Could we get some indication of what gateways are supported during the beta?
Spreedly Core - API powered payments w/o burden of PCI compliance
11–20 of 29 posts
Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#12I heard about this from the team a few weeks ago, and am excited to take it for a test drive with BCC sometime after my development schedule gets less nuts. Basically, instead of doing the traditional "send people off to Paypal to pay" routine, you have a form on your site which posts to a Spreedly server. Spreedly then redirects the user to you. You validate the token (similar to catching someone from an OpenID prov…
> Since the data never touches your servers, you never need to go through PCI compliance work. Is that actually true? My understanding is that since the HTML form is still served up by your site, you'll still need to go through PCI compliance (although it will be easier with no data stored), since a compromise of your server would compromise card data.
not sure exactly how the specifics of this will work...
Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#13- A PCIDSS compliant payment information store that's above the level of the payment gateway. The big win is that if you decide to switch gateways (or are forced to switch gateways, because you switched merchant account providers and can't always just relink your gateway to a different bank), you can still keep charging recurring payments to your customers without asking them for their payment info again.
- You can take the info with you if you decide, for some reason, to stop using Spreedly Core. And I trust they actually have the process in place for doing so, because it's coming from the Spreedly guys that have been doing this for a while already, not someone new.
Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#14Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#15Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#16Why not use Paypal directly for example (since that's one of the gateways they support)?
My question might sound silly but in B2B you just use wire transfers. So, I don't see the need to stack up too many layers for payments when each layer wants some money for the service they provide.
Is their main feature the fact you could switch gateways -- ie. they are selling an API wrapper?
Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#17Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#18So, we weren't quite ready to land on the front page of HN, but mission accomplished - we now have a whole list of smart people to invite into the beta, so thanks to bradleyjoyce for giving us that nudge.
I'm going to work through the questions that have come up in the discussion - good prep for the FAQ page I need to write - but feel free to email me directly if you have any other questions or just want to chat about Core (my email address is in my profile).
Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#19I heard about this from the team a few weeks ago, and am excited to take it for a test drive with BCC sometime after my development schedule gets less nuts. Basically, instead of doing the traditional "send people off to Paypal to pay" routine, you have a form on your site which posts to a Spreedly server. Spreedly then redirects the user to you. You validate the token (similar to catching someone from an OpenID prov…
Friendly reminder: You'll still need your own SSL for your checkout page, even though you're posting to https://spreedly.com
Re: Spreedly Core - API powered payments w/o burden of PCI compliance
#20I heard about this from the team a few weeks ago, and am excited to take it for a test drive with BCC sometime after my development schedule gets less nuts. Basically, instead of doing the traditional "send people off to Paypal to pay" routine, you have a form on your site which posts to a Spreedly server. Spreedly then redirects the user to you. You validate the token (similar to catching someone from an OpenID prov…
What Spreedly is offering (transparent post to payment processor, redirect back to retailer) is the same as what Braintree is already offering with PCI compliance built in. That said, we're not happy with Braintree since they messed up an account transfer of ours. The biggest point I'd like to make is that it sucks once you've got your customers in a recurring plan (Spreedly, Braintree, PayPal, etc). If you're not st…
We see this as one of the significant value adds of Core - avoiding lock-in, including lock-in to Core itself.