Hope Park Sports Card Processing Procedure 1.0 Introduction Hope Park Sports is the sport and leisure facility at the university. The facility offers space to hire by students, staff and members of the public for the purpose of sport, exercise and physical activity. When purchasing any product or service from the facility customers can make payment by cash, cheque and credit card. Specifically to card payments Hope Park Sports has a single PDQ machine that is located on the reception area within the sports hall – located in a fixed cabled position; it is placed behind a shelved area on the reception desk and is concealed away from clear vision by the paying public. The terminal is used for taking payments from a variety of customers that attend a range of programmed initiatives, one-off activities, fitness suite memberships and for the hire of the indoor and outdoor sport facilities. Each member of staff that operates and processes card payments at the facility have not undertaken any formal training in the proper use and handling of card payment information – the procedures adopted have been ‘self-taught’ and supported by ‘in-house’ training. The purpose of this paper is to define the procedures adopted at Hope Park Sports when collecting, storing, processing and transmitting card data and how the same procedures support the control and integrity of data as well as facilitating overall compliance. 2.0 Collection of Cardholder Data The normal procedure adopted by Hope Park Sports to collect data (process card transactions) is: •Using face-to-face transactions (where the customer is present with the card using the PDQ machine) or •By telephone using the existing office / reception telephone number (0151 291 2911) when the customer (and card) is not present. The card transaction process begins when the customer makes a purchase of a product or service that is offered from the facility and when their card is entered manually into the point of sale terminal to authorise and collect payment. Transaction Process (when customer is present) If the purchaser and credit card is present the card will be inserted into the PDQ terminal. In brief the following procedure is undertaken: a) Request card from cardholder for processing payment ensuring that the card has a signature on the back – if not the customer may be required to produce an approved form of ID. b) Process transaction by manually adding the card detail to the machine. c) The charged amount is added to the terminal by the member of staff and it is then passed to the customer for them to add their security PIN Number. The machine will then be handed back to the staff member and once checked that the details entered are correct the green ‘enter’ button is pressed to fulfil the transaction requirement. A customer and merchant copy receipt will then be printed from the machine. The card is removed from the terminal and handed back to the customer along with the customer receipt. The merchant copy is retained, processed and stored. Transaction Process (when customer is not present – telephone) If the customer (and card) is not present the card transaction can still be managed verbally over the telephone. In brief the following procedure is undertaken: a) Card information will be taken verbally over the telephone when the purchaser and card are not present. The detail will be entered directly into the credit card swipe terminal. No numbers or information is written down throughout this process. b) To fulfill the telephone transaction the staff member processing the purchase will require specific information from the customer that is then added to the card terminal - this is entered manually. The information requested from the customer will be the primary card number (16 digit number), expiry date of the card, the amount to be charged and the cvv code. c) Two security questions will be prompted by the PDQ machine – Post Code and first line of address of the cardholder. The purchaser will provide such detail and the transaction will continue if correct. The charged amount will be entered by the staff member. Once again two receipts for the transaction are printed – a customer and merchant copy. d) The customer card receipt shows an automated layout and is printed with only the last four digits of the long card number showing – the first twelve numbers are ‘masked out’ for security purpose; the merchant copy of the receipt shows the long card number in its entirety. 3.0 End of Day Reading Hope Park Sports card systems are closed out daily and are reconciled to the daily activity processed through the reception till system to ensure all transactions are correct. The daily settlement report (Z Reading) is generated when the system is closed each day. 1. All transactions undertaken with card payments are also put through the receptions till system as well as the PDQ terminal to show that the product booked and purchased has been paid for as required. 2. The end of day ‘Z’ reading of the PDQ terminal will take place at the same time as the ‘Z’ reading of the till system. The ‘Z’ reading from the terminal and the card payments on the till ‘Z’ reading must agree. Any discrepancy here will be investigated to determine the reason (s) for any unacceptable inaccuracies. 3. ‘Z’ Readings from the PDQ terminal are manually recorded and reconciled daily to ensure that all transactions are matched with card payments received for any given day. Merchant copy receipts are filed and stored in numerical order against for each day. The recording sheet used to reconcile card payments is counter signed and ‘authorized as correct’ by the Senior Manager and stored away in a locked unit. Reconciled sheets together with the merchant copy receipts are kept for a period of 12 months at which point they will be destroyed through a paper shredder. 4. The single PDQ machine is left at all times (except when taken out and handed to the customer) in its cradle on the reception desk, it is not locked away in a secure unit overnight. 4.0 Refunds Refunds are not issued from the card terminal however if a refund was necessary then it will only be administered against the original card from which the initial transaction took place. The university finance office will be required to assist and offer advice in terms of the processes required if and when a card refund is required. 5.0 Phoning for Authorisation On occasions the card terminal will prompt a message to the staff member to dial a pre-set telephone number to seek authorisation of the transaction. This process is partly automated and will prompt such questions as ‘is the card holder present’ and ‘the amount’ to be charged. An authorisation code is given to confirm that the transaction can proceed to full payment. 6.0 Merchant Copy Receipts Once entered and reconciled with the daily takings the merchant copy receipts are stapled to the ‘Z’ reading slip for that day. Both are then placed into the office safe along with all other payment methods received for that day (cash, cheque). All payment methods for a 7 day period (Friday to Thursday) are then reconciled for a second occasion and banked at the university finance section. The end of day ‘Z’ readings and the ‘Z’ reading from the PDQ terminal and merchant copy card receipts are kept together and are filed in a secure room within the facility. In line with the university requirements ‘Z’ readings from the PDQ terminal are recorded to a payment reconciliation sheet on a daily / weekly basis with the merchant copy receipts attached. The same sheets and the merchant copy card receipts are retained for 12 months at which point they will be destroyed using a paper shredder. 7.0 Storage and Access of Cardholder Data Storage of card details on PC’s in any format (email, access databases, excel spreadsheets, pen drives, etc. is not undertaken – once a purchase has been processed through the terminal and a customer and merchant copy receipt is produced the customer copy receipt is given to the customer or retained awaiting collection by the customer. If the customer does not collect the copy of their receipt it will be held at the facility for a period of time and will then be destroyed using a paper shredder. Merchant copies are filed with the necessary paperwork and stored securely. A spreadsheet record is kept weekly of card payment amount / date / and card type processed only as a point of reference i.e. method of payment records. 8.0 Staff Access / use of card machine The following members of staff are involved and responsible for card payment transactions: 1. 2. 3. 4. 5. 6. 7. Kevin Harris Stuart Fouldes Michelle Gilmurrey Laura Seddon Warren Lawrence Kiera Ellison Daniel Warnick Updated December 2014