Theatre Manager provides two different mechanisms for credit card authorization, along with two modes of operating each option (schedule "C" or Schedule "D" compliance mode). Both are PCI PA/DSS 1.2 verified.
There is a great deal more information found by clicking here concerning installation, setup, USB credit card swipes, PCI compliance, and card encryption.
Definitions
There is often confusion between the purpose of a bank and a service provider and understanding difference helps make sense of the authorization options available to you.
- Bank: A bank is where the money ends up at the end of the day. If somebody gives you money in any form (cash, check, credit card), you write up deposit slips and take it to the building at the corner on the main street. Banks are very bricks and mortar companies with charters to write loans, put your money is a safe, etc.
- Service Provider: A service provider is not a bank. Service providers are only in the business of authorizing credit cards on behalf of a bank and hold on to the money while it is electronically in transit to your bank. When you do your daily credit card batch settlement, the money in transit is transferred directly to your bank. In North America, there are about 15 major service providers such as Paymentech, Nova, 1st Data, Visanet, FMDS, etc. Some banks prefer working with some service providers - but generally most service providers can get your money to any bank.
The reason that service providers and banks are separate is historical. Banks started as local or regional entities in the USA. Most were not big enough to handle the infrastructure of authorizing credit cards. When cards became very popular in the 70's, they farmed out the business of authorizing cards to a service provider as an economical means of providing cards to their customers without the expense of hosting large computer centres.
Service providers provide the infrastructure to authorize cards and then then deposit YOUR funds in ANY bank.
This option for credit card authorization allows the venue to connect directly to one of the major service providers in the world - and avoid installing middleware like PCCharge. Theatre Manager talks directly to the service provider Paymentech who talks to your bank and places money in it at the end of the day.
For further information about setting up Paymentech Orbital, please click here.
This option requires that a middleware credit card server called PCCharge be installed on Windows machine behind the DMZ. A venue needs to set up a merhant account with one of the 15 +/- supported service providers (Paymentech is one of them). Installation is done using the standard PCCharge™ installers following the PCCharge™ Secure Implementation Guide.
For further information about installing PC Charge, please click here.
System Flow
With either solution, the money always gets to your bank account. You enter or swipe the card information into Theatre Manager and it sends all the correct information to the appropriate service provider. The following illustrates the difference in flow of the authorization. In either case, a merchant has to maintain a PCI compliant Office setup.
Advantages and Disadvantages
| |
Pro |
Con |
| Paymentech |
- supports CVV2 and address verification in USA AND Canada
- supports mutliple simultaneous credit card authorization which is more suitable for web sales, concert onsales spikes or large volume venues.
- faster authorizations (generally under 1 second)
- direct connection to Paymentech (one less software component to manage for PCI compliance needed as there is no local database)
- Always PCI compliant with no action required by you
- for Mac only venues, no 'black box' PC is required
- view card batches online from anywhere
- can be set up for easier remote authorizations
- world wide direct authorization capabilities - in 158 countries
|
- small monthly fee
- only operates as 'card not present' (means address verification and CVV2 only)
|
| PCCharge |
- supports CVV2, address verification and sending track II information
- connect to any number of service providers - North America only
|
- does one authoriztion at a time
- slower authorizations (approx 3 to 4 seconds)
- user must access the PCCharge server to view batch history
- some maintenance required to mange passwords and compress the pccw.mdb file when it reaches a threshold
- software upgrade every 2 years to meet ongoing PCI PA-DSS compliance when Visa changes PCI requirements
|