Hacker News new | ask | show | jobs
by rosbrith 2736 days ago
It is usual practice to pass on payment details to a hotel rather than the booking agent charging the cards themselves. This can be compatible with PCI-DSS when details are tokenised and stored with a third party.