How PCIDSS Affects Membership, Subscription, and Continuity Web Sites

How PCIDSS Affects Membership, Subscription, and Continuity Web Sites

New, tougher regulations from the credit card authorities will affect all membership and subscription businesses as PCIDSS increases the standards for the way business owner handle consumer data

PCIDSS

Web businesses are considered a high-risk environment as the card holder is not present when making a purchase or when signing up to a membership with a recurring subscription.

PCIDSS - Payment Card Industry Data Security Standard will challenge all web vendors and expect them to pass a test to continue taking cards

Accepting credit card payments for your membership site means you have to comply or face large fines, or even have your card facilities taken away

Payment Gateway

A provider that authorizes credit card payments. The request for payment reaches the payment gateway company and they will decide to accept or decline the payment for various reasons. The payment gateway company then provides MemberGate with the results and the transaction is updated automatically on the website.

Merchant Account

A bank account that allows a business to accept credit card payments. The transaction runs through the payment gateway will be sent to the bank who will then deposit the fees collected into this bank account. The bank has to be a reseller for one of the payment gateways .

  • Examples of merchant accounts include Chase Paymentech, Wells Fargo, BB&T Merchant Services
  • **Stripe allows you to accept payments without a merchant account.
Token System and Compliancy Tests

Security is of utmost importance when collecting payments online. You only want to use a payment gateway company that uses a token system. The token system stores the customer's credit card information at the payment gateway level. When accepting payments online, you have to pass a PCIDSS (compliancy) scan to make certain that your customer's credit card details are not at risk . Since you are not storing credit card information on your site when using a payment gateway, you are more likely to pass a compliancy test easier.

Checkout our FAQ about Token Systems and PCIDSS page for more in-depth information.

**MemberGate Software allows you the ability to use a Token System for payment processing. This means that your charges whether processed as subscription fees collected through recurring billing or non-recurring billing or charges made through your shopping cart all meet the highest safety standards.

Here is a visual representation to aid in the process:

How PCIDSS Affects Membership, Subscription, and Continuity Web Sites


Recurring Billing

The recurring billing process is taken care of and processed at the MemberGate level. Recurring billing allows you to automatically process subscription payments for your members every X amount of time. (X could be every month, every year, every three months etc)

Most payment gateway companies also have a setting to allow recurring billing payments. It is not necessary to sign up or pay for that addon. It is included in the MemberGate software.  


So Which Service Should I Use?

Which method that is used is going to be dependent on what works for you and is dependent on a few variables. One of the main variables is where your business is located. The payment gateway companies are growing wider as far as which countries are supported, but you'd have to check with each one to see if your country is supported. The supported countries continuously change, so the best bet is to visit the payment gateway for more information:

Stripe's Supported Countries
Authorize.Net's Supported Countries
Braintree

There are also going to be different fees to pay for each of the different payment gateway types. For example, if using authorize.net there are fees for the payment gateway and a different set of fees for the merchant account.

Since Stripe doesn't include the necessity for a true merchant account, the fees will be lower. 

Finally, it might be a consideration of which card types the payment gateway accepts. If there are specific ones that you would like to offer, it may narrow down your payment gateway company options.