What happens to expired credit card data when it is uploaded to the Blackbaud Payment Service?
The Blackbaud Payment Service does not check for expired credit card data during the upload.
Does the Blackbaud Payment Service purge expired payment card information?
PCI DSS requirements mandate the purging of all credit card data when the card has expired more than 60 days. This process runs nightly in the Blackbaud Payment Service.
For more information about PCI DSS compliance, visit our PCI compIiance page. General information regarding PCI DSS, including a PCI DSS self-assessment questionnaire, can be found at www.pcisecuritystandards.org.
What credit card data will not be uploaded to the Blackbaud Payment Service?
Credit cards appear with question marks instead of asterisks when they cannot be uploaded. Credit cards will not be uploaded to BBPS in the following situations:
- The card number entered is already truncated
- The expiration date is blank or expired by 60 days or more
- The card is being entered on a Gift record which is not a Pledge or Recurring Gift
- BBPS has not been registered or is not in use
How long is credit card information stored in the Blackbaud Payment Service when a token is generated by entering the information on a Recurring Gift or the Bio 2 tab of a Constituent record?
If a credit card is stored on the Bio 2 tab, or on a Recurring Gift record, then it will be stored in the Blackbaud Payment Service until the card expires or is manually deleted from the record.
Are credit cards stored multiple times in the Blackbaud Payment Service if The Raiser's Edge is installed on both a live and test environment?
This can occur when installing The Raiser's Edge 7.91 on both a live and test environment.
To avoid this, the first user to log into the database after installing the update will need to react to the prompt “Database Update Required” with the following steps:
- Click “Yes” when prompted “System changes require that your database be updated at this time. Do you wish to continue?”
- At database revision (Update ID: 169), there is a PCI notice prompt to enter Blackbaud Payment Service credentials.
- Enter a username, password, and security token (only required if using ICVerify).
- Click OK.
- Select to conduct a live or test conversion. Selecting a test conversion will automatically remove the credit card data sent to the Blackbaud Payment Service after 14 days.
When performing a test conversion of The Raiser’s Edge, can the credit card removal period from the Blackbaud Payment Service be extended beyond two weeks?
The testing time period cannot be extended beyond two weeks.
Can we avoid deleting expired credit cards from the Blackbaud Payment Service?
Note: To comply with PCI-DSS, the Blackbaud Payment Service routinely deletes credit card numbers that are past 60 days expiration.
This occurs when updating to The Raiser's Edge version 7.91 or higher, or when credit cards stored in the Blackbaud Payment Service are past 60 days expiry.
Will credit card numbers be erased in The Raiser's Edge 7.91?
Only if you are not using the Blackbaud Payment Service.
If you do not elect to use the Blackbaud Payment Service and upgrade to The Raiser’s Edge 7.91, all credit card numbers in the database will be changed to question marks plus the last four digits. The credit card numbers will become invalid, and the only option to retrieve the data is to restore a backup created prior to the upgrade.
Can I process transactions remotely and at any time in the test database?
Yes, you can still continue to work in the test database for The Raiser's Edge after 14 days. The 14 day period is only the period in which the credit card numbers are deleted from the Blackbaud Payment Service.
What is the content of the Blackbaud Payment Service Agreement?
The Blackbaud Payment Service agreement content is here: https://www.blackbaud.com/files/bbms/bbpstc.pdf.
Is there a charge associated with the Blackbaud Payment Service?
The fees for the Blackbaud Payment Service are included in your Blackbaud maintenance agreement. For more information, review the Blackbaud Payment Services Agreement.
If I choose not to use Blackbaud Payment Service, can I ever store credit card information?
Once you upgrade to The Raiser’s Edge 7.91 you cannot store valid credit card numbers in the credit card number field without the Blackbaud Payment Service. If you elect not to use the Blackbaud Payment Service and you insert a credit card number, the number will be truncated and replaced with question marks plus the last four digits. If your organisation initially declined to use the Blackbaud Payment Service, and now desire to use it:
- Go to https://bbps.blackbaud.com to create an account.
- If you have already updated, you must log into The Raiser's Edge as Supervisor and enter your Blackbaud Payment Service credentials in “Config > General”.
- If you have not yet updated, make note of the Blackbaud Payment Service credentials you create so that you can enter them when prompted during the update.
- If you have already updated, credit card data that was lost during the update will not come back after registering for Blackbaud Payment Services.
For more information, review the Blackbaud Payment Services Agreement.
Does the database server need to have an Internet browser open to access the Blackbaud Payment Service when running The Raiser's Edge?
When The Raiser's Edge database is first updated it will need to connect to the Blackbaud Payment Service server to upload the credit card information. If you will be using this service, Internet access will be required on the server at this time. Once the database has been updated, future connections to Blackbaud Payment Service are made from the workstation processing credit card information.
Should Blackbaud Payment Service credentials be created before or during upgrade?
There is no specific rule as to when to create Blackbaud Payment Service credentials; this can be created prior to your upgrade if needed or at the time of upgrade. For more information on how to register for the Blackbaud Payment Service, please see BB616496.
What to consider before updating to The Raiser's Edge 7.91:
- Review compatibility information and the system requirements before you update.
- If your organisation is currently using an older version of The Raiser’s Edge, you must update to The Raiser's Edge 7.85 and latest patch before updating to version 7.91.
- If your organisation integrates with Blackbaud NetCommunity, you must update to Blackbaud NetCommunity 6.10 before updating to The Raiser's Edge 7.91.
- If you are installing The Raiser's Edge 7.91 on Windows Server 2008 R2 or Windows 7 and using the prepackaged SQL Server 2005 Express instance of SQL Server, you must upgrade SQL Express to Service Pack 3.
- If your organisation uses NetSolutions™ and you choose to run a test conversion, do not open NetSolutions in the test environment or you will lose the ability to download NetSolutions transactions. (BB703136).
- If your organisation uses the Unpost Gifts plug-in, download the plug-in compatible with version 7.83 or higher (BB298412).
- If your organisation integrates with The Patron Edge, you must stop the SQL integration job before updating The Raiser's Edge. Also review the best practices for backing up and restoring a database when The Patron Edge and The Raiser's Edge are integrated (BB458816).
- If converting from GiftMaker Pro to The Raiser's Edge, review Knowledgebase solution BB278258 before downloading this update.
- If you use AddressAccelerator and did not request an unlock code for version 7.82, 7.83, 7.84, or 7.85, you must generate one. AddressAccelerator must be unlocked after updating to version 7.82 or above, and will remain unlocked for all future updates. To generate an unlock code, use the Unlock Code Generator.
- After installing the update, perform the database maintenance recommended (BB578516).
Regarding The Raiser’s Edge 7.91:
- How to download and install The Raiser's Edge 7.91: BB700728
- Error: The Raiser's Edge cannot connect to the Blackbaud Payment Service. For the secure storage of new or edited credit card number information, The Raiser's Edge requires a connection to Blackbaud Payment Service. Please check your internet connection: BB616676
- How to register for Blackbaud Payment Service: BB616496
- Error: Is this a test conversion when updating to version 7.91: BB620504
- What are the new password changes to version 7.91: BB608912
- What is the Blackbaud Payment Service? BB548354
- Error: The Raiser's Edge has detected that your NetSolutions account information has not yet been updated to use Blackbaud Payment Service. To all the Blackbaud Payment Service to retrieve credit card information for NetSolutions transactions, you must resubmit your NetSolutions configuration to the server: BB700738
- What happens to credit card numbers that are entered in The Raiser's Edge 7.91? BB613095
- Why is the credit card number blank when downloading transactions? BB700854
- What is the time limit before a user is logged out of The Raiser's Edge due to inactivity? BB700588
- If I choose not to use Blackbaud Payment Service, can we ever store credit card information? BB618297
- Is there a charge associated with the Blackbaud Payment Service? BB700828
Downloading The Raiser's Edge 7.91
* If you are currently on version 7.81 or lower of The Raiser's Edge, you must first update to 7.85.
- Click “download .exe” for the first time for the organisation.
- The Terms and Conditions page appears.
- After carefully reviewing the Terms and Conditions, select either “I accept” or “I decline”.
- If “I accept” is selected, you are connected to the Blackbaud Payment Service server. If you receive the error: “Service Unavailable”, refer to BB617828 for any error messages or questions.
- Enter your site ID and email address. If you do not know your site ID, click the site ID link to go to your profile, where the site ID is listed.
- Verify your organisation address. If this information is incorrect, click the link to take you to your profile, where the address can be updated (by primary contact only).
- Create a user name and password for the Blackbaud Payment Service. Important notes regarding this information:
- Your username cannot be longer than 20 characters.
- Your password must contain at least 12 characters and include at least one lowercase letter, one uppercase letter, one number, and one special character such as @, #, $.
- Note your user name and password and store this information in a secure place. After updating The Raiser's Edge, the first user who logs into the database will be prompted to enter your organisation's Blackbaud Payment Service user name and password.
- If your organisation uses ICVerify to authorise credit cards, mark the “Generate reference code” checkbox. Note the code provided, and store this information in a secure place. When the first user logs into the database, he will need to enter the reference code in addition to your organisation's Blackbaud Payment Service login.
- If your organisation does not use ICVerify, click Next to continue. Refer to BB617829 for any error messages or questions on this step.
- You will be redirected to the download file to proceed with downloading The Raiser’s Edge 7.91. The following content is placed on the download pages:
- Accepted Payment Application Data Security Standards (PA-DSS) Terms and Conditions, accepted by [Customer Name] on [Date] and [Time]
- Accepted Blackbaud Payment Service (BBPS) Terms and Conditions, accepted by [Customer Name] on [Date] and [Time]
- If “I decline” is selected, a confirmation page appears to make sure you want to decline the use of Blackbaud Payment Service. Click “Yes” or “No”. Clicking “No” takes you back to the Terms and Conditions page; clicking “Yes” takes you to download the .exe file.
- The following content is listed on the download pages:
- Declined Payment Application Data Security Standards (PA-DSS) Terms and Conditions, by [Customer Name] on [Date] and [Time]
- Declined Payment Application Data Security Standards (PA-DSS) Terms and Conditions, by [Customer Name] on [Date] and [Time]
Update The Raiser's Edge to version 7.91
- Review the installation instructions (BB202814) and update the server and workstations using the files downloaded above.
Note: Before you proceed with the following instructions, back up the database. If your organisation integrates multiple Blackbaud products, refer to the Additional Requirements section of the backup solution.
- The first user to log into the database for the first time after running the update receives a prompt that indicates “Database Update Required”. Click “Yes” to that prompt.
- At database revision (Update ID: 169) there is a prompt where it is determined whether or not you have chosen to use Blackbaud Payment Service, to which you can select “Yes” or “No”.
- If “No” is selected, The Raiser’s Edge truncates all credit card numbers in the database. After the conversion, the credit card number appears as question marks plus the last four digits of the card number.
- If “Yes” is selected, The Raiser’s Edge transfers the credit card data to Blackbaud Payment Servie. At this time, the Blackbaud Payment Service login and password created above should be entered before proceeding. In addition, the ICVerify security token from above should be entered, if applicable.
- Click “OK” to continue with the update.
- At the prompt, “Is this a test conversion?”, indicate whether the update you are running is intended for temporary and/or testing purposes only, or if it is a live update (BB700396).
- If “Yes” is selected, The Raiser's Edge will flag your credit card data as test, and remove it from Blackbaud Payment Service after 14 days.
- If “No” is selected, all credit card data will be uploaded to Blackbaud Payment Service and will remain on Blackbaud Payment Service until expiration or manual removal.
- Familiarise all users with the password changes for The Raiser's Edge 7.91, as each user will be affected by these changes upon login.