Thursday, August 12, 2010

the continuing PCI discussion

Many of you are now keenly aware of PCI Compliance and its burden on merchants. For online merchants it is the single most expensive piece of the merchant account! I have spoken to Rep. Mike Castle's office about the burden of PCI Compliance during the discussion of the debate on the financial services industry and will continue to discuss it in the future.

There are some facts which are coming to light:

You have 30 days from the opening of your merchant account to complete the survey sent via email. For merchants using Metro Merchant Services, please contact me and I will walk you through the survey. You should result in a "SAQ-A" merchant category with N/A as the Question 9 list of responses and Yes as the Question 12 answers.

If you do not complete the survey within the 30 days, you will be assessed a monthly $20 noncompliance fee. Ouch!

But there is some good news with this - if you change your merchant account and have satisfied the PCI Compliance questionnaire through your original merchant account, you do NOT have to start over. You are in compliance for the duration of the original certificate. For some of you I have laughed and said to frame the certificate. Little did I know that was true! Keep that certificate so you can show your compliance through its expiration date. You'll be notified 2 months prior to expiration for a renewal. Same is true for you who have merchant accounts through other providers and are switching to our lower cost solution.

And above all, 82North and DonorMarket are compliant services, connected to the PCI-certified Metro Payment Gateway. If you are using a web-based donor/member database, make sure your solution is PCI certified. Security breaches are happening more frequently as more people use the internet for financial transactions!

Call me at 888-900-3658 or 800-979-0082 if you have questions.

Betsey

Wednesday, May 26, 2010

Visa Card Transactions and 82North

82North brings this to you because we are part of that ability to accept electronic payments without the headache. Yes, duly noting transparency, there is a monthly fee of $8.90, 82North is a PCI Compliant service using the MMS merchant account and online gateway - and still is the most cost effective in the industry.

...

Visa Card Transactions Rose 14%
As electronic payment volume continues to rise, corporations can streamline their operations by outsourcing electronic payment reconciliation management, active exceptions management and PCI compliance. Visa processed 9 billion transactions in the U.S. last quarter, up 14% from the year prior. Visa's debit card transactions were up 19% and credit card transactions were up 2% over the year prior. Electronic bill payments provide many benefits to the company accepting them; however, they also can create headaches in the form of managing payment reconciliation, exceptions and PCI compliance. By outsourcing treasury management, companies can continue enjoying all the benefits of accepting electronic payments without the headache.
Source: Digital Transactions News, April 29, 2010

Thursday, February 4, 2010

Online Donations and State Regulation

Thank you to Susan Detwiler (Bloom Metz Consulting)who brought up recent discussions surrounding online solicitations and the effect it has on state regulations for nonprofit registration. To explain, for an organization to solicit funds in a particular state, that organization has to register with that state. Pennsylvania is particularly adamant about this, and of course it does not come without expense - a few hundred dollars for each state's registration.

For most of you, this does not present a problem - you are local organizations soliciting your local constituency, even if you cross borders with DE, NJ and PA. The problem Susan mentioned was a zoo in MD sending a letter to PA - but we have no idea how the state regulators got involved.

The end result? Just know that if you decide to send wide-spread solicitation letters to, perhaps, people you do not know, you may run into regulatory issues. But if your solicitees know who you are, you should be fine.

It is always something, isn't it? If you have run into this, please let me know! And if you are truly concerned, your CPA will know the IRS regulations.

Thursday, January 7, 2010

Happy New Year!

Thank goodness 2009 and that "ought" decade is over - we can start afresh with a new year and a new decade!

Some people have been asking about online auctions and 82North. Quite frankly, there are some players in the online auction business with which 82North cannot compete (one rhymes with see-grey) and sees no reason to reinvent that wheel. However, perhaps what you want to do doesn't need that service from see-grey. depending on what you are hoping to do, you can create an 82North site which has a picture of the items being auctioned, then a currency field for the bid amount. At the end of each day (or the next morning) you can go in and update the site to give that day's minimum bid. This might be preferable when you have silent auction items for which you are generating interest before your event, but the items' purchase will conclude at your event. One thought if you do that - give a "Buy It Now" price so if someone wants the items but cannot make it to your event, you'll still be reaping in the big bucks - and acknowledging a good supporter of your organization.

If you provide this type of site on 82North, it is IMPORTANT!!! that you declick "collect payment information" on the 5th page of the Create an Event process. If you do not declick that button, the site will try to charge a credit card for the bid.

And what are the benefits of having an 82North site do your online bidding?
1. if you are a "multiple sites" client, it costs you nothing
2. you let the bidders create the bidding sheet - you don't have to do it through emails to you
3. you have the ultimate control on the site.

Send us your fresh ideas and we will highlight them through the year.

Happy 2010!

82North
Betsey Moran

Thursday, December 17, 2009

The IRS and the Merchant Account

News from the IRS is that starting 2011, all merchants will be receiving 1099s from their credit card processing banks. What this means is the IRS will track credit card charges through your merchant account as income. For 99.9% of you, this is not an issue. For the other .1%... well, you got some work to do!

Of note: the IRS considers nonprofit organizations as prime money laundering targets, so these 1099s to nonprofits may be especially important.

Monday, December 14, 2009

82North and DonorMarket Certification

well, as we've said from the beginning, you don't know what you don't know!

82North (hence DonorMarket) are PCI Compliant and have contracted with McAfee for daily scans through their HackerSafe program. 82North has always been hacker safe and passed the first scan with flying colors - what else?!

Going forward, you can ask your constituents to download "securityadvisors" which will attach itself to the web browser and indicate the site's hacker safe protection.

82North has done everything it can to be on the forefront of ensuring your data's protection while continuing to provide a value-based product. Because DonorMarket uses the 82North software, DonorMarket has the same assurances in place.

Please contact us at 82North and DonorMarket with any questions you may have: 302-425-3658, 888-900-3658.

Happy Holidays! Betsey

Thursday, December 10, 2009

how to fill out the questionnaire

thanks for keeping track of this nonsense!

Ok, for the Metro Merchant Services questionnaire, you use a Completely Outsourced Shopping Cart (I hate that term, 82North is so much more!). If it requires you to answer something about a terminal, your use a Virtual Terminal - unless of course you actually bought a terminal and use it.

Once you have completed the survey, you may get a "Congrats you can fill out the SAQ-A" which is where all of 9 is N/A - you do not carry around any cardholder data on any media (meaning paper or hard drive or whatever) and all but one question for part 12 is YES. As I recall, there is one piece, again about media, which is N/A.

Later on the SAQ-A it will ask you to explain N/A - do so saying that no cardholder data is kept on any media.