One fan, nine systems,and the questionnobody puts in writing.

Every operator knows its payment data is fragmented. Far fewer can say, on paper, who owns the fan record once it leaves the turnstile. This report sets out the three things to require in writing from any payments partner, and why the dispute rules that changed in April make the question urgent rather than academic.

Field report 0112 references
Scope
North American arenasStadiumsMulti property operators
Subject
Data custodyCard security standardsDispute economics
Published
August 2026Ordr Technologies Inc.
11 minReading time
12References, all linked
Aug 2026Published
FreeNo form in front of it

The stack,
not the rate.

When a team puts payments out to tender, the document that comes back is priced in basis points. The problem it is meant to solve is not a pricing problem.

01The same person appears as several people

The fan who bought the ticket in March and the fan who bought two beers in section 103 in October are, inside the operator's own systems, two different people.

02Every channel has its own identifier

Ticketing on one platform, food and beverage on a second, retail on a third, premium on a fourth, parking on a fifth, CRM on a sixth. Each with its own merchant identifier, its own export format, and its own idea of what a customer record is.

03The rate is the smallest line in the argument

A processor competing on interchange plus is competing on the smallest number in the operator's economics. The larger ones sit in reconciliation labour, in sponsorship inventory that cannot be priced because attribution is missing, and in renewals decided without knowing what a seat holder actually spends.

On that last point there is a number. Forrester found that 76 percent of US B2C marketing executives who invested in sports sponsorship in 2024 struggle to calculate the ROI, while 39 percent planned to increase investment and 28 percent planned to enter the category for the first time. Forrester, Q4 2024 CMO Pulse Survey. Money is going in faster than measurement is.

A fan paying at a stadium concourse counter

Who owns the fan record.

This is the question most payment vendors never answer in writing, and the one an operator should ask first. In Canada it has a precise legal answer, and the answer is not flattering to vendors who prefer to leave it vague.

The operator is
the accountable party.

Under PIPEDA, Schedule 1, Principle 4.1.3, an organisation is responsible for personal information in its possession or custody, including information transferred to a third party for processing, and must use contractual or other means to provide a comparable level of protection while that third party processes it.

01

A transfer is a use, not a disclosure

The Office of the Privacy Commissioner has consistently treated a transfer to a service provider as a use by the organisation rather than a disclosure to a new owner. The information stays under the transferring organisation's control, and the service provider may use it only for the purposes for which it was originally collected.

  • The operator sets the purpose and owns the record.
  • The processor is purpose limited by contract, with comparable protection required for as long as it holds the data.
  • Enriched records return to the operator's systems, exportable in full on request or on exit.
  • Four exclusions are worth checking clause by clause: no resale, no cross client modelling, no marketing to the operator's fans, and no retention after termination beyond a stated window.
Custody chainPIPEDA 4.1.3
Fan
Consents once, to the operator's terms
Operator
Accountable organisationSets purposeOwns the record
Processor
Purpose limitedComparable protectionReturns or deletes on exit

Three instruments,
one direction.

Federal privacy reform in Canada is on its third attempt, and every version of it moves the same way.

01

Bill C-27 died on the Order Paper

The bill that would have replaced PIPEDA's private sector rules did not survive the parliamentary session. It was the second attempt after 2020's Bill C-11.

02

Bill C-36 was introduced on 15 June 2026

The Protecting Privacy and Consumer Data Act would repeal Part 1 of PIPEDA and replace it. Third attempt in six years, and substantially similar in shape to what came before.

03

Bill C-15 received Royal Assent on 26 March 2026

The Budget 2025 Implementation Act No. 1 adds a data mobility framework to PIPEDA. Regulations are still to come, so it is not yet operative.

Quebec's Law 25 is already fully in force with penalties in the same tier as GDPR. For any operator with Quebec resident fans, which is most Canadian sports and entertainment businesses, that is the effective floor today regardless of where federal reform lands. The practical implication for a procurement team is simple: write the custody model in controller and processor terms now, because that is where all of these instruments are heading.

What "secure"
has to mean.

Security claims on payments websites have a language problem. "Bank grade", "enterprise grade" and "PCI aligned" are not standards. There are only a small number of statements here that mean something, and each has a date attached.

v4.0.1Primary source

The active PCI DSS version. v3.2.1 was retired on 31 March 2024, and v4.0.1 was published in June 2024 as a limited revision that added and removed no requirements. Any assessment conducted in 2026 is conducted against it.

PCI Security Standards CouncilOpen the source →
31 Mar 2025

The date the 51 requirements that were future dated best practices in v4.0 became mandatory. A vendor describing itself as PCI compliant without naming a version and a validation date is describing nothing.

PCI Security Standards CouncilOpen the source →
Type II

The SOC 2 report enterprise buyers in regulated environments generally require. Type I is an opinion on design at a point in time. Type II tests whether controls operated over an observation window, typically six to twelve months.

The complete sentence names type, window and criteriaSee our position →

So "we have SOC 2" is an incomplete sentence. The complete one names the type, the observation window, the criteria in scope, and the systems inside the boundary. The six questions that produce an answer, and the non answers to watch for, are on the trust and security page.

Section 04.
Reference architecture.

The single most useful thing a payments partner can publish is a topology, because it shows without adjectives which path the money takes, which path the data takes, and whether those paths are the same one. In the model below they are deliberately separate.

Capture

Card credential tokenised at the point of authorisation, across PIN pads, mobile checkout, kiosks, box office and online ticketing. No primary account number enters the team’s systems.

Funds path

Gateway orchestration, then the acquirer under the operator's own merchant identifiers, then the operator's own bank accounts. The operator stays merchant of record and settlement never passes through the intelligence layer.

Data path

A matching engine joins card present and card not present activity to one fan record, and writes the enrichment back to the operator's CRM, loyalty and sponsorship systems.

The test to apply

If removing the analytics product would require re-tendering payments, the two paths are not actually separate, and the operator's switching cost is higher than the contract suggests.

The dispute math
changed in April.

Chargeback management has moved from a back office nuisance to a threshold problem with a date on it. On 1 April 2026 the Visa merchant excessive threshold under the Acquirer Monitoring Program dropped from 220 basis points to 150.

01Compliant yesterday, in breach today

The Acquirer Monitoring Program consolidated the legacy Dispute and Fraud Monitoring Programs into a single ratio: reported fraud plus disputes divided by settled transactions. An operator comfortably inside the old ceiling can be outside the new one without changing a single operational practice.

02Measured by count, which is the worst case for an arena

Because the ratio uses transaction count rather than value, a high volume game night carries proportionally more exposure than the same revenue spread across fewer, larger transactions. Acquirer level thresholds sit tighter still.

03The obvious response makes it worse

Tightening fraud rules to decline more transactions shrinks the denominator without shrinking the numerator, which can push the ratio further out of compliance. The workable path is approving more legitimate transactions while reducing genuine disputes, and that requires transaction level evidence rather than a stricter rule.

Threshold and programme structure from the Visa Acquirer Monitoring Program fact sheet. Mastercard does not publish its numeric excessive chargeback thresholds, so this report does not state them.

Evidence,
and its basis.

A report that argues for numbers over testimonials owes its own numbers a basis. Below is what Ordr has deployed, what was measured, and how each figure was produced, including where the measurement is weaker than we would like.

55 bps

Average interchange cost reduction following a fee structure review and routing changes, measured against the trailing period under the prior provider. Vegas Golden Knights.

Club reported, method documentedRead the case study →
53%

Reduction in processing costs within sixty days, following consolidation of more than a dozen vendors onto one platform. Pittsburgh Penguins.

Club reported, method documentedRead the case study →
80+ hrs

Internal staff time per month previously spent on reconciliation and manual reporting. Self reported by the club's finance team, and labelled as such wherever it appears.

Self reportedRead the case study →

Two further figures recovered from Ordr's earlier material, a 2.86 percent to 1.91 percent effective rate comparison and a $37,000 average annual saving, are deliberately absent from this report and from the rest of this site. Neither states across how many merchants or over what period it was measured. Until they do, they are not publishable by the standard this document is asking operators to apply.

Method
and disclosure.

Regulatory and card network statements in this report are drawn from primary sources where available, and from named secondary analysis where a primary source is paywalled or not public. Every such statement carries a reference and a date, because each is a moving target. Card network thresholds have changed twice in eighteen months, and Canadian federal privacy legislation is on its third attempt at reform.

References

  1. PIPEDA, Schedule 1, Principle 4.1.3. Justice Laws Canada. Open →
  2. Guidelines for processing personal data across borders. Office of the Privacy Commissioner of Canada. Open →
  3. Bill C-36, the Protecting Privacy and Consumer Data Act, introduced 15 June 2026. Fasken. Open →
  4. Bill C-15, Budget 2025 Implementation Act No. 1, Royal Assent 26 March 2026. Parliament of Canada. Open →
  5. Amendments to PIPEDA add data mobility. McCarthy Tetrault. Open →
  6. PCI DSS v4.0.1 published. PCI Security Standards Council. Open →
  7. The future dated requirements of PCI DSS v4.x became mandatory 31 March 2025. PCI Security Standards Council. Open →
  8. Visa Acquirer Monitoring Program fact sheet. Visa. Open →
  9. What is the true cost of a chargeback. Mastercard, updated June 2026. Open →
  10. Sports sponsorships surge despite fuzzy ROI. Forrester, Q4 2024 CMO Pulse Survey. Open →
  11. Archtics season ticketing and Archtics Transaction Services. Ticketmaster developer docs. Open →
  12. Cost of a Data Breach Report 2025. IBM. Open →

Deployment figures are Ordr's own, from client engagements, with the basis of each stated above. Ordr is a commercial payments and data platform for live event operators and this report argues for a position its product is built to serve. Weigh it accordingly and verify the regulatory claims independently. Every one of them is publicly checkable, which is the point. Last reviewed August 2026.

Take Section 03 with you.

The six questions in this report work on any payments vendor, ours included. Ask us first if you like. The technical pack answers all of them in writing.

Switching to Ordr was one of the smartest and easiest decisions we've made. By moving our payments under Ordr, we gained visibility into hidden costs and started unlocking valuable, revenue-driving data.
Mike DillonChief Financial Officer, Pittsburgh Penguins

We use this to route you to the right person. No sequence, no drip.

Thank you.

Your request is in. Someone from Ordr will reply directly, usually within one business day.