Authors

Showing posts with label mobile payment. Show all posts
Showing posts with label mobile payment. Show all posts

Friday, May 9, 2014

Are you Using a Mobile Payment System? Part II: Best Practices and Cyber Liability Insurance

Last week we introduced some of the basic policies and procedures a business owner should implement to keep their customers’ data and their business safe (Are You Using a Mobile Payment System? Part 1: Keeping Customer Data Safe).  We will finish the discussion this week by talking about being compliant and about insurance you may want to consider to further protect your business.

One more employee consideration

Aside from informing employees about how to handle, use, and store mobile devices it may be prudent to include background checks during the applicant screening and hiring process (bit.ly/1ftpQaA), if you do not already.  Some pre-hire background checks include requesting credit and criminal records (http://1.usa.gov/1uvVxV9).  Businesses that ask employees to handle payments, regardless if they are mobile device-based, have the right to require such background checks (http://1.usa.gov/1o36hbK).

Strategy for PCI compliancy

We introduced the concept of the PCI (Payment Card Industry) Security Standards Council and being compliant with their standards, but what does the entail?  The following table summarizes the responsibilities of the small business owner and the six goals that comprise “security best practices” (http://bit.ly/Oz1G1j).
Source: PCI Security Standards Council 
The PCI also has resources for small businesses, which they consider to be more vulnerable to security breaches than large companies, and several short videos to further demonstrate how retailers can protect consumer data (http://bit.ly/1rZWa5e).

What cyber liability insurance can offer

You may already have a comprehensive insurance policy or riders that protect your business incase of theft, fire, disaster, and even when essentials employee are unable to perform their duties.  As mobile payment systems and threats to these systems have evolved so has the insurance industry.  Cyber liability insurance is one such addition and “is designed to protect businesses” from:

Lawsuit damages
Lawsuit defense costs
Breach notice costs
Data restoration costs
Breach extortion costs (http://bit.ly/1iUntyb)

The following site includes a list of questions that can help you assess your level of risk and issues that should be discussed with an insurance agent (http://bit.ly/1rZK0sX).  Just a few of those listed include:

“What security controls can you put into place that will reduce the premium?
What is expected of you to reduce or limit the risks?
What and how big [of] a difference to your future premiums will a claim make?
Do all portable media/computing devices need to be encrypted?
Are malicious acts by employees covered?”

This source further suggests asking potential insurers if you, the small business owner, will have to participate in post claim tasks (e.g. alerting customers about the breach) or if they provide “a point of contact” to oversee all processes after a claim is initiated.

What might cyber liability insurance cost?

Of course costs vary by type of business, geographical market, and factors that impact your general policy (e.g. number of policies held, number of claims within a certain period) but according to one source “a cyber add-on to an existing liability policy might cost $300 a year while a separate policy could cost $1,000 or several multiples of that” (http://bit.ly/Sxrgqv).  Other sources state that policy premiums can be much higher (http://bit.ly/1shcr7Q).  Having cyber liability insurance may “pay off” even if a claim is never filled.  According to once source: “Cyber insurance also can help boost your business by giving customers and business partners more confidence in you” (http://bit.ly/Sxrgqv).

After a breach is detected

So, what do you do when you experience a security breach?  Insurers and IT security experts stress notifying the authorities and your insurance company as soon as a breach is expected. Also, finding and repairing the breach quickly is crucial, as well as keeping records of all procedures that were followed after the incident (in addition to having a good record keeping system to begin with; http://bit.ly/1uwoAb3).

Though no one ever wants to experience this type of disaster, taking precautions, being diligent in your practices, and being prepared is a must.  As our use and dependence on technology grows, with all the associated benefits and advantages such systems provide, it can only be assumed that business owners will need to be aware of possible security situations of which they will need to be aware.  

Kathy Kelley is a professor of horticultural marketing in the Department of Plant Science
Robert C. Goodling, Jr. is an extension associate in the Department of Animal Science

Thursday, May 1, 2014

Are You Using a Mobile Payment System? Part 1: Keeping Customer Data Safe

We have blogged a bit about mobile payment systems and the benefits they offer consumers and small businesses (Why You Might Want to Consider Offering Mobile Payments); however, what does a small business owner need to consider before implementing a system or when they switch mobile payment companies?  As with every business decision, the owner needs to do some research and make sure that the proper guidelines and procedures are followed to ensure a good experience for all. 

This week’s blog, the first of a two-part series, will focus on some of the security considerations pertaining to the device itself.  Next week’s blog will discuss measures, including insurance, small business owners can take to protect their businesses should the mobile device go missing or worse.  

What is at stake?

You very well could experience a security breach that (though not restricted to using a mobile device to collect payments but applicable to every method you use to collect cardholder data) with consequences that include:
An example of a mobile payment card reader.  Wikipedia.org
  • cost of reissuing new payment cards,
  • fines,
  • termination of ability to accept payment cards, and
  • "going out of business" (bit.ly/1iwnFUd).  
Still, even with these penalties, many businesses have been able to process credit cards with mobile payment systems without experiencing any problems.

Why is there so much concern about compromised data or a security breach associated with mobile devices? 

As you can imagine, and maybe it has happened to you, it is easier to misplace a smartphone or other mobile device compared to a register or computer that is either tethered to something or too heavy or bulky to just carry off without anyone noticing.

A safeguard that is suggested includes securely storing the device, in a safe for example, when not in use or fastening the device to a heavy, bulky item (such as a desk or counter) with a combination lock and cable, much as you would a laptop or desktop.  Concern is further based on “traditional security controls such as [anti-virus], firewalls, and encryption [not having] reached the level of maturity needed in the mobile space” (bit.ly/1ftLIm3). 

How can a small business owner using a mobile payment system protect customer data and their business?

Let’s first start with the device that you will use to collect payments.  A list of equipment and systems can be found here (Why Mobile Payment Systems Might Work for Your Business), but you’ll also need to consider device ownership, who can use the device, and (in certain instances) whether an employee can use the device for more than just collecting payments. 

If you are not already familiar with the PCI (Payment Card Industry) Security Standards Council, they work “to educated stakeholders (merchants, processors, financial institutes, and similar) about the PCI Security Standards…and promotes the awareness of the need for payment data security to the public” (www.pcisecuritystandards.org), in essence “keeping your customer’s payment card data secure.” bit.ly/1ix8PN3.  Retailers who accept credit cards are required to be compliant with the standards (next week’s blog will include an overview on how to be complaint).

Device ownership: BYOD vs COPE


The PCI strongly discourages what is referred to as BYOD (bring your own device), which involves employees using their own mobile device to process consumer credit card payments.  Instead the device should be owned by the business, regardless if it is used solely for “payment and acceptance for transaction processing” or for both business and personal tasks (bit.ly/1hayiqv).

Some companies do buy corporate-owned personally enabled (COPE) devices which they distribute to managers and other employees who process payments at remote locations.  In such instances these businesses permit employees to use the device for both business and personal use.  This allows the business to install and update software that might not necessarily be appropriate for an employee-owned device (bit.ly/1iCHYyj).  Updates can be pushed to devices and the business can seize the device when needed.  This particular arrangement is not unreasonable as employees are often provided with desktops, laptops, and tablets to use in their homes and when traveling. 

Basic mobile device security policies

Some of the more recognized security policies that you should implement:

•    Don’t store any sensitive cardholder data on the mobile device, or on any electronic equipment for that matter.  If you are using the smartphone or tablet and/or a mobile app to save customers’ addresses, birthdates, etc. for the purpose of keeping track of purchases (i.e. loyalty program) take steps to encrypt the data and only collect and store what is absolutely necessary. 

•    Be selective about what apps you download to the device and question why apps might need access to contacts, calendars, location services, etc. on the device.
Source: Pixabay.com

•    Require each employee who needs to have access to mobile devices to have a unique username and password.

•    Employees should be trained on how to properly use the device and owners should educate them on how to maintain device security. 

•    Don’t “jailbreak” or “root” your devices (iPhone, iPad, iPod touch, Android phone or tablets).  Jailbreaking or rooting a device allows the owner to download “additional applications, extensions, and themes” not available at the Apple App Store (bit.ly/1luD6Mb); however, Apple states on its website that doing could: shorten battery live, allow for security vulnerabilities, cause apps to crash, prevent future software updates, and similar (bit.ly/1iDCiEq).

•    Update your operating software.  Often you will get a notification but check the setting on each device often in case a push notification doesn’t go through. 

•    Keep apps up-to-date, too.

•    Beware of phishing emails (emails from individuals posing as legitimate companies with links to malicious software) and SMS texts.  Don’t click on any hyperlinks or URLs that look suspicious. 

All of these procedures, and other applicable best practices, should be included in your employee handbook and operations manual.  Just as you would expect your employees to adhere to a code of conduct when dealing with customers you should expect the same for those who have access to business-owned mobile devices.

No matter what type of device, mobile or stationary, that is used to collect payments it is the retailer’s responsibility to ensure that customer payments processed properly and that only the appropriate data is stored – and that it is stored correctly.  In next week’s blog we will continue the discussing and help you further ensure that you are operating a safe mobile payment system and have a policy in place for any issues that might occur with either a missing device or compromised cardholder data.

Kathy Kelley is a professor of horticultural marketing in the Department of Plant Science
Robert C. Goodling, Jr. is an extension associate in the Department of Animal Science


Monday, January 14, 2013

The Costs of Accepting Credit Cards

Credit cards are a payment staple for many consumers.  Although there are fees associated with processing credit cards, you should consider potential sales losses by not accepting them.  As I always stress, do your research to help you decide if/how you should process credit.  Below are some questions to ask to get you started.


In the U.S. alone, consumers collectively had over 609 million credit cards (Source: "The Survey of Consumer Payment Choice," Federal Reserve Bank of Boston, January 2010).  That's a lot of cards!  One of the main reasons small businesses don't accept credit cards are the fees associated with processing.  You will need to include this fee in your pricing strategy to determine if you will need to raise your prices. 

Questions you should ask:

1.  What fees are charged per transaction?  Do the fees vary?
Most credit card processors charge a per transaction fee plus a percentage of the total purchase price (for example, $0.30 per transaction plus 1.9% of the total purchase price).  Fees can vary depending on whether the customer is in the store and you swipe the card versus typing in a card number or paying online.  Also, the type of credit card may result in a higher fee (for example, an airline miles card usually costs more to process).  

Conversely, you also have the option to use a credit card processor that offers a flat rate like Square, Paypal, or Google Checkout.   

2.  Are there any other fees associated with processing credit cards?
Find out if there are other costs like monthly fees, regulatory fees, statement fees, etc. All potential fees should be spelled out clearly before signing a contract with a processor.

3.  How much will a terminal(s) cost?
A terminal is the actual machine in which you swipe the credit card.  Opt for purchasing rather than renting a terminal because rental fees are often exorbitant.  For example, purchasing a terminal may cost $200-$350 while renting could cost as much as $139 per month.

4.  Is the credit card processing system compatible with your online store?
You will want your processor's software to be able to connect with your online store so that both your brick and mortar sales and your online sales can be processed together.

Other tips:

-If you already have an established processor, give them a call and try to renegotiate your fees.  Processors sometimes charge higher fees for new businesses because of higher risks.  Being a loyal customer may save you some money! 
-Be wary of a processor that wants to charge you a setup fee.  You shouldn't pay a fee for the "privilege" of using their system.

To read more about credit card processing, check out these two great articles on Entrepreneuer.com-- "5 Questions You Must Ask Your Credit Card Processor" and "How to Cut Transaction Costs on Customer Purchases".

As an ag business owner, do you already accept credit cards?  Do you think that the convenience is outweighed by the fees?

If you don't accept credit cards, why not?  How frequently do you lose customers because you don't accept credit?

Thursday, June 21, 2012

Why Mobile Payment Systems Might Work for Your Business


Much has been written about mobile payment options and if you read any articles about this topic you find that one or two companies dominate the discussions; however, the list of businesses creating readers/apps/programs continues to grow.  Though not an exhaustive list, this article compares 19 of the currently available readers, such as Intuit GoPayment, Square, and Flagship ROAMpay (http://tinyurl.com/cq7t4r5).  

What equipment will you need?

For most basic operations you need at least one of the following:
  • Smartphone (e.g., 3rd generation iPhone running iOS 4.0 and higher, Android phone running 2.1 and higher, Blackberry)
  • iPod touch (2nd generation and newer running iOS4 or higher), or 
  • tablets (e.g. iPad and Android).

Others systems allow the business owner to expand their functionality when additional devices are used.  Square, for example, provides a card reader for “anywhere” payments but also turns iPads (running at least iOS5.0) into a Square Register with an additional app (squareup.com/register).   Do a thorough investigation of each reader you are considering.  Some are compatible with Android phones and/or Blackberry while others are not.   

Readers for swiping credit cards 

With credit card terminals already using card swipers to process payments, many businesses may feel the most comfortable investing in a mobile payment system that uses a similar type of tool.  

The most common type of reader for swiping cards is a “dongle” that plugs into either the headphone jack on a mobile device (for example, Square) or plug into the iPhones and iPads charger port (for example, Eventbrite, http://tinyurl.com/77bvczo).

Groupon has recently entered the market and instead of offering a dongle the company has decided that a wrap-around case as dongles could potentially snap off (http://tinyurl.com/6mhdlp6). Other systems with a wrap-around style include Mophie (http://tinyurl.com/26or6oy), and Chase Paymentech (http://tinyurl.com/7yd5dlz).  Yet another variable you’ll need to consider when selecting the right system for your business.  

Payments made with smartphone apps 

Google Wallet, which works with Android phones, has been around for about a year.  This mobile payment app first requires users to link their account with a Citibank MasterCard or load a Google Prepaid Card using any other credit card.  When at the store, customers “tap” their phone against a near field communications (NFC) reader/credit card terminal. (Apple recently announced that a iOS 6 Passbook will app is in the works, http://tinyurl.com/cq3ut82). 

More recently, FaceCash has emerged onto the mobile payment scene.  Instead of matching a customer’s signature with that on the back of their credit card to verify a purchase, “merchants use FaceCash to verify that [the customer’s] real face matches a digital image linked to [his or her] account” (https://www.facecash.com/).  

Like many other systems, customers activate their account prior to shopping.  During the registration process customers link their account with their checking or savings account (users also have the ability to load their card with cash at retail locations where FaceCash is used) and upload a government-issued photo (driver’s license or passport).  When at the retailer, customers tap their phone against the NFC reader or businesses use a CCD Barcode Scanner to scan the barcode on the customer’s phone and then compare the image in the FaceCash system with the person making the purchase.  FaceCash also allows the user to load loyalty program cards (e.g., airline frequent flyer accounts, supermarket frequent purchaser cards) which can be scanned at checkout.  A video that provides an overview can be found at: http://vimeo.com/17175906

Other payment options

PayPal is more recognized as a payment option for consumers who want to make online purchases without supplying their credit card number.  Instead, consumers authorize purchases at websites offering this option using their email and PIN number.  In 2011, PayPal had over 100 million active accounts worldwide (http://tinyurl.com/6leeyre).  

At least one home improvement store has implement PayPal as a payment option for customers.    In addition to using a card reader to swipe credit cards and accepting checks via the mobile device’s camera, businesses can process payments by asking customers to enter their telephone number and PIN on  the credit card process terminal. 

Comparison of costs for retailers

Transaction fees and other costs are likely to change as this technology becomes more widely used and as more competitors enter the marketplace.  Remember that you will need to consider the costs for processing each type of credit card you honor (can range from 1.74% to 3.7%), as well as whether there is a per-transaction charge (can range from $0.10 to $0.30).  

How might these fees add up during an average month and what might you expect to save annually?   Consider using websites such as http://tinyurl.com/cs4fwf4.  The site allows users to enter an expected monthly revenue, select whether credit cards are processed by swiping or being keyed-in, and see estimated costs for several different brands of mobile readers. 

Another question to think about: Based on your average customer transaction size – will one system provide more savings than another?

According to an article written about Groupon’s mobile payment system (1.8% transaction fee [2.7% for American Express] and $0.15 per transaction) compared to Square (2.75%  transaction fee but  no per transaction charge), Groupon’s system might be a better choice for sales greater than $15 while Square would cost the retailer less than Groupon for sales less than $15.00.  

An example that shows how these transaction fees impact sales: “On a $100 Visa transaction, Groupon would charge $1.95 vs. Square’s $2.75. That’s a 41% premium for Square” (http://tinyurl.com/6ncbxbn).  

Do this comparison for yourself based on common sales transactions you process.  With several variables to consider, including how you would prefer customer to “pay” for purchases, take the time to investigate several systems to find the best one for your business.  

Tuesday, June 19, 2012

Why You Might Want to Consider Offering Mobile Payments


Last week, I was at a restaurant where the serve took our order on her iPhone, swiped my credit card through a reader attached to an iPad, rotated the iPad screen toward me so that I could enter a tip and sign for my transaction using my finger, and asked me if I wanted a printed receipt or one emailed to me.    
The email receipt I received

Now, the transaction may not have been that much faster than a traditional restaurant transaction, but I did not have to wait for the receipt to print (or wait for the server to add a new role of paper to the receipt printer), search for a pen or use an electron stylus that is often tethered to credit card terminals, and calculate my tip.  I felt that the process was pretty seamless.  This restaurant used a system that involved both iPhones and an iPad register but several other systems exist where only one electronic device is needed to process a payment.  

You probably have head of Square (https://squareup.com/), among the number of other systems, which require a user to obtain a small scanner (most of which are provided free) that attaches to a smartphone, but several other systems exist.   This technology is evolving and you may find that you like a system that does not even require a consumer to use a credit card to make a purchase. 

In this posting I am going to touch on why you should investigate whether mobile payments could work for your business.

Consumer use of mobile technology

Recent statistics indicate that between 42% and half of all mobile phones used in the U.S. are smartphones (http://tinyurl.com/6q5rd5s) with capabilities that allow users to download apps they can use to make mobile payments.  Compared to the number of the consumers expected to own a smartphone at the end of 2012, 115.8 million, the percentage of users expected in 2015 is set to increase nearly 66% (http://tinyurl.com/cruhdlm).

So, that provides some insight about smartphone ownership, and we know from reports that the two most popular activities conducted on a smartphone are checking email and Facebook, but what about current data that describe purchasing using smartphones and tablets?  

  • During the first quarter of 2012 34% of tablet and 17% of smartphone owners had made at least one purchase on their devices.  
  • An even great percentage of smartphone owners (43%) used their device in a store “for a shopping purpose,” (http://tinyurl.com/8553tbh) which could include comparing product prices at other retailers and looking up product details.  

If over one-third of smartphone users are using their phones for these purposes it is possible that they may convert to mobile purchasers.  

Flexibility for businesses

I have shopped at a number of retailers where it would have been more convenient for me to make a purchase at a site other than where the cash registers were located.  Or, sometimes I have had to pay with cash or by check instead of with a credit card, my preferred payment method. According to one source, only 7% of transactions in the U.S. are completed with cash.  Hence, we are becoming a “cashless society” (http://tinyurl.com/d6wk5eg). 

Think about your business and situations where a mobile payment option might have been useful.

  • Residential landscape contractors and growers delivering product can collect payments immediately rather than invoice and wait for payments,
  • food and farmers’ market vendors,  agritourism businesses, and food tradeshow exhibitors  can provide more payment options, and
  • landscape nurseries can process payments in the tree lot after selecting plants with customers.  

Benefits mobile payments provide businesses 

Aside from flexibility these systems provide, businesses also benefit from their use:

  • These systems capture a fair amount of customer information, which can help the businesses create  a loyalty program (or take the place of an existing one),  
  • transaction funds are transferred to the business more quickly – reducing the duration from “days to hours” (http://tinyurl.com/893svvx), 
  • most mobile payment companies do not charge a setup fee or a monthly fee to use their system,
  • there may be little or no requirement to purchase equipment (if businesses already own the required smartphones/tablets), and
  • though percentage processing fees are applied to each transaction (can range from 1.74% to 3.7%) some companies have eliminated the per-transaction charge (can range from $0.10 to $0.30).      

In the next posting I’ll discuss a bit more about the different methods you can use to process mobile payments, including on that uses the consumer’s face to verify purchases!

Tuesday, December 6, 2011

Mobile Payment: A Direct Marketing Tool

The Penn State Extension Ag Entrepreneurship team, along with Ohio State and Minnesota Extension, have developed a series of webinars on social media and mobile technology for ag businesses (more information on the webinar series at http://www.cvent.com/d/lcq890).  These issues are especially pertinent for direct marketers who are rapidly finding that they need to engage their customers using these tools.

One of the webinar sessions will focus on mobile technology available for use by farm markets, farmers markets, roadside stands, and agri-tourism businesses to accept payments.  Chris Raines, Assistant Professor and webinar team member, was motivated to learn more about mobile payment following his own mobile payment experience when getting take-out.  So he purchased the needed attachment for his iPhone and tried it out.  Check out his blog post on his experiment and thoughts regarding mobile payment possibilities for direct marketers.