How to get a merchant account - a series of hoops
danieltenner.com
danieltenner.com
I haven't processed CCs before, but I'd love to hear people's stories about it.
Are there any metrics showing my intuition is not correct?
I have not heard good things about Paypal. There are a lot of stories about people getting ripped off using paypal. And as a seller, it is risky. One scam is to buy something off of Paypal, report it as destroyed, and then ship back worthless material.
Paypal returns money to fraud victim, sends him to collections:http://consumerist.com/5041902/paypal-refunds-50-defraud-sic...
Customer gets billed twice, Paypal does nothing:http://consumerist.com/5048218/blockbuster-double-dips-in-pa...
Destroyed Item scam:http://consumerist.com/5159479/ebay-scammer-says-pc-destroye...
More complaints:http://www.consumeraffairs.com/online/paypal.html
So basically, I trust my bank's customer service, and I don't trust Paypal's customer service. So I view Paypal as a potential headache if I have a problem with a purchase. I have generally had good experiences with Amazon, so there is no negative association with that brand, but I don't feel like I really need more protection than my bank gives me.
You may buy through Paypal; but, most buyers don't.
I am very interested in any metrics that show using a well known branding like PayPal, Amazon, Google, etc.. gets less transactions than having your own Vias/MC gateway.
Barriers to entry can work for or against you.
Just something to think about when setting up a payment system - you might want to grow into needing a merchant account system before you deal with the financial and logistical overhead.
Hmm. That's never occurred to to me when ordering stuff online. I do make a judgment about the reputation of the seller, but the payment method really doesn't figure into that unless it's something off the wall.
We're likely to end up with a worse rate then US citizens would, but it's still better then no merchant account.
Here's their FAQ on the matter: https://www.paypal.com/us/cgi-bin/webscr?cmd=_payflow-pro-fa...
PayPal won't support you against chargebacks, and they cost more, but if you want to get set up without the headaches of applying to a bank, they're a great option.
I wonder what the process is like if you directly go through a bank.
In my experience, the bank will trust you if you say that you've implemented a secure, PCI-DSS way to store credit card details. They'll also trust you if you say that you store the numbers on the gateway.
The important thing is to convey that you're aware of the issues, and you've dealt with them.
There is a liability issue with storing card numbers on your own servers, which, iirc, is that if you are breached, the numbers are stolen, and you are subsequently investigated and found not to be in compliance with PCI-DSS, you could lose your merchant account.
I've been looking at those things lately since I'm working on an ecommerce platform and it will be my server dealing with the my customers (who sell on my platform)' gateway... It's rather complicated..
There's a pretty good summary on the wikipedia page but it basically comes down to maintaining competent system/network security, not storing auth data like CVV2 and never displaying full card numbers, restricting access to the card numbers to those who need it and traceably logging it when they do, writing up a "policy" document which consists of stuff like "employees shall not disclose their passwords" etc, and commiting to test (and log that you've tested) the whole setup every month or so. No big deal.
Most of it is kind of obvious. A decent operation is going to doing most or all of that stuff as a matter of course. It's just kind of a checklist really, formalising what you already know to be good practise. Nothing to be afraid of.
+1
This is not an insurmountable problem, but it does mark you as a likely target for all sorts of internet fraudsters that would otherwise not be bothered about yet another project management application.