Solutions for OTAs & TMCs | PCI Booking

PCI Shield

All Distribution Channels – whether OTAs, TMCs, Corporate Booking Portals – need to protect their customers’ sensitive information and protect their brands.  A breach can cost more than the revenues being produced and the updated PCI standards now require that parties at both ends of the reservation process be PCI Compliant.  

PCI Booking solutions enable the exchange of information containing reservation and payment data in a secure, standardized and stable environment.  Distribution channels are able to secure payments throughout their connected distribution network by leveraging standardized formats, frameworks and messages common to the hospitality industry.  PCI Booking delivers solutions with ease of deployment and implementation, proven PCI audit scope reduction and significant compliance cost savings.  Our solutions ensure end-to-end protection of e commerce data.


On-the-fly Tokenization

Eliminates multiple Payment Gateway tokenization schemas that are incompatible with each other.

Pull tokenization request (Inbound on-the-fly HTTP Request)

Allows interception of incoming API requests, capturing card data, encrypting and storing on secure PCI Booking servers. A token is then sent to the ecommerce server with the card data masked.

Tokenization push (On-the-fly inbound HTTP Responses)

Allows interception of returned API responses and relaying them to the API requester. Captured card data is encrypted and stored on secure PCI Booking servers and a token is sent to the eCommerce server with the card data masked.

iFrame Payment Capture

Secure iFrame Payment Capture

Customized forms that are displayed on the lodging’s brand website and provide for the card data entered to be tokenized and stored on secure PCI Booking Servers and the token is passed on to the customer server. This provides the means to collect payment information on a hosted system without exposing the underlying Application Systems to PCI Scope.

Token Replacement

Token Replacement – On-the-fly

Allows the distribution channel to use the card data in the API requests to 3rd parties by providing a token.  Distribution channels can use the end customer card in the API requests to third parties such as payment gateways or suppliers (hotels, car rentals, airlines) without the need to be exposed to the card data itself.

Multiple card payments with single token

the solution allows the use of a single token (card) for sending multiple destinations saving up to 90% in card processing fees.  A captured (and tokenized) card can be used for real time payment to multiple parties such as any supplier associated with a booking.  i.e. airlines, car rental companies, car rental firms, payment gateways etc.  CVV details may be included in requests.  Captured cards may also include security code data.

Card Storage

Secure Card Storage

Card data can be stored for an unlimited time on PCI Booking Servers. This will provide better service to returning customers by enabling quick check-in and check-out processes.

Secure Card Storage Controls

Addition and deletion of cards in storage is controlled by the customer. This enables a flexible card retention policy.

Secure Card Storage Query

Ability to query existing card data stored on PCI Booking Servers by custom references. Allows easy listing of cards related to a specific end-customer and enables the end-customer to select an already stored card without the need to maintain sensitive data on internal systems.

Control 3rd Party Access to Card Data

Allow third suppliers such as hotels to use the card data already captured by the distribution channel.  The same card can be used multiple times for different bookings with different suppliers.

Compliance with EU Directive