PCI Compliance (CardPointe Integrated Terminal)
All merchant accounts via CardConnect have 60 days after account creation to get PCI compliant before being charged non-compliance fees. Here’s how to get PCI compliant:
- Go to www.cardpointe.com and log in.
- Go to My Account.
- If you see an alert message about not being PCI Compliant, then click the “Learn how to get compliant” link as shown in the picture above.
- This will take you to the CardPointe PCI Compliance Portal where you can complete the PCI Self-Assessment.
- If asked if you’re using a third party for anything, select No.
If you are asked if your software stores credit card numbers in any way, select N/A and input the reason we have detailed in the photos below.
We use a tokenized value for storing customer payment information – at no point in time do we ever store credit card numbers.
- Below are the exact answers to give for your setup with Wash-Dry-Fold POS and your CardPointe Integrated Terminal.
That’s all there is to it! It takes maybe 20 minutes or less to do all this.
There are no trick questions, and if you get anything “wrong” it will tell you afterwards and you can easily go back and update your answers once you’ve addressed the issue. No worries!
Beyond that you only need to do the Self-Assessment once per year and if there haven’t been any changes in your setup from the prior year it’s greatly simplified compared to the first time.
CLICK ONLY “Certified Point to Point Encryption (P2PE)” ON THIS STEP!
Most Wash-Dry-Fold POS subscribers have the Ingenico iPP350 or Ingenico Lane 3000. If you have a Lane 3000 and do not see it in this list, then please select the Ingenico iPP350.
You may copy & paste these paragraphs for the next step (“A summary of how and where you handle card payments”):
- Self-service laundromat with drop-off laundry service
- Credit cards are used in person with a CardPointe Integrated Terminal, or they are keyed manually in the Wash-Dry-Fold POS software which uses the CardPointe Hosted iFrame Tokenizer to tokenize any sensitive payment data.
- CardPointe Integrated Terminal at the service counter, used through Wash-Dry-Fold POS software.
You’re almost done! Now select “Manage” in the middle section that says “Complete security assessment”:
Select “N/A” and in the “Reason for this response” section, type “We do not store cardholder data.”
Select “Next”
Select “N/A” and in the “Reason for this response” section, type “We do not store cardholder data.”
You then will need to type in your full name where it has “Owner”. You may also need to enter your email address. Then, when you scroll down to “Merchant Executive Officer”, you’ll input your title (usually owner, president, CEO) and your full name in this section.
You should now be able to confirm your attestation.
If you successfully become compliant, you’ll be directed back to the main PCI compliance portal page where it will say “You’re compliant”.
Your CardPointe merchant account will take a day or two to reflect your PCI compliant status.