1. Is the card information (including name, exp date, CSC/CVV, zipcode) ever stored locally or in domains Database?
If yes then its not compliant and poses a security risk. It needs to be as part of the paypal API in a secured area. So that paypal handles the data not the local browser or server.
If not read here please
https:///...ieve-pci-compliance/
Thanks