Thursday, December 17, 2009

The IRS and the Merchant Account

News from the IRS is that starting 2011, all merchants will be receiving 1099s from their credit card processing banks. What this means is the IRS will track credit card charges through your merchant account as income. For 99.9% of you, this is not an issue. For the other .1%... well, you got some work to do!

Of note: the IRS considers nonprofit organizations as prime money laundering targets, so these 1099s to nonprofits may be especially important.

Monday, December 14, 2009

82North and DonorMarket Certification

well, as we've said from the beginning, you don't know what you don't know!

82North (hence DonorMarket) are PCI Compliant and have contracted with McAfee for daily scans through their HackerSafe program. 82North has always been hacker safe and passed the first scan with flying colors - what else?!

Going forward, you can ask your constituents to download "securityadvisors" which will attach itself to the web browser and indicate the site's hacker safe protection.

82North has done everything it can to be on the forefront of ensuring your data's protection while continuing to provide a value-based product. Because DonorMarket uses the 82North software, DonorMarket has the same assurances in place.

Please contact us at 82North and DonorMarket with any questions you may have: 302-425-3658, 888-900-3658.

Happy Holidays! Betsey

Thursday, December 10, 2009

how to fill out the questionnaire

thanks for keeping track of this nonsense!

Ok, for the Metro Merchant Services questionnaire, you use a Completely Outsourced Shopping Cart (I hate that term, 82North is so much more!). If it requires you to answer something about a terminal, your use a Virtual Terminal - unless of course you actually bought a terminal and use it.

Once you have completed the survey, you may get a "Congrats you can fill out the SAQ-A" which is where all of 9 is N/A - you do not carry around any cardholder data on any media (meaning paper or hard drive or whatever) and all but one question for part 12 is YES. As I recall, there is one piece, again about media, which is N/A.

Later on the SAQ-A it will ask you to explain N/A - do so saying that no cardholder data is kept on any media.

Wednesday, December 9, 2009

Who is an "acquirer"?

Most of you have First Data as your acquirer; some will have a different acquirer if you process using CardFlax, PayTrans, BuyTrans, or ImpactPay.

But you are no longer allowed to send your SAQ-anything to your acquirer!

For MMS merchants ONLY, you are required to send your SAQ to:

ControlScan
ATTN: Christina Leighton
340 Interstate North, Ste 347
Atlanta, GA 30339

Non-MMS merchants should contact their service provider directly for more details.

PCI Certification

Ok, so you've dutifully filled out the questionnaire, and if you are lucky you get a message that says "you qualify for SAQ-A", and it provides it there for you. At the end of SAQ-A, you are told to send it to your acquirer. Same thing as if you went to the website I told you about.

Well here is the newest wrinkle I learned last night - you STILL get charged a monthly fee even if you are PCI Certified! What a racket this has become. I am told by MMS that when certified, you will be charged $4.95 per month - $8.90/mo if you require a scan. SAQ-A merchants do not require a scan, but don't expect them to lose out on a fee when they can claim you do need a scan.

Nothing about this process makes any legitimate sense and it is all a money making scheme.

I welcome your comments if you disagree!

Monday, December 7, 2009

PCI Compliance - one more piece

In filling out the SAQ-A for 82North and DonorMarket, I now realize there is a second piece of documentation (nearly identical to the first) which is required: the Attestation of Compliance, or AOC-SAQ-A.

So after completing SAQ-A, download and fill out AOC-SAQ-A.

Stay tuned for the exact location of where to send the completed forms.

Thursday, December 3, 2009

Some useful tools

Did you know Vertical Response (www.verticalresponse.com) gives non-profits 10,000 FREE emails per month? here is a shout out to that generosity!

And I hope everyone has signed up with Tech Soup (www.techsoup.com) which provides access to deeply discounted software and hardware.