Do I need an SSL certificate for a website that allows people to make donations over

Discussion in 'eCommerce' started by brianflhome, Nov 25, 2010.

  1. #1
    It is technically a foundation, a non profit organization website, which will allow people to make donations for the cause. Is purchasing an SSL certificate for this site a good idea?
    If i have to purchase then which one is better for such a site?
     
    brianflhome, Nov 25, 2010 IP
  2. muffet

    muffet Active Member

    Messages:
    720
    Likes Received:
    7
    Best Answers:
    4
    Trophy Points:
    68
    #2
    Yes you will need a SSL certificate for your website since people will be either utilizing their credit card or PayPal account to make the donation. Google SSL Certificate Reseller there are many who sell SSL certificate. You don't necessarily need EV SSL Certificate just the regular one depending upon how much you want to insure buyers for their purchases in the event their financial information were stolen from your site.
     
    muffet, Nov 26, 2010 IP
  3. om3

    om3 Member

    Messages:
    180
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    30
    #3
    since you are panning to accept online payment it would be better if you have secure transaction using Dedicated SSL which won't charge you huge amount, SSL certificates are available from 20$ but it will give a good impression and secure environment for all great soul who want to help society.
    VeriSign, GeoTrust ,rapidssl etc are few wellknow vendors.
     
    om3, Nov 26, 2010 IP
  4. rofro

    rofro Peon

    Messages:
    49
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    If the OP is accepting donations via PayPal, there is no need for an SSL certificate as the donors will be redirected to PayPal's secure website to make the donation. No transaction or sensitive data will be transmitted on the OP's website.
     
    rofro, Nov 26, 2010 IP
  5. akabou

    akabou Peon

    Messages:
    24
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    If you have a shared server you can rent ssl certficate. If it's a dedicated server and want to accept online payment
    it's better to have an ssl certficat that is validated with for example verisign.
    Or as said rofro , you can use paypal, and just add a button that redirect user to your paypal account
     
    akabou, Nov 28, 2010 IP
  6. OliviaSSLGuru

    OliviaSSLGuru Greenhorn

    Messages:
    18
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    11
    #6
    You should have a certificate for a site. If you are using paypal, still you should get a standard certificate, otherwise go for a high security cert. Even paypal insists that you should get a certificate. They dont cost much. There are many resellers. I got it from rapidsslonline.com
     
    OliviaSSLGuru, Dec 15, 2010 IP
  7. 00dacousin

    00dacousin Peon

    Messages:
    41
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    You should defiantly have SSL you will also need a privacy policy and internal policies about how any information you collect is used and stored not just payment details but people's personal details make sure you follow all relevant laws regarding this.
     
    00dacousin, Dec 15, 2010 IP
  8. FookerFTW

    FookerFTW Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Yes, if you are handling peoples info then you will want a certificate or people will be uneasy.
     
    FookerFTW, Dec 15, 2010 IP
  9. Tomastamm

    Tomastamm Well-Known Member

    Messages:
    448
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    110
    #9
    yes :)
     
    Tomastamm, Dec 15, 2010 IP
  10. supdoggy

    supdoggy Peon

    Messages:
    105
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I'm not trying to advertise, but NameCheap offers free "Comodo SSL" for all new domain registrations. I think this is the same thing right?
     
    supdoggy, Dec 16, 2010 IP
  11. econeve

    econeve Peon

    Messages:
    40
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #11
    You don't necessarily need an SSL certificate but it would be nice to have one. If you're accepting payments via PayPal i.e. the donator leaves your site onto the PayPal site, it's not really needed. PayPal is already safe as is and is encrypted already.

    Either way, it's a good option to get one. I believe you can get one from around $50 per year as the cheapest and of course the prices increase depending on the companies and options you use.
     
    econeve, Dec 16, 2010 IP
  12. mhchan

    mhchan Peon

    Messages:
    72
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Yes, i agree. If you are accepting payment/donation via Paypal, you do not need to have a SSL certificate
     
    mhchan, Dec 25, 2010 IP
  13. alongston

    alongston Peon

    Messages:
    9
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    You should get an SSL cert if you are collecting any personal information about your visitors. If you require the visitor to leave the system to a page on the Paypal website (or an https site) then you will not need one, but if you have Paypal pro and collect the information via your site you will definitely need one. Most domain registrar companies also sell SSL. You will have to install the cert once you purchase it, so it may be easier to purchase from the domain registrar you purchased your domain from.
     
    alongston, Dec 26, 2010 IP
  14. Seeker2011

    Seeker2011 Peon

    Messages:
    15
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    SSL certificate is needed ALWAYS in my opinion if the content of the data being transmitted online is not something you want others to see.

    Simple as that.

    This includes emails, texting, ftp, ordering online, filling out forms, live chat, banking online ....

    It is so easy to have a software listen in on your data transmission (specially in coffee shops with a laptop) and record everything and see what you are sending over the internet if you do not use an SSL.

    Be warned.
     
    Seeker2011, Jan 7, 2011 IP
  15. Corey Bryant

    Corey Bryant Texan at Heart

    Messages:
    1,126
    Likes Received:
    51
    Best Answers:
    0
    Trophy Points:
    0
    #15
    If you are a non-profit, it could be understandable that you just re-direct users over to the electronic payment gateway's secure website or a third party processor. Doing this though - you would want to explain what would be happening.

    Having the SSL though on your website would help to maintain a consistent process. You would need to contact your hosting company to see if they charge extra for an IP address (this is needed for the SSL). As another poster stated, some hosting companies will offer a "free" https:// url. Usually though this is something like https://ssl.example.com/yoursite, since the SSL is issued to the domain name (ssl.example.com). You will need to make sure though that everything is uploaded properly - like your images, external CSS, etc. If not, the users will get an error message since some of the content is not coming from a secure website.

    Either way you choose, make sure you test it in a couple of browsers to see if any issues arise.

    As far as SSL certs, check out WhichSSL - this might help you some.
     
    Corey Bryant, Jan 10, 2011 IP
  16. gotlivechat

    gotlivechat Member

    Messages:
    516
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    35
    #16
    Regardless of your business type, if you're accepting payments online you need SSL. If you check your documentation through your cc processor they'll mention it's required as well.
    Not to mention visitors making donations will be more confident in doing so (if they see the padlock ensuring encrypted connection).
     
    gotlivechat, Jan 13, 2011 IP
  17. JerrickYeoh

    JerrickYeoh Active Member

    Messages:
    1,586
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    53
    #17
    Yes that a must. Even most of web hosting provider now are having bundle package with SSL.
    It become a basic need especially money involve website. Everyone that donate will look for SSL , is that secure to share their personal information and credit card numbers for the donation.
    You definitely need it.
     
    JerrickYeoh, Jan 18, 2011 IP
  18. gotlivechat

    gotlivechat Member

    Messages:
    516
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    35
    #18
    The only way I could see you wouldn't need a SSL cert is if i you're using a 3rd party payment processor (where a visitor to your site is taken to a 'separate' web site where they actually enter their payment details).
    But if your site is the place where the payment details are being handled (by server scripting) then yes SSL needed.
     
    gotlivechat, Jan 18, 2011 IP
  19. dhblewis

    dhblewis Guest

    Messages:
    466
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #19
    I would invest in a SSL cert if you take any details on your site even if payment is handled by a third party processor such as Paypal. It gives out a professional image and can be reassuring. They start from under $20 so theres no need to buy a €200++ one for what you need it for.
     
    dhblewis, Jan 18, 2011 IP
  20. pesnax

    pesnax Peon

    Messages:
    67
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #20
    It depends. Are you’re visitors/donors submitting any information at your website (credit card details, e-mail address, address or similar) – when I would say yes. If not – no – but it might help improve your sites/organizations credibility. VeriSign sells their VeriSign Trust Seal at $299 (I know it is expensive) – which is not a SSL certificate but includes a daily malware scan of your website.
     
    pesnax, Jan 20, 2011 IP