Short answer: a greeting card or gift shop needs the CVV to authorize a card-not-present order, but you may never store it, log it, or pass it on. The three or four digit code printed near the signature strip, called CVV, CVV2, or CVC depending on the card network, is a verification value. It confirms the buyer physically holds the card at the moment of purchase. Once the transaction is approved, that number has no further legal use inside your business. This guide covers the rules, the checkout settings worth switching on, and the fraud patterns that hit gift and greeting card stores hardest. It does not explain how to sell card verification values. Trading stolen payment data is a criminal offence in the United States and most other countries, and no legitimate processor or gift supplier will work with a store that does it.
What the CVV is and why your processor asks for it
Card networks issue two verification strings. The magnetic stripe and chip carry one value. The printed code on the back of the card, or on the front for American Express, carries another. In a card-present sale the terminal reads the chip or stripe. In a card-not-present sale, meaning your online store, phone orders, or a wholesale gift order placed by email, the printed code is often the only proof you have that someone is holding the plastic.
Your payment gateway sends that code to the issuing bank as part of the authorization request. The bank replies with a match, no match, or not processed. A no-match response is a strong signal of a stolen card number, and most gateways let you decline those orders automatically.
The rule that decides everything: no storage after authorization
PCI DSS treats the CVV as sensitive authentication data. Merchants may transmit it to complete a single transaction. They may not retain it afterward in any form, encrypted or not. This applies to your order notes, your helpdesk tickets, your email inbox, a spreadsheet a staff member keeps, and any handwritten slip at a craft fair.
- Do not ask customers to email the code. Use a hosted payment page or tokenised form instead.
- Do not write the code on a packing slip for a gift order that a relative is placing for someone else.
- Do not store phone order details with the code attached after the charge clears.
- Do check that your gateway and shopping platform are set to auto-decline no-match responses.
If a cardholder disputes a charge and your records contain a stored CVV, you have created a compliance problem on top of the chargeback. The fine and the forensic audit cost more than the order was worth.
Why selling CVVs is not a business
Queries about selling CVV data usually come from people who have seen carding forums or fake vendor pages. Those markets are built on stolen card numbers, and the participants are targets for law enforcement, not business partners. In the United States, trafficking in payment card credentials falls under federal fraud statutes and carries prison time. Investigators at the FBI Internet Crime Complaint Center track these cases, and payment networks share fraud data across members.
For a gift shop, the practical risk is different and just as serious. A store that accepts obviously stolen orders becomes a funnel for chargebacks, gets flagged by its processor, and can lose the ability to take cards at all. Gift cards and high-value hampers are favourite targets because they resell fast.
Checkout settings that reduce gift order fraud
CVV plus address verification
Run both checks and decline when either fails. The CVV confirms the card is in hand. Address verification compares the billing street number and postcode with the issuer's file. Together they filter most casual fraud attempts on gift baskets, personalised prints, and subscription flower plans.
3-D Secure for high-value baskets
For orders above a threshold you set, such as corporate gift hampers or large greeting card assortments, ask the issuer to step in. The customer confirms the purchase in their banking app. Liability for certain fraud chargebacks shifts to the issuer, which matters when your average order value is high and margins are thin.
Manual review triggers
Flag orders where the shipping address differs from the billing address, where the same card is used across several recipient names, or where a first-time buyer orders six identical gift sets. A short phone call to the buyer resolves most of these in under a minute.
Verification methods compared
- CVV check. Pros: fast, invisible to the customer, cheap. Cons: only proves the card is present, not that the buyer is the cardholder.
- Address verification. Pros: catches mismatched billing details, works on phone orders. Cons: weak for gift orders shipped to a third party, and can fail on recent moves.
- 3-D Secure. Pros: strong authentication, chargeback liability shift. Cons: adds a step, and some buyers abandon at the bank screen.
- Manual review. Pros: catches patterns software misses. Cons: slows fulfilment and needs staff time during peak seasons.
Which setup fits your shop
- Single-person craft stall taking occasional phone orders: use a hosted payment page for every remote sale and never note the code anywhere.
- Online greeting card store with low order values: CVV plus address verification on by default, manual review only for mismatched shipping.
- Gift hamper or corporate gifting business: add 3-D Secure above your threshold and verify the buyer by phone for first orders over that amount.
- Shop with a physical counter and a web store: keep the two payment flows separate so card-present terminals and online gateways never share stored data.
The short version for any greeting card or gift seller: collect the CVV at checkout, send it once, keep nothing, and treat any offer to buy or sell card data as a legal problem rather than an opportunity.