Currently, users need to re-enter their credit card data with each new transaction (not subscription payments). The ideal solution would be to store card/payment details on our server but that incurs significant cost and time in both hardware/infrastructure and ongoing certification so is not something we will be doing for some time. In the meantime, we may be able to move towards this in a more limited way using the existing functionality available in the backends we use. For instance, Paypal allows repeat payments up to a user-specified limit and Bibit/RBS allows repeating transactions. However we go about this, it should be entirely abstracted from the consumer sites.
Primary beneficiaries will be U1 and the Software Centre.
This might be useful:
http:// aws.typepad. com/aws/ 2010/12/ aws-achieves- pci-dss- 20-validated- service- provider- status. html