Direct answer
We will not write a guide about selling CVV numbers. A CVV is the three or four digit card verification value printed on a payment card, and buying or selling that data is payment card fraud in every market we serve. This page answers the useful question behind the request: how a greeting card and gift shop handles CVVs when it accepts payments, what the rules require, and what to do if someone offers you card data.
What a CVV is and what it is for
The CVV was created to prove that whoever is paying has the physical card, or at least the printed details, in hand. It is not a password and it is not a customer identifier you can keep on file for repeat orders.
- It appears on the card, never in a receipt, and never on a statement.
- It is used once, during the authorization request, to help confirm the card is present or the details are known.
- After authorization, card industry rules do not permit merchants to store it, even in encrypted form.
- Card networks treat it as sensitive authentication data, not as ordinary customer information.
Why trading CVV data is a crime, not a business
Card data sold on forums is almost always stolen from people who did not agree to the sale. That makes the transaction trafficked stolen property, and depending on where you are it can also count as identity theft, computer intrusion, or money laundering. There is no lawful marketplace, no licensing path, and no compliance program that turns it into a legitimate trade. Anyone presenting themselves as a broker of card data is either committing a crime or running a scam against the buyer.
What this means for a greeting card and gift shop
Gift and stationery shops take a high volume of small card payments, often by phone, at markets, or through a small online store. Those channels attract fraud attempts because the order values look harmless. A fraudulent order for a hundred greeting cards and a gift box is easy to place and easy to resell. The defense is not knowing how to buy card data. It is knowing how to protect the data your own customers trust you with.
Practical steps for your shop
- Use a payment processor that handles card data for you, so the numbers never touch your systems.
- Never write CVVs on order slips, in notebooks, or in a customer spreadsheet.
- Keep your point of sale software and card terminals on current, supported versions.
- Train staff to ask for the code during the transaction only, and never to record it.
- Review refund and chargeback requests quickly, since gift orders are a common target.
- Confirm your PCI DSS obligations with your processor, because they depend on how you accept payments.
If someone offers you card data
Do not respond, do not test the numbers, and do not send payment. Report the contact to your acquiring bank and to the national fraud reporting body in your country. Testing a stolen card number, even with a one dollar authorisation, is itself a criminal act and can end your merchant account.
The bottom line
There is no legitimate guide to selling CVV numbers, so we did not write one. If you sell greeting cards and gifts, the work worth doing is protecting the card data your customers hand you and keeping your own payment setup compliant with card industry rules.