<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>thread Re: PCI Compliance with Mail Orders that Contain Credit Card information in Payments Troubleshooting</title>
    <link>https://community.squareup.com/t5/Payments-Troubleshooting/PCI-Compliance-with-Mail-Orders-that-Contain-Credit-Card/m-p/626606#M33673</link>
    <description>&lt;P&gt;&lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/333926"&gt;@CintiObserv&lt;/a&gt;&amp;nbsp;When you accept the mail and then enter into square you are entering the info into a PCI compliant system.&amp;nbsp; The biggest thing you need to do is ensure that access to the mail is limited, mail is not left unsecure, and destroying them after entering them is ideal (crosscut shredder!).&amp;nbsp; As long as the mail is secure and you are not storing paper copies insecurely, you are fine as far as PCI compliance from what I know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Restrict physical access to cardholder data.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PCI DSS Requirement 9 relates to physical security. All physical access to cardholder data within the cardholder data environment must be controlled and restricted to only individual&amp;nbsp;who require this physical access."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;These safeguards limit your liability.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2023 19:15:45 GMT</pubDate>
    <dc:creator>Donnie-M</dc:creator>
    <dc:date>2023-01-05T19:15:45Z</dc:date>
    <item>
      <title>PCI Compliance with Mail Orders that Contain Credit Card information</title>
      <link>https://community.squareup.com/t5/Payments-Troubleshooting/PCI-Compliance-with-Mail-Orders-that-Contain-Credit-Card/m-p/626594#M33672</link>
      <description>&lt;P&gt;We are a non-profit and use Square POS for our gift shop, program fees, memberships, donations and the like. I understand that by using Square we are PCI compliant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However we do receive some credit card information via the mail (typically memberships and donations), which are then processed in Square POS. Once they are approved we shred the mail with the credit card information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we need undertake any PCI assessment or tasks to be 100% in compliance?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Craig&lt;/P&gt;&lt;P&gt;Cincinnati Observatory Center&lt;/P&gt;</description>
      <pubDate>Sat, 20 Sep 2025 20:17:42 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Payments-Troubleshooting/PCI-Compliance-with-Mail-Orders-that-Contain-Credit-Card/m-p/626594#M33672</guid>
      <dc:creator>CintiObserv</dc:creator>
      <dc:date>2025-09-20T20:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance with Mail Orders that Contain Credit Card information</title>
      <link>https://community.squareup.com/t5/Payments-Troubleshooting/PCI-Compliance-with-Mail-Orders-that-Contain-Credit-Card/m-p/626606#M33673</link>
      <description>&lt;P&gt;&lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/333926"&gt;@CintiObserv&lt;/a&gt;&amp;nbsp;When you accept the mail and then enter into square you are entering the info into a PCI compliant system.&amp;nbsp; The biggest thing you need to do is ensure that access to the mail is limited, mail is not left unsecure, and destroying them after entering them is ideal (crosscut shredder!).&amp;nbsp; As long as the mail is secure and you are not storing paper copies insecurely, you are fine as far as PCI compliance from what I know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Restrict physical access to cardholder data.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PCI DSS Requirement 9 relates to physical security. All physical access to cardholder data within the cardholder data environment must be controlled and restricted to only individual&amp;nbsp;who require this physical access."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;These safeguards limit your liability.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 19:15:45 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Payments-Troubleshooting/PCI-Compliance-with-Mail-Orders-that-Contain-Credit-Card/m-p/626606#M33673</guid>
      <dc:creator>Donnie-M</dc:creator>
      <dc:date>2023-01-05T19:15:45Z</dc:date>
    </item>
  </channel>
</rss>

