You’re Playing With Fire And Don’t Even Know It. Why Your Credit Card Info Might Be At Risk.

Eric Najjar
ShopKetti
Published in
4 min readAug 21, 2017

--

At ShopKetti.com we talk to our clients. We also talk with businesses who don’t work with us because it’s important to hear criticism from both inside and out. One thing we try to emphasis regardless of popular opinion is safety. Whether it’s enforcing MAP pricing or ensuring that only real manufacturers are represented on our platform, we make sure to enforce the rules.

That being said there seems to be a disconnect when it comes to how we perceive safety. For too many safety is thought of something physical. It’s using a seatbelt, it’s looking before you cross the road, but for some reason it’s not protecting your credit card information.

During my first trade show (and every trade show since) I’ve was shocked to see people writing out full credit card and billing information on a piece of paper and walking away. Almost everyone does it. You want to place an order, so you write down your payment info and hand it to a person who will type it in manually. But what if I told you that people make mistakes? What if I told you that those pieces of paper sometimes go missing? Credit card info and all. It’s not the fault of the manufacturer, heck most retailers get a copy of their order and it’s only human to lose those too. The problem comes when someone finds that sheet of paper lying on the ground. Every order you place has you rolling the dice and you better hope that if that paper goes missing that the person who finds it doesn’t decide to buy something nice on Amazon.

After my first trade show I was so shocked by the open liability that I had my still not fully launched company beta test an in booth payment processor. The tool worked but it was admittedly a little rough around the edges. Six months later we were ready, we had fully developed our in booth transaction tool and called it Merchant, by ShopKetti. For the first time retailers would be able to place a secure order with a manufacturer and the manufacturer would have it integrated into their existing wholesale framework. Win-win, right? While this solution (which works in all situations, offline mode included) is present and growing, businesses are still choosing to use old paper order forms and run the very real risk of compromising their or someone else's information.

While trade shows are an important place to emphasize security, they’re a small portion of our time. Online ordering is a much bigger issue that most retailers don’t even know they’re at risk during. One of our web based competitors (who I won’t name) does not process any payments. That’s perfectly fine. Their MASSIVE security breach comes with how orders are processed. Retailers place an order, enter their credit card info, and a few days later their card is charged and goods are received. In actuality this company is receiving this credit card and billing information, they leave it all in the open, and send it to the respective manufacturer(s) in full, unencrypted, and undisguised. There is no security. If a manufacturer has malware or spyware on their computer that credit card info is instantly compromised, if an employee at either organization becomes disgruntled they can take that information and run. If there’s an email breach on either end the credit card info becomes compromised.

The worrying part is it happens all the time. When credit card information is stolen it’s often not used instantly, criminals can wait up to a year to use it, making it harder to track and identify the breach, which is exactly what they want. The question isn’t when will it happen with this specific company but how many times has it happened already? This is a serious matter and not something that should be taken lightly.

I knew this from the start. That’s why I made sure that both ShopKetti and the manufacturers on our platform wouldn’t have access to full credit card information. When an order is placed in our wholesale marketplace or through Merchant, we see the last four digits, the manufacturer sees the last four digits, and there’s nothing we can do to change that or compromise that. We can do this because we transact the orders on our end, this level of security is impossible any other way. And frankly, any other less secure method is downright foolish and irresponsible.

As someone who runs a startup I’m on the frontline when it comes to protecting my users information. It upsets me when I see people in my position at other companies skirt that important responsibility. In this case I’m not talking about manufacturers or retailers but platforms, like ShopKetti.com and our competitors, which maintain them. Every time we work on a new feature or service we make sure to ask ourselves if it’s responsible and if it will increase or decrease risk on the platform.

While updates to our service might seem to come at a slower pace we’re actually updating all the time. Our primary objective is to make sure our service simplifies your life and that means your data too. Because if your credit card information is compromised that will only complicate your day.

ShopKetti is a wholesale platform connecting independent creators and retailers in the pet industry. Explore the community and join for free at shopketti.com

--

--