I'm building a political campaign web site and I thought I'd ask the community here their recommendations for accepting donations on a MODx Revolution build? Since it's not quite the same as a shopping cart, per se, I was curious on anyone's past experiences? I need something beyond just a Paypal integration. Any ideas or suggestions?
Depending on where you are located, there are a number of credit card processors out there. Depending on how the organization is setup, the cost of processing and receiving funds can vary greatly. I did one for a religious non-profit using BluePay and I have also used PayPal Merchant (merchant allows processing on-site over sending users to PayPal for transactions).
Some info here:
http://www.searchenginejournal.com/top-12-alternatives-paypal/70297/
BTW, PayPal, much as I hate and fear them, has a fairly rich API. You can do pretty much anything with them. I use PayPal for donations here:
http://bobsguides.com/support-this-site.html
I've also have very good luck with Gumroad, which is remarkably easy to set up, though I'm not sure how well Gumroad would work for donations.
-
☆ A M B ☆
- 24,524 Posts
I have a concern about Stripe. Since all the processing is done on your site rather than Stripe's, if someone were to crack the system I think you would be liable for any losses (which could be substantial). I could be wrong, but I've never seen this issue discussed.
I would avoid anything with processing on your site versus the vendor's. PCI compliance is no joke or inexpensive. I would avoid anything more than transmitting data (of course over https).
-
☆ A M B ☆
- 24,524 Posts
It's some comfort that they claim PCI compliance, but that doesn't really address the issue of who is liable if someone manages to compromise your site and makes charges on your user's credit cards. If someone hacks PayPal, it's clearly PayPal's problem, but I suspect that with Stripe, it's your problem.
-
☆ A M B ☆
- 24,524 Posts
How can they make charges on your user's credit cards if you never have the user's credit card information on your server? Using the JQuery method, the form data is sent directly to Stripe.
A miscreant with access to your site could basically set up a man-in-the-middle attack with a dummy form that emails the credit card details somewhere before executing the regular JS code Stripe provides. If this happened with PayPal, the user could see that the host was not paypal.com, but with Stripe, the host would be your site whether it was secure or not.