Sorry for the confusion - the statement regarding pre-authorization was specific to CVV. "CVV was always purged after billing, as per processing requirements. However, because the hackers may have been able to access some data from orders in pre-authorization stage it was prudent to include that...