Z.H. RENTALS · BARBADOS
Payment Security
How the Z.H. Rentals production checkout is designed to keep raw card data out of the rental-management system.
How online card payment is intended to work
The production checkout will use a CIBC Caribbean-approved e-commerce gateway. Z.H. Rentals is currently evaluating the gateway recommended by CIBC for vehicle-rental transactions, including authorization-only security holds.
- The customer selects dates and an available vehicle on zhrentals.net.
- Z.H. Rentals creates the booking and payment amount in BBD.
- The customer is transferred to, or securely presented with, the approved gateway’s hosted/tokenized payment interface.
- The payment gateway and CIBC process the card transaction using the enabled card-network and authentication controls.
- Z.H. Rentals receives a payment result and transaction reference, not the customer’s raw card number.
Cardholder data
Z.H. Rentals does not intend to store card numbers, CVV/security codes or magnetic-stripe/chip data in the rental-management database. Payment records are limited to operational information such as amount, status, currency and provider transaction reference.
3-D Secure and fraud controls
The final production configuration will use the authentication and fraud controls required or supplied by CIBC and the selected gateway, including 3-D Secure where enabled for the merchant account.
PCI DSS
Z.H. Rentals will complete the PCI DSS compliance requirements assigned by CIBC for the selected e-commerce architecture. The precise PCI scope depends on the gateway integration method approved by CIBC.
Current staging status
No live card-entry form is enabled in this staging build. Customers should not enter card numbers anywhere on the staging site.