Your fans. Your data.Our rails.

The questions an enterprise buyer asks before the demo, answered before the demo. Take them into every payments conversation you have this year, including the one with us.

Payment topologyTwo paths
Funds path
CaptureGateway orchestrationAcquirer, operator MIDsOperator bank accounts
Data path
CaptureMatching engineOne resolved profileOperator CRM, loyalty, sponsorship
Never shared between them
SettlementMerchant of recordBank credentials
PCI DSSv4.0.1 is the active standard
SOC 1 and SOC 2Security governance
P2PE capableTokenised at capture
150 bpsVisa merchant excessive threshold

The club owns
the fan record.

This is the question most payment vendors never answer in writing, and the one an operator should ask first.

01

Who is accountable

The club or operator is the accountable organisation. Ordr is a processor working to the club's instructions, for the club's purposes, and for no others. Any arrangement that cannot be described in those terms should be read closely.

  • Enriched records return to systems you own. Your CRM, your ticketing platform, your BI stack, exportable in full at any time.
  • No resale. Ordr does not sell client data to anyone.
  • No cross client modelling. Your fans do not train anything for another club.
  • No marketing to your fans. Not by us, not by a partner of ours.
  • No retention after termination beyond the window stated in your agreement.
Custody chainContractual
The fan
Consents once, to the club's terms
The club
Accountable organisationSets the purposeOwns the record
Ordr
Processor onlyPurpose limited by contractComparable protection required
A fan tapping to pay at a reader

Tokenised at capture.

The card credential is tokenised at the point of authorisation. Primary account numbers do not enter club systems, which is what takes those systems out of PCI scope rather than merely encrypting what is already there.

Encrypted in use,
not just at rest.

Ordr’s payment data runs on Cy4Secure, Cy4data’s persistent encryption platform. Most stacks encrypt data at rest and in transit, then decrypt it to work on it. That decryption window is the gap Cy4Secure closes: the data stays encrypted while it is queried, processed and shared, so a stolen credential or a copied database yields cipher text rather than a record.

01At rest, in motion and in use

AES-256 applied at the element level, down to a single field or record. Databases operate natively on the encrypted data, so nothing is decrypted to run a query and there is no performance cost to carrying it.

02Keys and data live apart

Encryption keys are held separately from the data, with no connection between key locations, data stores and users. Possession of a password is not possession of the keys, which is what takes an insider or a supply chain compromise off the table.

03Every key request is watched

Keys are issued only to authorised users and applications. Access is monitored in real time, abnormal patterns are stopped by machine learning detection and multi factor verification is forced, so credential dumping, account takeover and man in the middle attempts fail at the key rather than at the door.

Persistent encryption is how Ordr meets PCI DSS requirements 3 and 4, protecting stored cardholder data and encrypting it in transmission, and it supports the same obligations under GDPR and CCPA. Platform details from the Cy4data security and compliance certification issued for Ordr, reviewed annually. The requirement by requirement mapping is in the technical pack.

Reference
architecture.

The most useful thing a payments partner can publish is a topology, because it shows without adjectives which path the money takes, which path the data takes, and whether they are the same path.

The funds path and the data path are separate.

Settlement moves from the acquirer into your accounts under your merchant identifiers. The intelligence layer never sits in the funds path.

Which means it is removable.

Dropping the analytics would not force a payments re-tender. Apply that test to any vendor diagram, ours included: if removing the data product breaks settlement, the paths were never separate and your switching cost is higher than the contract suggests.

Gateway agnostic by design.

Certified with FreedomPay and Moneris, with native connectivity to Micros Simphony and to Ticketmaster through Archtics Transaction Services.

Role based access, event and device level.

Reporting, reconciliation and dispute evidence are scoped to the people who need them, down to the individual fixture and the individual terminal.

Named,
not implied.

Ordr holds PCI DSS, SOC 1 and SOC 2, and is P2PE capable. The technical pack names the version, the assessment type, the observation window and the criteria in scope, because a certification without those four things is a word rather than a claim.

01PCI DSS v4.0.1 is the standard that applies

Version 3.2.1 was retired on 31 March 2024, and the 51 future dated requirements in v4.0 became mandatory on 31 March 2025. Any assessment conducted in 2026 is conducted against v4.0.1.

02SOC 1 and SOC 2 are different reports for different questions

SOC 1 addresses controls relevant to financial reporting. SOC 2 addresses the trust services criteria. Security is mandatory in every SOC 2. The others are selected against the commitments the provider has actually made.

03P2PE capable is not the same claim as a validated P2PE solution

We say capable because that is the accurate word for the hardware and the architecture. Vendors who blur those two claims are worth a follow up question.

PCI DSS version status from the PCI Security Standards Council.

The math changed
in April.

On 1 April 2026 the Visa merchant excessive threshold under the Acquirer Monitoring Program dropped from 220 basis points to 150. An operator that was comfortably compliant under the old ceiling can be in breach today without changing a single operational practice.

150 bps

The merchant excessive threshold from 1 April 2026, down from 220. Acquirer level thresholds sit tighter still, at 50 basis points standard and 70 excessive.

Visa, 2026Open the fact sheet →
By count

The ratio is measured by transaction count rather than value, so a high volume game night carries proportionally more exposure than the same revenue spread across fewer, larger transactions.

Why arenas are exposedSee Transact IQ →
$82 + $46

Internal cost plus third party fees on a single chargeback, before the value of the goods. The Vegas Golden Knights recovered $82,500 of it.

Mastercard, June 2026Open the source →

There is a trap in the obvious response. Tightening fraud rules to decline more transactions shrinks the denominator without shrinking the numerator, which can push the ratio further out of compliance. Approving more legitimate transactions while reducing genuine disputes requires transaction level evidence, not a stricter rule.

One mesh.
Every transaction
in it.

A bank note is engraved rather than printed because the pattern is the proof. The same idea runs through this platform: one continuous surface where every transaction, every fan and every partner activation sits in the same weave rather than in nine separate documents.

Six questions,
and the non answers.

Take these into every payments conversation you have this year. The second half of each card is what a vendor says when the real answer is inconvenient.

01Which PCI DSS version were you assessed against, and when?

A usable answer names the version, the assessment date, the assessor and the report type. "We are PCI aligned" is not a standard and not an answer.

02SOC 2 Type I or Type II, and over what period?

Type I is an opinion on whether controls are suitably designed at a point in time. Type II tests whether they operated over an observation window. A usable answer names the type, the window and the criteria in scope.

03Where does cardholder data live, and who is in PCI scope?

A usable answer is that card credentials are tokenised at capture, no primary account numbers enter club systems, and the scope reduction is documented. "Everything is encrypted" is not.

04Who is merchant of record, and where do funds settle?

A usable answer is that the operator is merchant of record and funds settle directly into the operator's own accounts. "We handle settlement for you" is a different arrangement.

05On termination, what do we get back and what do you keep?

A usable answer is a full export in a documented format and a stated deletion window. Silence, or "we would work with you on that", is the answer to be worried about.

06Where is the data resident?

A usable answer names the region, names the provider and puts both in the contract. "Secure cloud infrastructure" names nothing.

Ask the hard one.

Send the question your security team would ask if they were on the call. If the answer is not flattering to us we will still give it to you in writing.

Switching to Ordr was one of the smartest and easiest decisions we've made. By moving our payments under Ordr, we gained visibility into hidden costs and started unlocking valuable, revenue-driving data.
Mike DillonChief Financial Officer, Pittsburgh Penguins

We use this to route you to the right person. No sequence, no drip.

Thank you.

Your request is in. Someone from Ordr will reply directly, usually within one business day.