Prato Erboso Shop's secure online payment management platform is fully managed by one of Italy's largest card transaction acquirers, GestPay (Bancasella). Gestpay has extensive experience in transaction security and guarantees its merchants and their customers (cardholders) the highest level of security available in online sales. Specifically, the Gestpay platform fully complies with the following security standards:
CVV (CARD VERIFICATION VALUE)
This code is printed on credit cards and is used as an additional security feature for CNP (Customer Not Present) transactions, generally in eCommerce and MOTO (Mail Order – Telephone Order) transactions. The use of this security code ensures that the person making a purchase has possession of the credit card. For VISA and MASTERCARD cards, the CVV is printed on the back of the credit card (3 digits). For AMERICAN EXPRESS cards, the CVV is printed on the front of the credit card above the card number (4 digits).
3DSECURE (VERIFIED BY VISA - MASTERCARD SECURE CODE)
This code consists of a "password" that the credit card holder must provide upon request from the merchant's website where they are making a purchase. It is used only for e-commerce transactions and provides additional security to the CVV. The cardholder must enter the same "password" that they previously stored on the website of the bank that issued their credit card (issuing bank). Only in this way can the transaction be considered secure, as it is assumed that only the true cardholder knows it. 3DSsecure applies to VISA and MASTERCARD payment cards.
PCI DSS (PAYMENT CARD INDUSTRY – DATA SECURITY STANDARD)
This acronym identifies the most important "global security standard" for companies that handle payment card information in any way (credit cards, debit cards, prepaid cards, etc.). This standard is regulated by the PCI Security Standard Council, which essentially oversees and controls the handling of payment card data by all stakeholders (banks, merchants, intermediaries) in order to reduce the risk of fraudulent transactions. All stakeholders are subject to an annual surveillance audit by a QSA (Qualified Security Assessor).


