# Privacy and Payments

## Privacy and Payments

- Forter’s order validation call should be executed **between payment authorization and payment capture.** This positioning is important because the request to Forter uses the authorization response data. Based on the configuration, the payment capture either can or cannot be executed if Forter returns a “decline” decision.

- When the **Auto-invoice when transaction is approved** option is checked, the payment capture will be executed on approval.

- When a **decline** response is received, the action taken regarding voiding the payment depends on the merchant’s chosen configuration setting. Merchants can opt to void the payment manually or automatically, either immediately.

- Forter complies with and exceeds the requirements of **PCI DSS standard level 1,** and **Forter is PCI Level 1 Certified**.

Please note that **Forter does not collect full PAN** and that Forter is committed to the appropriate protection of the parts of Cardholders’ Data that it collects; this is achieved by a thorough hardening of the full Cardholders’ Data Environment (CDE).
