Announcement

Collapse
No announcement yet.

Payment details captured.

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Payment details captured.

    Hi,

    We currently use PayPal on our website to process the payments, unfortunatley this appears to put some customers off and also causes payment problems from some buyers. The consequence is we are losing sales!

    I dont like the way it also tries to encourage people to sign up to paypal.

    I have been made aware of an alternative, to set up our site simply to capture the customers details (including CC info) which we then download and process via our instore terminal at a later point.

    I appreciate this may be more work but it will be well worth it if the sales increase by the amount I think they will and it is no more difficult than a telephone sale.

    The config seems relatively easy on the site, is it just a case of getting the relevant parts of the site on SSL?

    Are there any other issues that we may see?

    Any advice appreciated.

    Thanks
    Steve

    #2
    You can't do this any more, even though older versions appear to let you. Search for PCI compliance on here for reasons why. You need to sign up with a PSP.
    Reusable Snore Earplugs : Sample Earplugs - Wax Earplugs - Women's Earplugs - Children's Earplugs - Music Earplugs - Sleep Masks

    Comment


      #3
      Ok, now every time I read about PCI I just feel like I'm incredibly stupid because it has me totally bamboozled.

      Now the general message seems to be you can’t capture credit card details you have to use a PSP, and if you don’t use a PSP you will be hunted down and shot. Or at least be in a whole heap of trouble.

      But then I hear that it’s not compulsory at all. And a quick google search throws up hundreds of people selling SSL certificates specifically for encrypting credit card details.

      So what really is the deal with all this? Because I honestly think that SSL would be best for our site. But at the moment we’re using paypal or having customers place their order in our actinic site then phone us with their card details. Not ideal!! But PSP just seems expensive and limited to the service it provides.

      So if anyone could give some advice to a PCI idiot I’d be most greatful!!

      Comment


        #4
        Here's a interesting place to start:
        https://www.pcisecuritystandards.org/

        Funnily (ironically?) all the site's pages are on SSL

        Comment


          #5
          If you wish to offer secure card payments you must now use a PSP, you will be breaking the contract between you and your credit card processing bank if you are not PCI compliant (downloading credit cards details) and should a incident arise you could be held liable for any loss the bank makes. By saying it is not compulsary is quite true if you only accept paypal payments but the moment you think about downloading cc details it becomes compulsary.

          It all seems like a very confusing set up, but someone like actinic payments is a lot easier than it sunds to a, add to your site and b, use.

          The idea behing PCI is to limit the number of people that come into contact with sensitive card details and to prevent unauthorised viewing of them, generally if you have details waiting to download and someone breaks in and nick your pc with actinic on they have full access to someones card details. Meeting PCI will remove this risk.
          www.parklifeclothes.co.uk

          Parklife, Whitby

          Diesel, Converse, Crocs, Quiksilver, Miss Sixty, Scotch & Soda, Bench, Levi's, Kickers

          Comment

          Working...
          X