Billing Systems
Recurring billing, card and bank-draft payments, and collections reporting built around how your customers pay you.
Some billing systems run fully automated recurring charges by credit card or bank draft / EFT; others need reports and work queues for a billing team that works by hand. Either way, the rules come from your business: when charges run, how credits and proration apply, what happens after a declined card, and when an account moves to collections.
Keeping card data out of your systems
One design for card payments uses a payment processor that tokenizes the card. The customer enters card details in the processor's hosted page or fields, and your billing system stores only a token and the processor's transaction references. In that design your database does not hold the card number, which reduces the PCI DSS requirements that apply to your own environment. An existing system that already stores or handles card numbers has a different scope and needs its own review.
It does not remove your responsibility. The PCI Security Standards Council states that PCI DSS still applies to a merchant that outsources all payment processing: the merchant confirms its provider is PCI DSS compliant, keeps a written agreement setting out each party's responsibilities, monitors the provider's compliance at least annually, and completes its own applicable validation, such as a self-assessment questionnaire.
Around the payment itself we build encryption of stored billing data, role-based access to payment history, and an audit trail of refunds and adjustments.
Ready to get started?
Describe the system or process you want built or fixed, and we will follow up to talk through the project.
Contact IKRC