: beware, as if you accept any form of credit/debit cards on your website - even if it is not being processed by/through you - you might be required to undergo PCI DSS compliancy. This can be an expensive and administrative exercise. I certainly do not want to waste any time dealing with this, so I am stopping all card processing integration on my sites.