How to Migrate to a New PSP Without Disrupting Your Business
Merchants often find themselves in the position of wanting, or needing to migrate to a new payment processor. A PSP migration is normally either to take advantage of lower fees or superior services, and rarely without challenges.
A reliable way to migrate to a new payment processor without disrupting business is to store card data in an independent vault rather than with the processor itself. This keeps a business from having to re-collect or re-tokenize any data when you migrate.
Why migrate to a new payment processor?
Most payment service providers (PSP) offer a somewhat unique fee structure, service set, and customer experience.
Many merchants start as clients of full-service PSPs, or aggregators, who eliminate the need for the merchant to jump through many of the hoops that can be necessary to start transacting credit card payments, like acquiring a merchant account, or becoming PCI-DSS compliant. Those full-service PSPs, while providing a valuable service that helps merchants get live quickly, unsurprisingly charge higher fees than those with more barebones offerings.
It is, therefore, extremely common for high-service PSP customers, as their transaction volume grows, to decide to migrate to a new payment processor.
Even merchants working directly with gateways find that, from time to time, opportunities arise to reduce their transaction costs or access new capabilities, particularly when they are operating at a high volume. Often, successful merchants will not just migrate to a new payment processor.
They will, in fact, add additional PSPs to their environments and commit to a multi-processor strategy.
What causes delays when migrating to a new PSP?
One of the key sources of delay in payment processor migrations is the transfer of stored customer credit card information. Generally speaking, the existing payment processor will store the merchant’s customers’ PII in its own environment and provide the merchant with a token. These tokens can be used to complete future transactions, enabling merchants to offer customers the option to securely save their credit card information.
However, to migrate to a new payment processor while retaining access to stored credit card details, the old processor must pass them to the new one, and the new one must pass new tokens back to the merchant.
Unsurprisingly, arranging for details to be shared from one PSP to another, particularly when the entity currently holding the information is losing a customer, can be long winded, complex, and expensive. Once that is finally completed, the process of having the new processor issue new tokens, then accurately switching those with the ones from the old processor, can disrupt the final steps of the process.
What are best practices for a PSP migration?
Perhaps unsurprisingly, the simplest way to avoid those data migration disruptions is not to allow them to happen in the first place. If the original payment processor does not hold the merchant’s customers’ credit card information, then it cannot disrupt the migration process with excessive delays or fees to transfer that data.
This is why many merchants today opt to use a third-party tokenization service provider (TSP) to act as an intermediary. Cardholder information is stored in the TSP’s secure vault, and the TSP issues the token to the merchant. The merchant can then instruct the TSP to share the card information with whichever PSP they choose, without ever bringing that PII in-house and putting themselves in a position where they must become PCI-compliant.
As an added bonus, by opting to use a TSP as an intermediary between their own systems and their original PSP, merchants have more options than to simply migrate to a new payment processor when better alternatives are available.
Because the cardholder data is securely stored in a programmable payment vault, the merchant can sign on with multiple PSPs, and use intelligent routing to decide which processor will be asked to complete each transaction.
In this way merchants can increase their likelihood of successfully executing each sale, reduce their fees, and build leverage in future negotiations with service providers.
When Maxio, a billing and financial reporting platform for B2B subscription businesses, needed to upgrade its payment infrastructure to support new markets, its tokens stayed portable.
How?
Basis Theory.
"Many providers hold tokens hostage in an attempt to prevent you from leaving their platform," says Jon Cochrane, GM of Partnerships and Payments at Maxio. "Because we had Basis Theory in place, this was a non-issue. We could simply focus on creating the best product experience for our customers. Without Basis Theory, that was a potential seven-figure problem for us.”
How does a PSP migration also reduce PCI scope?
Merchants that launch their businesses with full-service PSPs often do so because they are moving at lightning speed to get to market and have neither the time nor the resources to build fully PCI-compliant environments. Those full-service PSPs take on all the compliance risk, but also charge fees that reflect the additional responsibility, and use their guardianship of customer data as a lock-in device to keep merchants from migrating to new payment processors.
Ironically, using a TSP provides the same security for customer data without the lock-in to a single payment processor; it also allows the use of any PSP, from the most bare-bones gateway to high-risk merchant accounts to full-service processors.
Because the PII is submitted to and securely stored by the TSP and is passed to payment processors without ever being shared in plain text with the merchant, the PCI-compliance responsibility is retained by the TSP.
Merchants who have their customers’ credit card data stored securely at a TSP can migrate to a new payment processor without disruptions in time, resources, or money. They also have the option not only to migrate away from an existing PSP, but in fact to retain it and add others, and to use smart routing to send each transaction to the best processor for the job.
Start migrating payment data on your timeline. See how this works with Basis Theory