Live data from Hacker News

Why we ditched PayPal for Stripe

gc-taylor.com

41–50 of 120 posts

Re: Why we ditched PayPal for Stripe

#41

The post is spot on. My initial attraction to Stripe was because of a reason mentioned in the post: not wanting to redirect or otherwise interrupt the normal order process of my site with another company's (branded) checkout form just to handle credit card payments. The other reason for initial attraction was of course their elegant API, which was very refreshing to see after having dealt with Intuit's QBMS API ( shu…

> not wanting to redirect or otherwise interrupt the normal order process of my site with another company's (branded) checkout form just to handle credit card payments. That's a restriction only for the free accounts. With the Pro account ($30/month) you use the API and your customers never leave your site.

But doesn't that API require you to submit the card number to them from your server and hence makes you have to do a ton of PCI compliance work?

Re: Why we ditched PayPal for Stripe

#42
post #36
post #32

Earlier quoted context omitted.

We at Stripe (and more importantly, our PCI auditors) don't agree with this assessment of how the chain of responsibility works. When you use Stripe.js, you need only serve your page over SSL and verify that you aren't collecting credit cards through other means to be PCI compliant.

We don't do PCI assessments (I have a generally low opinion of the process), but we do the "real" appsec work for lots of companies that do, and the impression I have is that --- counter to what you'd expect --- 'boucher is right, and you can self-assess using their interface, despite the fact that anyone doing so is in fact an XSS flaw away from giving up cards. In particular, while I have no idea whether Stripe's i…

Interestingly, PayPal actually offers (or offered?) an iFrame checkout for some customers and it was confirmed to be PCI-compliant. But again, another PCI auditor might have another opinion on it :)

Re: Why we ditched PayPal for Stripe

#43
post #34

Earlier quoted context omitted.

That's somewhat a fair point, but I'll disagree. In that instance, the co-founder replied, but I've heard from a number of Stripe's other employees since then, and in every case the customer support has been wonderful. Perhaps that's solely because they are still a startup, but given what I know now about the people themselves, I don't believe that to be the case. I don't mean my original comment to suggest that the…

I am curious if you've ever actually called PayPal. I have received nothing but high quality support from them. You can call them throughout most of the working day (until 8pm PST, I believe), and they seem to have somewhat knowledgable engineers available at that tech tier. They also have a merchant technical support site that seemingly no one knows about where you can often get answers in the middle of the night (I…

I have called PayPal once before. The experience wasn't horrible, but it didn't leave me enthusiastic like Stripe's does. I'm not holding that against them though: it's only one mediocre experience, and I have not used them much because of the whole payment redirection thing (I did not know about their Pro account then).

To be clear: I'm not actually saying that PayPal is bad. I don't have enough experience with them to weigh in one way or the other. I am merely saying that I do like Stripe.

I'm not sure of Stripe's reasoning behind not resending webhooks, but I don't know that I care for them not resending them either. Perhaps this is something they'll be addressing in the future or otherwise have a legitimate reason.

Re: Why we ditched PayPal for Stripe

#44

The better question would be "why wouldn't you ditch paypal for stripe?" Stripe is much easier to integrate than the x.com/paypal.com family of conflicting api's, all of which lack easy to read documentation. https://cms.paypal.com/us/cgi-bin/?cmd=_render-content&c... Compared to https://stripe.com/docs Stripe doesn't have a history of randomly locking accounts, and even if they do (if you process payments, I can und…

I can only see two reasons why someone might need PayPal rather than Stripe: if the business resides outside the US, or if they need to take methods of payment other than credit cards. Other than that, Stripe seems like a no-brainer.

I'd love to use Stripe, however the 2.9% fee is a total deal breaker. I'm currently using Payflow Link (by PayPal and Verisign) and I pay a flat rate of $20 a month plus 500 incl monthly transactions. I can get more at 0.10 per transaction. And after that it's all done with my Merchant account, which I've been able to negotiate down below 2%.

When you're doing hundreds of thousands of dollars (or more for you big guys) in credit card transactions, eating 1% just for a friendly API is a huge turnoff.

Please Stripe, prove me wrong and provide an external merchant account option!

Re: Why we ditched PayPal for Stripe

#45
post #34

Earlier quoted context omitted.

That's somewhat a fair point, but I'll disagree. In that instance, the co-founder replied, but I've heard from a number of Stripe's other employees since then, and in every case the customer support has been wonderful. Perhaps that's solely because they are still a startup, but given what I know now about the people themselves, I don't believe that to be the case. I don't mean my original comment to suggest that the…

I am curious if you've ever actually called PayPal. I have received nothing but high quality support from them. You can call them throughout most of the working day (until 8pm PST, I believe), and they seem to have somewhat knowledgable engineers available at that tech tier. They also have a merchant technical support site that seemingly no one knows about where you can often get answers in the middle of the night (I…

I second that. I've had to call PayPal a few times due to integration issues and the people on the phone (all 4 I spoke to) were beyond kind and helpful.

Unfortunately, everyone is coming out the woodwork now to get their two shots in while PayPal is down.

Re: Why we ditched PayPal for Stripe

#46
The usual gripe - my company is based in New Zealand, and it's well nigh impossible to open a US bank account so we can't use Stripe or Wepay. I'd love to know how many of PayPal's merchants are non-resident, it's the only reason we use them.

In fact, if it wasn't for PayPal non-US websites selling to the US would be almost impossible. The US has a massive advantage in that the rest of the world is happy to pay in US dollars, but US citizens won't pay in other currencies.

So here's a very lucrative challenge, Stripe and Wepay: the one that figures out how to allow non-residents to set up an account first simply has to post the news to HN and will be flooded with new accounts. I'd switch within 24 hours if there was a viable alternative to PayPal.

Re: Why we ditched PayPal for Stripe

#47

The better question would be "why wouldn't you ditch paypal for stripe?" Stripe is much easier to integrate than the x.com/paypal.com family of conflicting api's, all of which lack easy to read documentation. https://cms.paypal.com/us/cgi-bin/?cmd=_render-content&c... Compared to https://stripe.com/docs Stripe doesn't have a history of randomly locking accounts, and even if they do (if you process payments, I can und…

I can only see two reasons why someone might need PayPal rather than Stripe: if the business resides outside the US, or if they need to take methods of payment other than credit cards. Other than that, Stripe seems like a no-brainer.

Josh, you are failing to recognize other reasons why a business might still consider using Paypal as their merchant account provider. Here are ours:

1) Costs. We pay 2.2% + $0.30 USD per transaction vs. Stripes' 2.9% + $0.30 USD per transaction. At our transaction rate, that makes a difference in received revenue.

2) Moving. Refactoring a well established business to interface with a new payment provider can be a costly and expensive process. Think of switching personal banks.

3) Fraud. Paypal probably has the most advanced fraud protection in the online business today. If you deal in any decent amount of online payments you will find this to be a huge issue.

Additionally, we have our own dedicated Paypal account manager that actively reaches out to us and keeps in contact, and we can instantly call a direct line to this person if we need assistance with an issue.

With that said, our team is actively looking at Stripe because we like the ease of use when it comes to reoccurring payments, which we don't do at this time but plan to implement in the coming year. From what we see, reoccurring payments are a messy with Paypal and I'm not satisfied with Paypal's solution compared to their competitors like Recurly, Chargify, and, well, Stripe. But I am impressed with what Stripe has to offer on all fronts. Especially their API which appears to be very easy to use. ...And, they have a nice looking reoccurring payments process which fits our vision nicely.

Anyway, disclaimer: we run between 50K and 100K a month through Paypal, so that is probably why we get fantastic support from them and better pricing.

Re: Why we ditched PayPal for Stripe

#48
post #32
post #26

Earlier quoted context omitted.

The external javascript library is still being loaded on a page served from your domain, so it's totally possible for you to grab the credit card data and ajax it to your server (or for an XSS vulnerability to allow a 3rd party to send it somewhere). Since the CC info is accessible to both the client and Stripe, both are liable for PCI compliance. [edit: just to be clear, with stripe, you aren't liable for all of the…

We at Stripe (and more importantly, our PCI auditors) don't agree with this assessment of how the chain of responsibility works. When you use Stripe.js, you need only serve your page over SSL and verify that you aren't collecting credit cards through other means to be PCI compliant.

This seems like a risky compliance hack to be relying on. While it might conform to the letter of the law[1], it absolutely does not comply with the spirit of PCI compliance in regards to securing cardholder data.

There's literally no security difference between processing the card transaction through your own servers, and processing it client-side via HTML/JS that your servers are providing (and can modify).

[1] I wouldn't have thought this would meet compliance requirements, but I'm not a PCI expert -- I've only had to work on compliance on the user side, and deal with the auditing requirements.

Re: Why we ditched PayPal for Stripe

#49

Earlier quoted context omitted.

> not wanting to redirect or otherwise interrupt the normal order process of my site with another company's (branded) checkout form just to handle credit card payments. That's a restriction only for the free accounts. With the Pro account ($30/month) you use the API and your customers never leave your site.

But doesn't that API require you to submit the card number to them from your server and hence makes you have to do a ton of PCI compliance work?

Would like to know more about this- i thought the whole point of it was that you didn't have to deal with PCI...

Edit: i just checked; https://www.paypal.com/pcicompliance

It looks like Paypal takes care of PCI compliance only if you use; PayPal Website Payments Standard, Email Payments, or Payflow Link. Otherwise you're on your own.

Re: Why we ditched PayPal for Stripe

#50
post #46

The usual gripe - my company is based in New Zealand, and it's well nigh impossible to open a US bank account so we can't use Stripe or Wepay. I'd love to know how many of PayPal's merchants are non-resident, it's the only reason we use them. In fact, if it wasn't for PayPal non-US websites selling to the US would be almost impossible. The US has a massive advantage in that the rest of the world is happy to pay in US…

In tepid defense of US customers - even US banks can't really figure out foreign currency. We went to the bank in Bloomington, Indiana to exchange some Euros we had laying around and they literally had no way to handle them. The best they could offer was to mail them to American Express. Or drive to the airport in Indianapolis. And this wasn't a local bank, it was Chase Manhattan's branch in Bloomington.

We ended up driving to the airport in Indy. No way am I just going to put a few hundred Euros in cash into the mail.

Post reply on HN