Skip to main content
Hit enter to search or ESC to close
Close Search
ConnectionPoint Help Center
Menu
  • About
  • Contact
  • Help Centre

    Help Guide

    • Getting Started
      • About the ConnectionPoint Help Center
      • ConnectionPoint Login
      • ConnectionPoint Platforms
      • Crowdfunding 101 with ConnectionPoint
      • All About Organization Profiles
    • Pricing & Payments
      • How to understand the difference between Pricing Models
      • Payment Processing Accounts & How to Collect Funds
    • Apps & Integrations
      • Zapier
      • Embedded Live Streaming
      • Raiser’s Edge
      • Facebook Pixel
      • Google Analytics
      • Mailchimp
    • Resources
      • Glossary of common ConnectionPoint terms
      • Campaign Stickers for Download – Crowdfundr
      • Fundraiser HUB by ConnectionPoint for FundRazr, CoCoPay, & PetFundr
      • Creator HUB by Crowdfundr
      • FundRazr Blog
      • CoCoPay Blog
      • Discord Channels

    Fundamentals

    • Navigating the platform
    • ConnectionPoint Platform FAQs
    • Campaign Privacy Settings
    • How to share a campaign
    • Adding payment processors
    • How to create a campaign

    Organization Management

    • Email Communication for Organizations (Creating your Community)
    • How to set up Dedications
    • How to set up Allocations
    • Organization Fundamentals
      • Organization Verification: How do I get Verified?
      • Organization Staff
      • How to create an organization campaign
      • How to create an organization profile
      • What is an organization profile? Who can start one?
    • Organization General Set-up & Management
      • Turn Your Supporters into Advocates for Your Organization
      • How to set up Dedications
      • How to set up Allocations
      • How to enable Mailchimp on your Campaign
      • How to customize your organization theme (including campaign headers, fonts, and colours)
      • Apply Gift Aid to your campaign (UK organizations only)
      • Setting up automatic tax receipts
      • How to set up Mailchimp in your organization
      • Connect Google Analytics and Facebook Pixel
      • Editing organizational information
      • Where to find and edit your organization profile
      • Customizing and embedding organization widgets
      • Archive campaigns in your organization’s campaign list.
      • Organization logo: where it appears and how to edit it
      • Sponsor match: Set up a sponsor banner with optional matching fund capabilities
      • Notify past supporters about new campaigns with one click!
      • Organization Verification: How do I get Verified?
      • All About Organization Profiles
    • Organization Teams
      • What is the difference between Campaign Team and Organization Staff?
      • How do I add, remove, and change staff member permissions?
      • Staff notifications
      • Organization Staff
    • Organization Payment Accounts & Troubleshooting
      • Transaction codes: Identifying campaign transactions in payment accounts
      • Organizations: Default pricing model
      • Organizations: How to change the payment processing account
      • Why can’t I connect my PayPal account?
      • Do I need a PayPal account to use a ConnectionPoint platform?
      • Stripe or PayPal – Which should I choose? What’s the difference?
      • Roadblock: The receiver PayPal account is set to block (Error Code: 559044)
      • Roadblock: The PayPal account is restricted
      • Roadblock: The PayPal account is locked
      • Roadblock: The PayPal account is based in a country which cannot receive payments (Error 539041)
      • Roadblock: The PayPal account has exceeded its sending limit (Error Code: 579048)
      • Roadblock: The PayPal account email address is not confirmed
      • Roadblock: The email address cannot accept payments
      • Error Code: 1001 – The payment has been cancelled
    • Organization FAQ
      • How to understand the difference between Pricing Models
      • I think I’m missing a table column…
      • Can I view a list of organizations I’m on the Staff team for?
      • Can I run more than one campaign at the same time? 
      • Will you send me a 1099-K form? (USA only)
      • What happens if users or campaigns break Terms of Service?
      • Will you share my campaign?
      • What languages can I run my campaign in?
      • What is the difference between Campaign Team and Organization Staff?

    Campaign Management

    • 🖼️ Let Your Supporters Shine! – Media Gallery Enhancements
    • ⏳ Automatically Finish Campaign at Deadline
    • ⏳ Timeline Features – How to Schedule Your Campaign
    • How to Maximize Support with Embeddable Donation Forms!
    • Campaign Fundamentals
      • How to Maximize Support with Embeddable Donation Forms!
      • How to start a new campaign
      • Campaign Layouts – similarities, differences, and how to switch them.
      • How to set and change the campaign goal
      • How to set the campaign deadline
      • Launch your campaign
      • How to share a campaign
      • Visual Editor Navigation
      • Keep-it-all or All-or-nothing campaign… What’s the difference?
    • General Campaign Help
      • How do I delete comments or contributions from the activity feed?
      • What is a ‘Rollover’ campaign?
      • What are the campaign Highlights?
      • Campaign Story Updates – How to add, edit, and delete.
      • How to customize the campaign link
      • How to delete a campaign
      • How to add a campaign background
      • How to edit the campaign title
      • The social media summary and how to change it.
      • How to change campaign types: Keep-it-all and All-or-nothing
      • Campaign Comments and Activity Feed
      • How to preview a campaign in desktop, tablet, and mobile phone views.
      • How to change a campaign category
      • Add campaign notes for future help
      • How to pause, restart, or finish a campaign
      • How to clone a campaign
      • Embed a live-stream video into your campaign
      • Launch your campaign
      • What is the campaign time limit?
      • How does the platform handle sales tax?
      • Notify past supporters about new campaigns with one click!
      • What do I do if I DO NOT reach the campaign goal?
    • Campaign Goals & Deadlines
      • ⏳ Automatically Finish Campaign at Deadline
      • KEEP-IT-ALL CAMPAIGNS: How to reset the launch date
      • ALL OR NOTHING CAMPAIGNS: What happens when an all-or-nothing campaign goal is reached?
      • ALL-OR-NOTHING CAMPAIGNS: What happens when you reach the all-or-nothing campaign deadline?
      • KEEP-IT-ALL CAMPAIGNS: What happens when the campaign hits its deadline?
      • Campaign funding limit: ensure you do NOT raise more than your goal
      • How to set and change the campaign goal
      • How to set the campaign deadline
      • How to remove the campaign stats (such as goal and deadline)
      • What is the campaign time limit?
      • What are ‘Campaign Stats’?
    • Campaign Teams
      • How to message campaign team members
      • How to set a main campaign team member goal
      • How to show or hide campaign team features
      • Contribution tracking: How to track which team members inspired which contributions
      • How to add or change a campaign team name and picture
      • How to hide team members from public view
      • Campaign Team Notifications
      • How to change a team member role
      • How to remove campaign team members
      • How to add campaign team members
      • Campaign Team Roles & Permissions
      • What is a campaign team?
    • Campaign Story
      • Adding Emojis & GIFs to Your Contributions and Campaigns
      • AI Story Assist
      • Story Editor FAQs
      • Responsive preview – Formatting your story for all devices
      • How to add external & internal campaign story links
      • How to add extra campaign story tabs
      • How to insert a campaign story video
      • How to insert and resize campaign story pictures
      • How to add campaign story anchors
      • How to change the campaign story font style, size, and colour
      • The social media summary and how to change it.
      • Campaign Story Updates – How to add, edit, and delete.
      • How to edit the campaign story
    • Campaign Media Gallery
      • 🖼️ Let Your Supporters Shine! – Media Gallery Enhancements
      • How to format pictures in the media gallery
      • How to add or delete pictures & videos from the Media Gallery
      • How to make your media gallery a slideshow
      • How to add or change the campaign cover picture & video
    • Campaign Sharing & Communication
      • 📢 How Are Campaigns Shared?
      • Campaign Link – Where to find yours
      • How to import contacts onto your campaign
      • Campaign Referral Links
      • Campaign QR Code
      • Campaign commenting – to allow or not to allow?
      • How to add a personal message to a campaign
      • How to notify past supporters with one click
      • How to embed a campaign to an outside site
      • Private Campaign Messaging
      • Campaign confirmation email
      • Text-to-give (Organizations only)
      • Campaign Sharing & Communication FAQ
    • Campaign Tasks
      • What are campaign tasks?
      • How to use campaign tasks
      • How to create tasks
    • Campaign Pricing & Payments
      • Prompt for unrestricted usage of funds
      • How to understand the difference between Pricing Models
      • Are the contributions I receive taxable?
      • Can I contribute (donate) to myself?
      • What countries can I accept payments from?
      • ALL OR NOTHING CAMPAIGNS: Failed pledges
      • What currencies do you accept?
      • How do I withdraw/receive my funds?
      • Disallowing pictures with contribution comments
      • Apply Gift Aid to your campaign (UK organizations only)
      • ALL OR NOTHING CAMPAIGNS – How to cancel a pledge
      • What is the effective fee rate? Where do I find mine?
      • Can I change the currency displayed in the stats of my campaign?
      • How to customize the ‘Contribute’ button
      • How to customize contribution amounts
      • Recurring contributions – adding and modifying
      • Text-to-give (Organizations only)
      • Find and resend tax receipts to supporters
      • A contribution has been attributed to (i.e. credit given to) the wrong team member. Can I change this?
      • Customize the payment confirmation email to campaign supporters
      • How to add offline contributions
      • How to issue a refund
      • How to view and download campaign transaction details
      • Choosing what supporter information to collect
      • Adding payment processors
      • Apply automatic tax-deductible receipts to a campaign (Organizations only)
      • How to change your campaign’s pricing model
      • Can a supporter’s contribution be completely anonymous?
    • Campaign Analytics
      • Campaign conversion rates & average gift per supporter
      • How to add Google Analytics to your campaign
      • Adding Facebook Pixel to your campaign
      • What to learn from Campaign Analytics
      • What is the effective fee rate? Where do I find mine?
    • Campaign Privacy
      • How to hide a campaign from your user profile
      • 🔒 Campaign Privacy Settings
      • How to turn campaign comments on/off
      • Campaign Privacy Settings
    • Campaign FAQ
      • What campaigns or projects are NOT allowed to use a ConnectionPoint platform?
      • Am I allowed to host a raffle or auction on any ConnectionPoint platform?
      • Can I raise money for disaster or tragedy relief?
      • What’s the difference between a personal campaign and organization campaign?
      • What happens if, after I’m finished my campaign, I need more funds to complete the project?
      • I don’t have a network. Will you share my campaign?
      • Can I remove the prompt asking for a top-up to contributions?
      • Why is someone else’s name and picture at the top of my campaign?
      • Is the campaign visible before launch?
      • What is a campaign’s ‘Category’? Why is it useful?
      • Can I message all (team members, contributors/supporters, subscribers) at once? Separately?
      • Can a campaign’s team members get credit for contributions from their friends and family?
      • My customer has a question about your platform, where do I send them?
      • Why does my campaign’s header and/or URL look different?
      • Can I raise money on behalf of a charity?
      • ALL OR NOTHING CAMPAIGNS: Failed pledges
      • Campaign Link – Where to find yours
      • What do I do if I DO NOT reach the campaign goal?
      • What is the campaign time limit?
      • How does the platform handle sales tax?
      • What pricing model is my campaign on?
      • How do you (ConnectionPoint: FundRazr, CoCoPay, Crowdfundr, Petfunder) make money off the platform?
      • What languages can I run my campaign in?
      • Will you share my campaign?
      • Can I run more than one campaign at the same time? 
      • What happens if users or campaigns break Terms of Service?
      • I think I’m missing a table column…
    • Campaign Rewards
      • ALL OR NOTHING CAMPAIGNS: Allowing supporters to cancel pledges
      • ALL OR NOTHING CAMPAIGNS: How to change a pledged reward order
      • Mark an order ‘Complete’
      • How to fill in missing addresses or edit addresses for reward fulfillment
      • How to organize orders for reward fulfillment
      • How to edit, arrange, discontinue, and delete reward items
      • How to create a reward
      • What are the differences between Reward Types? Perks, Wishes, Products, and Tickets?
      • Campaign Rewards & Shipping FAQ
      • How is shipping calculated for orders of multiple rewards?
      • How do tickets work?
    • Campaign Payment Troubleshooting
      • Roadblock: The PayPal account has exceeded its sending limit (Error Code: 579048)
      • Error Code: 1001 – The payment has been cancelled
      • Roadblock: The email address cannot accept payments
      • Roadblock: The PayPal account email address is not confirmed
      • Roadblock: The PayPal account is based in a country which cannot receive payments (Error 539041)
      • Roadblock: The PayPal account is locked
      • Roadblock: The PayPal account is restricted
      • Roadblock: The receiver PayPal account is set to block (Error Code: 559044)
      • Why can’t I connect my PayPal account?
    • Sub Campaigns
      • Increase Campaign Participation with Targeted Invitations
      • Sub-campaign Management
        • Sub-campaign transactions and financial reports
        • Creating Sub-campaign Deadlines
        • Viewing registrant (fundraiser) information
      • Sub-campaign Content
        • How to set a sub-campaign title template
        • Sub-campaign stories: setting and editing a story template
        • How to set up rewards on sub-campaigns
        • How to hide stats (goal, deadline, funds raised, & number of supporters) on sub-campaigns
        • Sub-campaign Galleries
      • Sub-Campaigns: Goals & Deadlines
        • What is the difference between a sub-campaign goal and the team member goal?
        • How to set or edit the sub-campaign goal
        • How to set or edit the sub-campaign team member goal
        • How to prevent sub-campaign owners from changing the sub-campaign goal.
        • What is the difference between a sub-campaign goal and the main campaign goal?
      • Sub-campaign Teams
        • Why are my team members listed as individuals?
        • Why are my team members listed as individuals?
        • What is the difference between a sub-campaign goal and the team member goal?
        • How to switch a user from one sub-campaign team to another.
        • How to change an individual sub-campaign into a team sub-campaign.
        • How to change a sub-campaign team name and/or picture
        • How to hide the ‘Join a team’ banner from sub-campaigns and widgets
        • How to invite team members to a sub-campaign
        • How to edit a team member personal message
        • List, leaderboard, grid, or not at all: Options for viewing sub-campaigns on other related sub-campaigns
        • What is the difference between a campaign team and a sub-campaign team?
      • Sub-campaigns: Registration
        • How to Add Content Tabs to Your Registration Page
        • What is the confirmation message, and how do I edit it?
        • What does the registration flow look like?
        • Viewing registrant (fundraiser) information
        • Automatically launch sub-campaigns
        • Mandatory approval for newly created sub-campaigns
        • Allowing team members to skip registration
        • Encourage sub-campaign customization in registration flow
        • Registration fees & rewards: how to add, edit, and troubleshoot
        • Registration waivers & compliance messages
        • Customizing the Registration Form
        • Registration for individuals, teams, or both
      • Sub-campaigns: Fundamentals & Set-Up
        • Sub-Campaigns: What is a sub-campaign? How are they used?
        • List, leaderboard, grid, or not at all: Options for viewing sub-campaigns on other related sub-campaigns
        • How to create a sub-campaign
        • Add a beneficiary to your sub-campaign
        • How to turn on the sub-campaign feature
        • How to launch, pause, finish, and delete sub-campaigns
      • Sub-campaign FAQ
        • Why are my team members listed as individuals?
        • Where is the information from my custom registration form?
        • Why is there a banner with another user’s name on my sub-campaign (or why is my picture and name on another campaign)?
        • Does every team member have to complete registration?
        • Can the sub-campaigns have different deadlines?
        • How to launch, pause, finish, and delete sub-campaigns
        • Can I hide transactions from sub-campaign owners?
        • How do I view the main campaign when I’m in a sub-campaign?
      • Sub-Campaigns: Invitations
        • Increase Campaign Participation with Targeted Invitations

    User Account Management

    • General User Account Information
      • Can I hide just one campaign on my user profile without hiding all of them?
      • All about your user profile
      • Changing user profile privacy
      • How to change or unlink your social accounts
      • How to change your account email and/or password
      • How to change your user profile picture
      • How to change your user name
      • Deleting user accounts
      • How to create a ConnectionPoint user account and get started
      • How to change email notifications from the platforms
    • Account Troubleshooting
      • Do I need a personal Facebook account to use the platform?
      • Why do I need a user picture? Where does it appear?
      • Why your campaign list or user profile may look different/be missing items
      • I forgot my password
      • Can I change my view to Dark mode?
      • Hiding and revealing the navigation menu
      • I think I’m missing a table column…

    Payment Processing

    • Payment Processing - General Information & Set-up
      • ORGANIZATIONS: Adding or changing payment processors
      • PERSONAL CAMPAIGNS: How to add a payment processor
      • Choosing what supporter information to collect
      • Customize the payment confirmation email to campaign supporters
    • Payment Processing - Error Messages & Troubleshooting
      • Roadblock: The PayPal account has exceeded its sending limit (Error Code: 579048)
      • Error Code: 1001 – The payment has been cancelled
      • Roadblock: The email address cannot accept payments
      • Roadblock: The PayPal account email address is not confirmed
      • Roadblock: The PayPal account is based in a country which cannot receive payments (Error 539041)
      • Roadblock: The PayPal account is locked
      • Roadblock: The PayPal account is restricted
      • Roadblock: The receiver PayPal account is set to block (Error Code: 559044)
      • Why can’t I connect my PayPal account?
    • Payment FAQs
      • Are the contributions I receive taxable?
      • Can I contribute (donate) to myself?
      • What countries can I accept payments from?
      • Can campaigns connect with providers other than PayPal and Stripe?
      • Can you help me get a Stripe/PayPal account or troubleshoot issues with my Stripe/PayPal account?
      • Can I give out tax receipts on the platform?
      • Do you connect with Gift Aid (United Kingdom users only)
      • Do you allow recurring contributions?
      • What currencies do you accept?
      • How do I withdraw/receive my funds?
      • Do you allow offline contributions?
      • Do I need a PayPal account to use a ConnectionPoint platform?
      • How to understand the difference between Pricing Models
    • Stripe & PayPal Information
      • How do I contact someone from PayPal?
      • How do I contact someone from Stripe?
      • Stripe or PayPal – Which should I choose? What’s the difference?

    For Supporters

    • Contributions
      • Do I need a PayPal or Stripe account to contribute to a campaign?
      • Can I view a list of every contribution I’ve made? Can I view past tax receipts?
      • How do I edit/skip/cancel my recurring contributions?
      • Editing contribution details
      • Can I contribute to a campaign outside of my country?
      • Do I need a ConnectionPoint account to contribute?
      • Why do I see two separate charges for my contribution on my statement?
      • What payment forms do you accept?
      • Roadblock: The receiver PayPal account is set to block (Error Code: 559044)
      • Roadblock: The PayPal account is restricted
      • Roadblock: The PayPal account is locked
      • Roadblock: The PayPal account is based in a country which cannot receive payments (Error 539041)
      • Roadblock: The PayPal account has exceeded its sending limit (Error Code: 579048)
      • Roadblock: The PayPal account email address is not confirmed
      • Roadblock: The email address cannot accept payments
      • Error Code: 1001 – The payment has been cancelled
      • How is a contribution made?
      • Will I receive a receipt for my contribution?
    • FAQ
      • Can I browse campaigns that are currently running?
      • How do I contact a campaign owner?
      • Can my campaign contribution be completely anonymous?
      • What does it mean to subscribe to a campaign?
      • What are campaign updates? Where can I view them?
      • What do I do if I don’t receive my contribution reward?
      • What happens if the campaign I contributed to does not meet its goal?
      • How do I know a campaign is not a scam?
      • Is my campaign contribution secure?

    Resources

    • Campaign Stickers for Download – Crowdfundr
    • Fundraiser HUB by ConnectionPoint for FundRazr, CoCoPay, & PetFundr
    • Creator HUB by Crowdfundr
    • FundRazr Blog
    • CoCoPay Blog
    • Discord Channels

    About ConnectionPoint

    • Who is ConnectionPoint? How is it connected to FundRazr/Crowdfundr/CoCoPay/PetFundr?
    • ConnectionPoint Security Description
    • ConnectionPoint Privacy Policy
    • ConnectionPoint Terms of Service

    Talk To Us

    • FAQs
      • In what languages does ConnectionPoint offer support?
      • How do I report fraud?
      • How soon can I expect an answer from a support agent?
      • I think I found a bug. How do I report it?
      • How do I contact someone from ConnectionPoint?
      • How do I report spam or abusive comments?
      • Can I suggest a feature?
      • Can I call someone?
    • Live Chat
      • Discord Channels
    View Categories
    • Home
    • Help Centre
    • About ConnectionPoint
    • ConnectionPoint Security Description

    ConnectionPoint Security Description

    This document describes the data security environment for ConnectionPoint systems.

    This environment applies to our crowdfunding applications including:

    • FundRazr
    • CoCoPay
    • Crowdfundr

    It also applies to the underlying crowdfunding-as-a-service infrastructure used under contract by
    ConnectionPoint whitelabel partners.

    Overview
    ConnectionPoint takes the security, preservation, and privacy of our customer’s data very seriously. It is
    our intention not only to adhere to applicable data privacy laws in Canada and America but to go
    beyond that with best practices from other regions such as the European Union including the GDPR
    regulations. We publish and communicate our data privacy policy to our customers in links from our
    website pages and, on request, in a written and dated document.

    To achieve these goals, we manage these aspects of our systems:
    • Computing infrastructure
    • Data storage locations
    • Data encryption
    • Data access controls
    • Employee access
    • Customer access
    • Credit card data protection
    • Payment transaction data flow

    Each of these aspects will be discussed in more detail below.

    Computing infrastructure
    We host our compute servers with Amazon Web Services (AWS) at locations in Quebec in Canada and
    North Virginia in America. By leveraging the investments AWS has made in physical security and data
    availability, we can provide very high levels of data protection at low cost.

    These benefits include things like
    • Generator-backup of all electrical systems intended to cover extended periods of electrical
    outages from natural disasters like hurricanes, tornados or floods.
    • Armed physical building security at the data server locations to prevent malicious attacks from
    disgruntled persons or even terrorists.
    • Network intrusion detection and denial-of-service attack counter-measures.
    We follow AWS best practices in building our applications that use their data services and enjoy the
    many benefits they provide.
    AWS is widely admired for their commitment to data security and privacy. They provide extensive
    documentation on their security practices. This information is available on their web site here.

    Data Storage Locations
    We store application and customer data in two AWS data centers. Data for customers who prefer
    storage within Canada is stored in the facility in Quebec. Data for other customers is stored in North
    Virginia.

    Data Encryption
    Data stored within the databases are encrypted. Even if the database itself was copied and moved from
    our facilities it cannot be read without our secret access keys. Access to these keys is restricted to key
    employees of ConnectionPoint who commit to their protection via signed employee data confidentially
    agreements.

    Data Access Controls
    Internet access to our database servers is very tightly controlled. Only machines communicating from a
    short whitelist of known locations (as defined by their IP addresses) are permitted access to the data.
    These known locations correspond to the ConnectionPoint offices and specific machines in possession of
    our CEO and CTO. All communication with our computing and database servers is over secure IP
    protocols such as SSL and HTTPS.
    All other access to the data is managed through our application compute servers. Our applications
    enforce rules to control access i.e. who can view data and what data each individual is allowed to load.
    Employee Access
    ConnectionPoint employees are required to sign data confidentially and protection agreements.
    Employees are restricted in what data they are allowed to access and are granted access only to data
    they need to perform their jobs.
    Employee login access to our control systems such as managing the AWS environment or accessing our
    application master accounts at Facebook, LinkedIn, Google, PayPal, WePay, Stripe, etc. is protected by
    two-factor authentication. This means that accessing one of our systems using an employee’s account requires not only an identifier and password but access to a code generator on an employee’s mobile
    phone which creates a unique identification number for each access attempt or via a text-back service
    that sends a unique, time-limited identifier to the employee’s phone.
    Customer Access
    ConnectionPoint customers, after logging in, can access their donor and contribution information
    through secure web pages on our sites. Customers can grant their employees and volunteers various
    levels of access. This provides very granular levels of control over who can see and access donor
    information. The chart below is copied from within our application and shows these levels.

    Customers in the Owner or Manager role can download all donor and contribution information into CSV
    or XLS files. These files are transmitted over encrypted channels to the user’s device to prevent
    interception while transiting over the network.
    An important point from the chart above is that Promoters (either staff members or volunteers) can
    securely upload their own contact lists to the system. The Promoter can then send an email to the
    members of this list prompting them to support the campaign. Only those contacts that proactively
    ”opt-in” to receiving information from the organization are copied into the organization’s records. This is in compliance not only with anti-spam legislation such as CASL but also with best practices for
    preserving personal privacy such as the European Union’s GDPR and California’s CCPA.
    Credit Card Data Protection
    ConnectionPoint does not store credit card data. This is done very intentionally to eliminate the
    potential for a security breach either through internal employee malfeasance or by internet hacker
    attacks. We work with payment processing partners who offer mechanisms for us to process payment
    transactions without requiring us to manage the card data. With this approach we can rely on the
    payment processors highest levels of Payment Card Industry (PCI) data security compliance without
    having to implement these costly procedures ourselves. Despite this approach, we still follow PCI
    compliance standards ourselves as best practices for maintaining customer data security.
    Payment Transaction Data Flow
    The payment processing industry is complex and intentionally obscure. This next section will explain
    how data security is maintained as payments are processed by ConnectionPoint in cooperation with our
    partners PayPal, Stripe and WePay.
    There are three main flavors of payment transactions:
    1) Payments via credit cards
    2) Payments via bank transfers
    3) Payments via a PayPal account
    ConnectionPoint processes all three types of transactions via one or more of our three payment
    processing partners depending on the preferences of our customer. In addition, we also can process
    transactions using a PayPal account. These will be discussed separately.
    Credit cards via Stripe or WePay
    Processing credit cards requires a donor to enter their name, billing address, credit card number, expiry
    date and CVV number into an online form. When paying with Stripe or WePay, this form is hosted on the
    ConnectionPoint product page. The contents of the form are encrypted and delivered to the donor’s
    browser using Secure Sockets Layer (SSL) technology. This encryption is done in case hackers are
    monitoring traffic on the wireless network and trying to intercept this important data.
    The data entered into this form is encrypted and “tokenized” to make it harder to intercept and then
    sent from ConnectionPoint’s servers to the payment processor’s Application Programming Interface
    (API) over SSL. The payment processor creates a transaction requesting payment that is securely
    transferred to the credit card Interchange Network – the massive global system run by the banks and
    credit card processing companies. The bank or credit card company that issued the credit card checks
    the availability of credit on the card and, if after appropriate anti-fraud security checks are done and the
    transaction is approved, debits the card for the value of the transaction. The completed transaction
    confirmation message is returned via the Interchange Network and the payment processing account of
    ConnectionPoint’s customer is credited with the value of the transaction less any agreed upon processing fees. It is important to note that at no time in this process did ConnectionPoint hold or have access to the value of the transaction.
    Bank payments via Stripe or WePay
    When using Stripe or WePay it is possible for customers in the US to enable their account such that a
    donor can elect to pay via a bank card. When this is turned on an additional option of Pay by bank is
    provided at checkout. Clicking on this link opens a new window containing a secure webpage on the
    WePay or Stripe systems. There, the donor is prompted to search for their bank, securely log in to the
    bank’s payment system, select the account to fund the payment and confirm the transaction. On the
    successful completion of the transaction the donor is returned to the campaign page and prompted for
    any additional tax receipt information that has been requested by the campaign. At no time in this
    process are the details of the bank account shared with ConnectionPoint or made visible outside of the
    bank’s secure website.

    Paying with PayPal
    When paying via PayPal as the payment processor the process is slightly different. When the donor
    clicks to confirm they want to make a contribution, they are transferred to a secure PayPal webpage.
    There, they are prompted to log into their PayPal account with their email and PayPal password to
    complete the transaction. They can select any of the funding sources attached to the PayPal account
    including previously registered credit cards, connected bank accounts or even a PayPal account balance.
    If they do not have a PayPal account, they click on a Pay as a guest option which prompts them for their
    credit card information as described above. On successful completion of the transaction, they are
    returned to the campaign page and prompted for any additional tax receipt information requested by
    the campaign. At no time are the internal details of the funding payment account (such as the bank
    account number, credit card number or even credit card type) shared with ConnectionPoint.
    Recurring Payment Transaction Data Flow
    As mentioned above ConnectionPoint does not store credit card data. This complicates the process for
    securely managing recurring payments and pledge payments i.e. payments made conditionally on the
    achievement of certain future objectives. By working in collaboration with our payment processors we
    have a good solution to this problem.
    To enable the processing of these types of payments, contributors are prompted during the payment
    processor portions of the payment workflows to pre-authorize future payments. If the contributor
    grants the authorization, ConnectionPoint is provided with a secure “token” which we store in our
    database. At the appropriate times in the future when we want to process a recurring payment or
    pledge payment, we submit the token to the payment processor instead of the contributor’s payment
    card data. This token presentation authorizes the payment processors to create a transaction according
    to the parameters the contributor agreed to (i.e. the value and frequency of the contribution) and the
    transaction is executed using the Interchange Network.
    This process is very secure because even if the preauthorized tokens are stolen from our database, they
    cannot be processed by anyone other than ConnectionPoint and to any other beneficiary besides the
    organization originally identified as the recipient of funds in the authorization transaction.
    Summary
    ConnectionPoint cares deeply about the security of our customers’ information and the integrity of our
    payment processing activities. We have implemented industry best practices to help us achieve a very
    high level of security. However, we are always interested in further improvements to our system and
    welcome feedback on perceived vulnerabilities and suggested enhancements.


    FundRazr logo, click to go to platform
    PetFundr logo, click to go to platform
    Crowdfundr logo, click to go to platform
    Cocopay logo, click to go to platform

    Share This Article :

    • Facebook
    • X
    • LinkedIn
    • Pinterest
    Need more help? Contact us now!

    How can we help?

    Updated on January 18, 2023
    ConnectionPoint Privacy PolicyWho is ConnectionPoint? How is it connected to FundRazr/Crowdfundr/CoCoPay/PetFundr?

    Copyright © 2023 ConnectionPoint Systems Inc.
    Built with love in Vancouver, Canada
    All rights reserved.

    Resources

    • About
    • Contact
    • Help Centre

    Our Platforms

    • FundRazr
    • Crowdfundr
    • CoCoPay
    • PetFundr
    Close Menu
    • About
    • Contact
    • Help Centre