We have our Event Espresso installed at events.rrc.ca and it has been working swimmingly despite running on a Windows IIS server. We are in the middle of a PCI compliance exercise at my work, and the question that came us was “is using Paypal PCI compliant?” We do not store any payment/cc info other then the registrant’s name and sometimes address, we push them to Paypal to pay, and when they are done paying we store the Paypal transaction ID. We have a SSL-certificate installed on our site (so it’s https://events.rrc.ca when they are filling out event registration stuff). We have a consultant saying that Paypal’s servers are in-scope in the latest iteration of PCI compliance madness. We disagree. But we’d like to hear your guy’s opinion on the matter.
Yes. As long as you are using Paypal Standard, you shouldn’t have to worry much about PCI compliance. If you were using Paypal Payments Pro, then you would need an SSL (https://) on your server to remain in compliance.
The support post ‘We use Paypal Standard (PayPal IPN) to process payments… are we PCI compliant?’ is closed to new replies.
Have a question about this support post? Create a new support post in our support forums and include a link to this existing support post so we can help you.
Support forum for Event Espresso 3 and Event Espresso 4.