i don't understand it either, if you require cvv2 - make a submit form so that system can perform the check and won't store it in the db as per requirement of visa/mc and no live person will ever see it and handle it. i would never trust sending back card scan to anyone, way too insecure. no single issuing bank will approve such a requirement also
|