January 2024 Summaries
10 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
“Games of skill” merchants, including daily fantasy sports and skill-based eSports platforms, are generally classified under MCC 5816 and treated as high-risk by payment providers because they involve real-money wagers, prizes, and potential regulatory overlap with gambling. Unlike gambling, which is primarily chance-based, games of skill are intended to depend mainly on player knowledge or strategy, though merchants must carefully limit chance elements to avoid gambling classification and related geographic restrictions. Visa’s Integrity Risk Program identifies card-absent games of skill as a Tier 2, high-brand-risk industry due to risks including chargebacks from regretted or unauthorized payments, customer disputes, fraud, regulatory concerns, and potential player addiction. Recommended practices include understanding applicable rules, using payment processors experienced with high-risk merchants, clearly communicating billing and cancellation terms, maintaining strong customer support and PCI DSS compliance, monitoring transactions for fraud or harmful behavior, and engaging specialized compliance and security partners. Basis Theory promotes its tokenization, card-data, and payment-routing tools as a way for such merchants to reduce PCI compliance burdens, retain control of payment data, and avoid reliance on a single processor, citing creator platform Passes as an example of a business that used its services to build more flexible payment-provider options.
Jan 31, 2024
1,312 words in the original blog post.
A token requestor ID (TRID) is a merchant-specific identifier required to obtain network tokens from card networks for stored card, or card-on-file, payments. By replacing actual card numbers with tokens that work only alongside the merchant’s associated TRID, network tokenization reduces exposure of sensitive payment data and limits the value of stolen tokens to unauthorized parties. Merchants need a separate TRID for each card network they use, although they can begin tokenizing with one network while awaiting approval from others; TRIDs are generally 11 characters long and include identifiers for the relevant token service provider. Payment service providers, banks, and tokenization platforms can often request IDs on a merchant’s behalf through the On-Behalf-Of Token Requestor process, though network approval may take up to two months. A merchant typically uses one TRID per network across its business divisions, and because the ID remains tied to the merchant rather than a particular provider, it can generally be retained when changing payment partners.
Jan 30, 2024
792 words in the original blog post.
Basis Theory’s 2023 product efforts focused on global expansion, developer integration improvements, expanded tokenization and payment capabilities, and broader native integrations. The company launched production environments in the EU and India to address regional compliance requirements such as GDPR and reduce latency, while adding tools including a CLI, debugging features, integration templates, simplified Reactor formulas, a whitelabel proxy, asynchronous Reactors, and enhanced privacy features. Its payments stack grew through support for fraud-prevention providers, KnotAPI for issuers, BIN detail lookup, new payment-focused pricing tiers, and integrations with services such as 3DS, network tokens, account updating, and other payment providers. Platform enhancements also included Elements support for React Native, iOS, and Android, API access to Payment Account References, an HTTP client for dual writing, portal multi-factor authentication, extended CVC storage, and Reveal for interactive data displays, with further development planned for 2024.
Jan 26, 2024
423 words in the original blog post.
Negative option merchants use models such as free trials that require payment details and automatically convert customers into recurring subscriptions unless canceled, a structure common across subscription boxes, streaming platforms, gyms, and software services. Visa classifies these businesses under MCC 5968 as Tier 3, or high-brand-risk, because unclear enrollment terms, forgotten renewals, customer dissatisfaction, fraud, and misuse of trials can generate elevated disputes and chargebacks, prompting greater scrutiny from payment service providers. Suggested risk-management measures include understanding card-network rules, working with payment processors experienced in high-risk sectors, clearly explaining billing and cancellation terms, offering responsive customer support, maintaining PCI DSS compliance, monitoring transactions, and using specialized fraud, compliance, and analytics partners. Basis Theory presents its payment-data platform as a way for such merchants to reduce compliance burdens and retain flexibility across providers through network-agnostic tokenization, citing creator platform Passes, which adopted its tools after an unexpected processor shutdown to support faster provider changes and payment cascading.
Jan 24, 2024
990 words in the original blog post.
Stripe’s advertised U.S. payment-processing price of 2.9% plus $0.30 per transaction may produce relatively modest margins after interchange and network costs, which vary by payment method, card type, and purchase category, while lower-cost debit, bank-transfer, and digital-wallet payments can be more profitable. Beyond core processing, Stripe earns revenue through optional services such as Billing, Connect, Radar, and Sigma, which add percentage-based or per-transaction charges for subscription management, marketplace payments, fraud prevention, and data analysis. The account also identifies less visible potential revenue sources, including negotiated interchange economics, chargeback and refund fees, foreign-exchange spreads and cross-border charges, and costs associated with merchants moving their stored payment credentials elsewhere. It argues that larger merchants may seek greater control over payment routing, currency conversion, and customer card data to reduce costs and use multiple processors, while promoting token-vault providers as a way to enable that flexibility.
Jan 23, 2024
1,208 words in the original blog post.
Triangulation fraud is an ecommerce scheme involving a fraudulent seller, an unwitting customer, and a legitimate merchant, in which the fraudster operates a convincing online storefront, collects payment and card details from a customer, then uses a separately stolen credit card to purchase the ordered item from a real merchant for direct shipment to the customer. Although customers may receive the product they ordered, they risk unauthorized future charges, duplicate payments, or failed delivery, while legitimate merchants can face chargebacks, financial losses, payment-provider restrictions, and reputational harm when fraudulent orders surface. Fraudsters benefit from immediate customer revenue and access to additional payment data, often concealing the scheme until chargeback patterns emerge. Suggested defenses include risk-scoring and fraud-detection tools that identify suspicious transaction velocity, repeated purchases, IP-address patterns, mismatched billing and shipping details, and abnormal account behavior, alongside prompt investigation to prevent schemes from expanding. Merchants are also advised to use payment partners with strong security practices and PCI-DSS compliance, while continuously reviewing their security environment and provider relationships as operational risks evolve.
Jan 19, 2024
920 words in the original blog post.
A token vault is a smart contract-based system that stores sensitive information separately from vendors’ environments and provides non-exploitable tokens that authorized systems can use to retrieve or route data under strict authentication and access controls. Vaulted tokenization centralizes sensitive data in a secure repository, supporting approved downstream uses such as payment processing and recurring transactions while helping merchants meet PCI DSS requirements; it may introduce modest latency but offers security and convenience for stored cardholder data. Vaultless tokenization, described as a form of local encryption, keeps data at the customer side and requires customer-side interaction to use it, which can reduce central storage and give users direct transaction control but limits subscriptions and other future payments. Its reliance on local cryptographic-key protection, limited ecosystem adoption, and lack of PCI DSS recognition for protecting payment account numbers make it less suitable for merchants needing to store and reuse payment data. The passage presents third-party vaulted providers such as Basis Theory as a way for merchants to collect, secure, and route payment information while reducing their own PCI compliance scope and maintaining flexibility in payment-provider choices.
Jan 11, 2024
1,119 words in the original blog post.
Delinquent payments occur when recurring obligations such as loan installments or subscription fees are missed, threatening merchants that depend on predictable customer revenue and calculate acquisition costs against expected lifetime value. Although some customers intentionally stop paying because of dissatisfaction or changed preferences, many failures result from temporary or administrative issues, including expired cards, insufficient funds, or outdated account details, and may therefore be recoverable. Merchants can reduce delinquency through automated payment management that distinguishes temporary from permanent failures, retries appropriate transactions, updates card information, sends advance reminders, and offers payment methods suited to regional customer preferences. Greater flexibility also allows businesses to route transactions through the most suitable payment service provider, interpret failure codes, and use tokenization or token vaults to retain control of payment data rather than relying entirely on a single provider.
Jan 10, 2024
872 words in the original blog post.
Payment vaulting involves using a provider to securely store cardholder data and return tokens that merchants can use for future transactions without directly handling sensitive information, potentially reducing PCI-DSS responsibilities. Full-service payment service providers commonly include vaulting within their processing platforms, but this can leave merchants dependent on a single provider and make data migration costly or difficult. Independent tokenization providers can store payment data while allowing merchants to route transactions among multiple payment processors, potentially improving flexibility, payment-method access, approval rates, and fee management. Vaulting costs may include visible event- or usage-based charges as well as less obvious expenses from bundled processing fees, duplicate card records, inefficient card-update checks, and provider migration. The choice between integrated PSP vaulting and third-party tokenization therefore involves balancing convenience and potentially implicit costs against explicit tokenization fees, greater control over stored payment data, and the ability to change or combine processing partners.
Jan 04, 2024
1,139 words in the original blog post.
Vendor lock-in occurs when a customer becomes dependent on a provider and faces major technical, contractual, or financial barriers to switching, a risk that can be especially significant with full-service payment service providers that store cardholder data on their own systems. Merchants may be unable to transfer stored payment credentials without costly portability fees or may be bound by long-term contracts, limiting their ability to adopt new technology, negotiate pricing, add partners, or bring payment operations in-house. This imbalance can reduce competition and innovation while enabling providers to raise costs or impose unfavorable terms. Suggested safeguards include regularly comparing vendors, negotiating termination and data-portability clauses, and retaining ownership of customer payment data from the outset. The passage presents programmable payment vaults, including Basis Theory, as a way for merchants to connect with multiple providers, manage compliance and payment flows, and preserve control over their data while maintaining the ability to migrate away.
Jan 02, 2024
778 words in the original blog post.