4 ms·
(I work for Gluejar on unglue.it) We've struggled with the issue of finding the right payment processor. We went originally with PayPal, but 7 months after we
by rdhyee 14y ago
(I work for Gluejar on unglue.it) We've struggled with the issue of finding the right payment processor. We went originally with PayPal, but 7 months after we submitted our application, we still don't have a decision (see http://blog.unglue.it/2012/05/03/unglue-it-payment-options-amazon-vs-paypal/ http://blog.unglue.it/2012/05/03/unglue-it-payment-options-a...). Amazon FPS was easy to get started with, and we got what seemed to be approval very quickly. So it was a bit surprising to then get shut down by Amazon after running for a while and demonstrating unglue.it works in practice.
We'd love to hear of alternative payment systems. I'm looking at using subscriptions in https://www.braintreepayments.com/docs/python/subscriptions/ https://www.braintreepayments.com/docs/python/subscriptions/ to simulate conditional payments. http://www.quora.com/Online-and-Mobile-Payments/What-payment-solutions-besides-Amazon-can-be-used-for-crowdfunding http://www.quora.com/Online-and-Mobile-Payments/What-payment... leads to https://www.wepay.com/ https://www.wepay.com/ and https://www.balancedpayments.com/ https://www.balancedpayments.com/ I'd love to hear of people's experiences with these payment systems and any others we should look at for unglue.it
- dangrossman 14y agoCan you not get a traditional merchant account provider to approve your business? If you accept credit cards yourself instead of through a 3rd party, just about every payment gateway supports storing customers' info to charge at a later time. You can also use something like SpreedlyCore to store the payment info and have the ability to switch to different payment gateways without losing the info.
- drone 14y agoI think you're referring to an Authorization, which is valid only for a limited time. To store enough details to re-bill a non-pre-auth transaction in the future will get you into PCI DSS Level D compliance, which is not cheap - to say the least. Full compliance with the PCI DSS with stored credit card data, including PAN and CVC generally requires a number of products/services from 3rd party vendors and a dedicated team to manage compliance. Then, you have the issue as to whether or not the card has the amount available in the future when you intend to charge it...
- dangrossman 14y agoNo, you simply send the card details to the payment gateway which vaults them. You get back a token to reference to make the actual charges in the future. You don't have to do an authorization up front. Virtually every payment gateway has such a feature. There's no need to implement storage on your own and take on the compliance burdens. If you use SpreedlyCore, for example, you point your signup/billing form to their server, which stores the card data then redirects back to your site, so the user never sees anything but your site yet the payment data never hits your server. If you use Stripe, for example, the form submission gets intercepted by JavaScript that sends it to Stripe instead of your server, then returns a token in a callback. If you use services like these, there's virtually no compliance burden at all. > Then, you have the issue as to whether or not the card has the amount available in the future when you intend to charge it... You'd have that issue whether you used a 3rd party processor or your own merchant account. Amazon Payments wouldn't have given them money when the customers' cards had no funds either. BTW: There is no PCI-DSS or PA-DSS level that allows storing of verification codes, for either businesses or payment software companies. The whole point of that code is that it's never stored.
- drone 14y ago"just about every payment gateway supports storing customers' info to charge at a later time." "No, you simply send the card details to the payment gateway which vaults them. You get back a token to reference to make the actual charges in the future. You don't have to do an authorization up front. Virtually every payment gateway has such a feature. There's no need to implement storage on your own and take on the compliance burdens." Neither Authorize.net nor MES do. (Two of the largest in the US, that I've been using for the past few years.) I only know of a few specialized players that offer such functionality.
- dangrossman 14y agoHuh? Both of them do. I've been using Authnet's vault for almost 8 years. I've also integrated with 8 other gateways that offer payment info vaulting. It's a standard feature for any competitive gateway at this point. http://www.authorize.net/solutions/merchantsolutions/merchantservices/cim/ http://www.authorize.net/solutions/merchantsolutions/merchan... http://merchante-solutions.com/files/MES_PaymentGateway.pdf http://merchante-solutions.com/files/MES_PaymentGateway.pdf I'm surprised you've been using these gateways for years and didn't know about these features. CIM is prominently advertised on the first page you see every time you log in to the gateway.
- armored_mammal 14y agoI guess the issue is that you have to store the CC number? With Braintree you could put customer CC numbers in their vault and then manually run the transaction later, but it'd cost you a flat fee plus a penny or two per/card/month. (They do support running validations without completing a transaction.) It doesn't seem like the end of the world, though. And the architecture isn't super complicated. I assume you already had to handle telling Amazon whether to go through with the charge or not after the time period? Maybe Amazon also was keeping track of the pledge amounts for you? (Contrib Id or Card Id, Pledge Amount, Campaign Id) doesn't seem like that crazy of a thing to store on your own system.