際際滷

際際滷Share a Scribd company logo
Online payments
June 2013
Alternative Models
Requires Online Merchant
Account
 Merchant gateway account
connected to bank online
merchant account
 Settlement typically 24 hours
 Examples:
 eWAY
 SecurePay
 TNSI (was Dialect)
 PayPal Pro
 Payment Express
 Various bank gateways
No Online Merchant Account
 Transactions settled to any
bank account
 Settlement period typically 2
days +
 Examples:
 PayPal (Standard & Express)
 Paymate
 POLi (Can be same day  but
generally 24 hours)
 Skrill (was Moneybookers)
 Google Checkout (USA)
 Braintree
Hosted vs Integrated
Hosted Payment Page
 PayPal style model
 Customer leaves the website
to pay
 Payment page hosted on
providers servers
 Payment page branding
 PCI Compliance
 Return to website for
confirmation of order
Integrated Payment Page
 eWAY style model (support
both)
 Payment page exists inside
merchants website
 Information not kept on
website
 Information transferred using
encrypted (HTTPS) URL, XML
or similar
 SSL encryption essential
 Stay on the website
Payment Gateway Flow
Website
Checkout
Transaction
sent to gateway
Credit Card
entered in
hosted page
Gateway
checks with
merchant
bank
Merchant bank
corresponds with
issuer bank
3D Secure
direct to
issuer bank
Some Payment Providers
Note: Not a complete list
Pro
Wallets Gateways Bank
Cross Section  Supported
Banks
Others
Sample Costs
Provider Setup
Fees
Annual
Fees
Volum
e
Rate
Trans
%
Fees Note
No Yes Yes No 0.15c  0.50c / trans Merchant account fees
No No Yes Yes 2.4% - 1.1% + 30c / trans No bank fees
No Yes Yes No 0.22c  0.45c / trans Merchant account fees
Yes No N/A No $55 / month Merchant account fees
Yes Yes Yes No 0.16c  0.24c / trans paid annually
in advance based on package
Merchant account fees
Yes Yes Yes No 0.10c  0.50c / trans based on
volume package paid monthly
Merchant account fees
Note: Publicly available information taken from vendors websites
 Install and maintain a firewall
 Do not use vendor-supplied defaults
 Protect stored cardholder data
 Encrypt transmission of cardholder data over open
networks
 Use and regularly update anti-virus software
 Develop and maintain secure systems &
applications
 Restrict access to cardholder data by business
need-to-know
 Assign a unique ID to each person with computer
access
 Restrict physical access to cardholder data
 Track and monitor all access to network resources
and cardholder data
 Regularly test security systems and processes
 Maintain a policy that addresses information
security
Build and Maintain a Secure Network
Protect Cardholder Data
Maintain a Vulnerability Management Program
Implement Strong Access Control Measures
Regularly Monitor and Test Networks
Maintain an Information Security Policy
PCI DSS Principles and Requirements
Website Security and Trust
 Hackers: exist and difficult to stop
 Increase in available hacker scanning and protection
systems
 PCI certified scanners listed 
www.pcisecuritystandards.org
 SSL Certificates: essential for an online
store that accepts personal details or
payments
 Many suppliers  128/256 bit encryption
 Make shopping both safer and more trusted
 Additional supplier Anti-fraud options
 eWAY  Beagle Alerts Anti-fraud integrated
 Retail Decisions (ReD)Technologies
Improving user experience
Your payment methods can be a marketing tool
 PayPal Express Checkout
 Customer and Shipping data provided by
PayPal
 Less information input by buyer online
 Offer multiple payment methods
 Consumer choice
 People without credit cards
 Integrated Anti-fraud detection
 Geographic, blacklists, IP checks, matching
etc
 Example  eWAY Beagle and Beagle Alerts
 PayPal  built-in anti-fraud
Ad

Recommended

How to identify credit card fraud
How to identify credit card fraud
Henley Walls
What Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSS
London School of Cyber Security
Psdot 16 a new framework for credit card transactions involving mutual authen...
Psdot 16 a new framework for credit card transactions involving mutual authen...
ZTech Proje
Block chain in banking industry
Block chain in banking industry
Yoshi
CheckPlus from Printech Global
CheckPlus from Printech Global
Printech Global Secure Payment Solutions LLC
Cheque truncation system (cts)
Cheque truncation system (cts)
SangitaChina1
Defending Netflix from Abuse
Defending Netflix from Abuse
Jason Chan
PACT-brochure
PACT-brochure
Robert Brasiel
Chameleon PCI Presentation
Chameleon PCI Presentation
christoboshoff
CS-Cart Addon - Braintree payment gateway (Version 2.2)
CS-Cart Addon - Braintree payment gateway (Version 2.2)
Webkul Software Pvt. Ltd.
E commerce payment systems
E commerce payment systems
Nishant Pahad
Secure electronic transaction ppt
Secure electronic transaction ppt
Subhash Gupta
Secure electronic transaction
Secure electronic transaction
Nishant Pahad
Loanet_AccountingSettlement
Loanet_AccountingSettlement
Anupam Biswas, MBA, CISA (pass)
CREDIT CARD FRAUD DETECTION
CREDIT CARD FRAUD DETECTION
K Srinivas Rao
Dwi Ebanking
Dwi Ebanking
Daniel Wamara
incuto Vision2020 launch event
incuto Vision2020 launch event
incuto Limited
Secure Electronic Transaction
Secure Electronic Transaction
United International University
Maria sparagis
Maria sparagis
Chiara DePaolo
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
Varun Mittal
Payment Gateway
Payment Gateway
ShujaShah
Payment Gatway.ppt
Payment Gatway.ppt
ssusere4c6aa
Payment Gateway
Payment Gateway
Nyros Technologies
Navigating Payment Processing | Jay Wigdore
Navigating Payment Processing | Jay Wigdore
JayWigdore
Payment Gateway
Payment Gateway
Ashraf Bashir
BA 65 Hour 5 ~ Creating an Ecommerce Site
BA 65 Hour 5 ~ Creating an Ecommerce Site
dpd
Trading Online Getting started and how to grow your business
Trading Online Getting started and how to grow your business
Secure Trading
How to Find the Right E-Payment Technology Provider
How to Find the Right E-Payment Technology Provider
PaymentAsia
E-commerce & WordPress: Navigating the Minefield
E-commerce & WordPress: Navigating the Minefield
Ingenesis Limited
Why Payment gateway integration is important.pdf
Why Payment gateway integration is important.pdf
Integrated IT Solutions

More Related Content

What's hot (12)

Chameleon PCI Presentation
Chameleon PCI Presentation
christoboshoff
CS-Cart Addon - Braintree payment gateway (Version 2.2)
CS-Cart Addon - Braintree payment gateway (Version 2.2)
Webkul Software Pvt. Ltd.
E commerce payment systems
E commerce payment systems
Nishant Pahad
Secure electronic transaction ppt
Secure electronic transaction ppt
Subhash Gupta
Secure electronic transaction
Secure electronic transaction
Nishant Pahad
Loanet_AccountingSettlement
Loanet_AccountingSettlement
Anupam Biswas, MBA, CISA (pass)
CREDIT CARD FRAUD DETECTION
CREDIT CARD FRAUD DETECTION
K Srinivas Rao
Dwi Ebanking
Dwi Ebanking
Daniel Wamara
incuto Vision2020 launch event
incuto Vision2020 launch event
incuto Limited
Secure Electronic Transaction
Secure Electronic Transaction
United International University
Maria sparagis
Maria sparagis
Chiara DePaolo
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
Varun Mittal
Chameleon PCI Presentation
Chameleon PCI Presentation
christoboshoff
CS-Cart Addon - Braintree payment gateway (Version 2.2)
CS-Cart Addon - Braintree payment gateway (Version 2.2)
Webkul Software Pvt. Ltd.
E commerce payment systems
E commerce payment systems
Nishant Pahad
Secure electronic transaction ppt
Secure electronic transaction ppt
Subhash Gupta
Secure electronic transaction
Secure electronic transaction
Nishant Pahad
CREDIT CARD FRAUD DETECTION
CREDIT CARD FRAUD DETECTION
K Srinivas Rao
incuto Vision2020 launch event
incuto Vision2020 launch event
incuto Limited
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
Varun Mittal

Similar to Accepting Online Credit Card Payments Review (20)

Payment Gateway
Payment Gateway
ShujaShah
Payment Gatway.ppt
Payment Gatway.ppt
ssusere4c6aa
Payment Gateway
Payment Gateway
Nyros Technologies
Navigating Payment Processing | Jay Wigdore
Navigating Payment Processing | Jay Wigdore
JayWigdore
Payment Gateway
Payment Gateway
Ashraf Bashir
BA 65 Hour 5 ~ Creating an Ecommerce Site
BA 65 Hour 5 ~ Creating an Ecommerce Site
dpd
Trading Online Getting started and how to grow your business
Trading Online Getting started and how to grow your business
Secure Trading
How to Find the Right E-Payment Technology Provider
How to Find the Right E-Payment Technology Provider
PaymentAsia
E-commerce & WordPress: Navigating the Minefield
E-commerce & WordPress: Navigating the Minefield
Ingenesis Limited
Why Payment gateway integration is important.pdf
Why Payment gateway integration is important.pdf
Integrated IT Solutions
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
Meetup #1 Fundamentals of Payments
Meetup #1 Fundamentals of Payments
ZOOZ2019
Paola Trecarichi - Pagamenti digitali: limportanza del Payment Provider nell...
Paola Trecarichi - Pagamenti digitali: limportanza del Payment Provider nell...
Stefano Saladino
Online payments Gateway Strategies By Jay Wigdore
Online payments Gateway Strategies By Jay Wigdore
JayWigdore
Get Paid presentation_20190123
Get Paid presentation_20190123
Peter Walker
Atp masha cilliers on apm cost reduction
Atp masha cilliers on apm cost reduction
Masha Cilliers
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
Online payments and Security Gateways
Online payments and Security Gateways
Sarujan Chandrakumaran
Payment Gateway
Payment Gateway
ShujaShah
Payment Gatway.ppt
Payment Gatway.ppt
ssusere4c6aa
Navigating Payment Processing | Jay Wigdore
Navigating Payment Processing | Jay Wigdore
JayWigdore
BA 65 Hour 5 ~ Creating an Ecommerce Site
BA 65 Hour 5 ~ Creating an Ecommerce Site
dpd
Trading Online Getting started and how to grow your business
Trading Online Getting started and how to grow your business
Secure Trading
How to Find the Right E-Payment Technology Provider
How to Find the Right E-Payment Technology Provider
PaymentAsia
E-commerce & WordPress: Navigating the Minefield
E-commerce & WordPress: Navigating the Minefield
Ingenesis Limited
Why Payment gateway integration is important.pdf
Why Payment gateway integration is important.pdf
Integrated IT Solutions
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
Meetup #1 Fundamentals of Payments
Meetup #1 Fundamentals of Payments
ZOOZ2019
Paola Trecarichi - Pagamenti digitali: limportanza del Payment Provider nell...
Paola Trecarichi - Pagamenti digitali: limportanza del Payment Provider nell...
Stefano Saladino
Online payments Gateway Strategies By Jay Wigdore
Online payments Gateway Strategies By Jay Wigdore
JayWigdore
Get Paid presentation_20190123
Get Paid presentation_20190123
Peter Walker
Atp masha cilliers on apm cost reduction
Atp masha cilliers on apm cost reduction
Masha Cilliers
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
SecureTrading Corporate Presentation 2010
SecureTrading Corporate Presentation 2010
Secure Trading
Online payments and Security Gateways
Online payments and Security Gateways
Sarujan Chandrakumaran
Ad

Recently uploaded (20)

Connecting Data and Intelligence: The Role of FME in Machine Learning
Connecting Data and Intelligence: The Role of FME in Machine Learning
Safe Software
Using the SQLExecutor for Data Quality Management: aka One man's love for the...
Using the SQLExecutor for Data Quality Management: aka One man's love for the...
Safe Software
Creating Inclusive Digital Learning with AI: A Smarter, Fairer Future
Creating Inclusive Digital Learning with AI: A Smarter, Fairer Future
Impelsys Inc.
"How to survive Black Friday: preparing e-commerce for a peak season", Yurii ...
"How to survive Black Friday: preparing e-commerce for a peak season", Yurii ...
Fwdays
Securing AI - There Is No Try, Only Do!.pdf
Securing AI - There Is No Try, Only Do!.pdf
Priyanka Aash
Tech-ASan: Two-stage check for Address Sanitizer - Yixuan Cao.pdf
Tech-ASan: Two-stage check for Address Sanitizer - Yixuan Cao.pdf
caoyixuan2019
Techniques for Automatic Device Identification and Network Assignment.pdf
Techniques for Automatic Device Identification and Network Assignment.pdf
Priyanka Aash
Security Tips for Enterprise Azure Solutions
Security Tips for Enterprise Azure Solutions
Michele Leroux Bustamante
Cluster-Based Multi-Objective Metamorphic Test Case Pair Selection for Deep N...
Cluster-Based Multi-Objective Metamorphic Test Case Pair Selection for Deep N...
janeliewang985
From Manual to Auto Searching- FME in the Driver's Seat
From Manual to Auto Searching- FME in the Driver's Seat
Safe Software
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
ICT Frame Magazine Pvt. Ltd.
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Safe Software
AI VIDEO MAGAZINE - June 2025 - r/aivideo
AI VIDEO MAGAZINE - June 2025 - r/aivideo
1pcity Studios, Inc
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
Priyanka Aash
Key Requirements to Successfully Implement Generative AI in Edge DevicesOpt...
Key Requirements to Successfully Implement Generative AI in Edge DevicesOpt...
Edge AI and Vision Alliance
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance
PyCon SG 25 - Firecracker Made Easy with Python.pdf
PyCon SG 25 - Firecracker Made Easy with Python.pdf
Muhammad Yuga Nugraha
"Database isolation: how we deal with hundreds of direct connections to the d...
"Database isolation: how we deal with hundreds of direct connections to the d...
Fwdays
2025_06_18 - OpenMetadata Community Meeting.pdf
2025_06_18 - OpenMetadata Community Meeting.pdf
OpenMetadata
Connecting Data and Intelligence: The Role of FME in Machine Learning
Connecting Data and Intelligence: The Role of FME in Machine Learning
Safe Software
Using the SQLExecutor for Data Quality Management: aka One man's love for the...
Using the SQLExecutor for Data Quality Management: aka One man's love for the...
Safe Software
Creating Inclusive Digital Learning with AI: A Smarter, Fairer Future
Creating Inclusive Digital Learning with AI: A Smarter, Fairer Future
Impelsys Inc.
"How to survive Black Friday: preparing e-commerce for a peak season", Yurii ...
"How to survive Black Friday: preparing e-commerce for a peak season", Yurii ...
Fwdays
Securing AI - There Is No Try, Only Do!.pdf
Securing AI - There Is No Try, Only Do!.pdf
Priyanka Aash
Tech-ASan: Two-stage check for Address Sanitizer - Yixuan Cao.pdf
Tech-ASan: Two-stage check for Address Sanitizer - Yixuan Cao.pdf
caoyixuan2019
Techniques for Automatic Device Identification and Network Assignment.pdf
Techniques for Automatic Device Identification and Network Assignment.pdf
Priyanka Aash
Security Tips for Enterprise Azure Solutions
Security Tips for Enterprise Azure Solutions
Michele Leroux Bustamante
Cluster-Based Multi-Objective Metamorphic Test Case Pair Selection for Deep N...
Cluster-Based Multi-Objective Metamorphic Test Case Pair Selection for Deep N...
janeliewang985
From Manual to Auto Searching- FME in the Driver's Seat
From Manual to Auto Searching- FME in the Driver's Seat
Safe Software
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
ICT Frame Magazine Pvt. Ltd.
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Safe Software
AI VIDEO MAGAZINE - June 2025 - r/aivideo
AI VIDEO MAGAZINE - June 2025 - r/aivideo
1pcity Studios, Inc
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
Priyanka Aash
Key Requirements to Successfully Implement Generative AI in Edge DevicesOpt...
Key Requirements to Successfully Implement Generative AI in Edge DevicesOpt...
Edge AI and Vision Alliance
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance
PyCon SG 25 - Firecracker Made Easy with Python.pdf
PyCon SG 25 - Firecracker Made Easy with Python.pdf
Muhammad Yuga Nugraha
"Database isolation: how we deal with hundreds of direct connections to the d...
"Database isolation: how we deal with hundreds of direct connections to the d...
Fwdays
2025_06_18 - OpenMetadata Community Meeting.pdf
2025_06_18 - OpenMetadata Community Meeting.pdf
OpenMetadata
Ad

Accepting Online Credit Card Payments Review

  • 2. Alternative Models Requires Online Merchant Account Merchant gateway account connected to bank online merchant account Settlement typically 24 hours Examples: eWAY SecurePay TNSI (was Dialect) PayPal Pro Payment Express Various bank gateways No Online Merchant Account Transactions settled to any bank account Settlement period typically 2 days + Examples: PayPal (Standard & Express) Paymate POLi (Can be same day but generally 24 hours) Skrill (was Moneybookers) Google Checkout (USA) Braintree
  • 3. Hosted vs Integrated Hosted Payment Page PayPal style model Customer leaves the website to pay Payment page hosted on providers servers Payment page branding PCI Compliance Return to website for confirmation of order Integrated Payment Page eWAY style model (support both) Payment page exists inside merchants website Information not kept on website Information transferred using encrypted (HTTPS) URL, XML or similar SSL encryption essential Stay on the website
  • 4. Payment Gateway Flow Website Checkout Transaction sent to gateway Credit Card entered in hosted page Gateway checks with merchant bank Merchant bank corresponds with issuer bank 3D Secure direct to issuer bank
  • 5. Some Payment Providers Note: Not a complete list Pro Wallets Gateways Bank
  • 6. Cross Section Supported Banks Others
  • 7. Sample Costs Provider Setup Fees Annual Fees Volum e Rate Trans % Fees Note No Yes Yes No 0.15c 0.50c / trans Merchant account fees No No Yes Yes 2.4% - 1.1% + 30c / trans No bank fees No Yes Yes No 0.22c 0.45c / trans Merchant account fees Yes No N/A No $55 / month Merchant account fees Yes Yes Yes No 0.16c 0.24c / trans paid annually in advance based on package Merchant account fees Yes Yes Yes No 0.10c 0.50c / trans based on volume package paid monthly Merchant account fees Note: Publicly available information taken from vendors websites
  • 8. Install and maintain a firewall Do not use vendor-supplied defaults Protect stored cardholder data Encrypt transmission of cardholder data over open networks Use and regularly update anti-virus software Develop and maintain secure systems & applications Restrict access to cardholder data by business need-to-know Assign a unique ID to each person with computer access Restrict physical access to cardholder data Track and monitor all access to network resources and cardholder data Regularly test security systems and processes Maintain a policy that addresses information security Build and Maintain a Secure Network Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy PCI DSS Principles and Requirements
  • 9. Website Security and Trust Hackers: exist and difficult to stop Increase in available hacker scanning and protection systems PCI certified scanners listed www.pcisecuritystandards.org SSL Certificates: essential for an online store that accepts personal details or payments Many suppliers 128/256 bit encryption Make shopping both safer and more trusted Additional supplier Anti-fraud options eWAY Beagle Alerts Anti-fraud integrated Retail Decisions (ReD)Technologies
  • 10. Improving user experience Your payment methods can be a marketing tool PayPal Express Checkout Customer and Shipping data provided by PayPal Less information input by buyer online Offer multiple payment methods Consumer choice People without credit cards Integrated Anti-fraud detection Geographic, blacklists, IP checks, matching etc Example eWAY Beagle and Beagle Alerts PayPal built-in anti-fraud