When paying with a credit card or Knet card at Sultan Center you might have noticed that once the transaction goes through the employee swipes your card into their computer and your credit card number and other information gets dumped into their system. Cajie a reader of the blog sent them an email complaining about this, here is what he sent them:
I have been a frequent shopper of Sultan Center for quiet some time. However, I have become increasingly concerned about your procedure of scanning and storing customer’s credit card numbers in your sales system. This is a highly risky and unacceptable IT process, especially for such a leading retailer such as Sultan Center. Other leading merchants store only the last 4 digits of the credit card for verification purpose, which is just fine. It is my strong recommendation that your systems be reconfigured not to store sensitive customer data – especially in these days of increase rise in electronic fraud.
To his surprise the MIS manager at Sultan Center called him on the phone and assured him they made changes in their system to protect the customers financial data. After the phone call they sent him the following email with more details:
It was a pleasure talking to you over the phone, and we are really glad to have your comments and suggestions which will help us service our customers better. I would like to assure you that our Point of Sales system doesn’t hold or store the Full Credit card details, in fact this was rectified longtime back based on our Internal Audit department report. Now the transactions which are stored in our systems will only carry the last four digits of the credit card number XXXX XXXX XXXX 9021.
I hope that you are satisfied with this and Please don’t hesitate to contact us or me directly for any further queries. Wish you a very pleasant time in our stores and everywhere else.
It still doesn’t make me comfortable having them scan my card but at least now I know the information they do keep from the scan is very minimal.