

GoCardless
By GoCardless Ltd
The typical implementation process for GoCardless software generally involves the following steps:
Account setup: Create a GoCardless account or connect an existing one. This can be done quickly, often in minutes.
Integration: Integrate GoCardless with your existing systems or website. This may involve using their API or pre-built integrations. The time required depends on your technical resources and complexity, but can be relatively quick for basic setups.
Customer onboarding: Set up a process for customers to authorize Direct Debit payments. This includes creating mandate forms and payment pages.
Testing: Thoroughly test the integration to ensure payments are processed correctly. This may take a few days to a week.
Go live: Start accepting real payments once testing is complete. This can be done immediately after successful testing.
Ongoing optimization: Regularly review and optimize your payment processes. This is an ongoing process that continues after initial implementation.
The total implementation time can vary widely depending on the complexity of your integration and your internal processes. A basic setup could be completed in a few days to a week, while more complex integrations might take several weeks. GoCardless offers support throughout the process to help streamline implementation.
GoCardless offers several customization options to fit specific business needs:
Custom payment pages: You can customize the GoCardless sign-up pages and notification emails with your brand logo and colors to provide a consistent brand experience.
Tailored payment flows: GoCardless allows you to embed bank debit as your preferred payment method throughout your customer flow, including contracts, engagement letters, and dedicated "About GoCardless" pages on your website.
API integration: GoCardless provides a clean, RESTful API that allows you to integrate their payment system directly into your website or application.
Multiple implementation options: You can use GoCardless through their dashboard, via account software partnerships, or through their API, depending on your business needs.
Localization: GoCardless supports tailoring payment pages for different countries, including language customization and using local terminology for payment methods.
Branding on bank statements: You can customize what appears on customers' bank statements by contacting GoCardless support.
Premium Success services: For businesses with more complex needs, GoCardless offers a Premium Success package that includes tailored strategic guidance, dedicated support, and personalized recommendations.
Partner integrations: GoCardless has integrated with over 300 popular billing platforms, CRMs, and accounting packages, allowing for easy integration with existing business systems.
Flexible payment options: You can collect both one-off and recurring payments, giving you flexibility in how you structure your payment collection.
These customization options allow businesses to tailor the GoCardless experience to their specific needs, branding, and customer base.
GoCardless offers several types of training and support to help new users get started and make the most of their platform:
Online Customer Hub: GoCardless provides an online platform dedicated to helping users succeed, with training resources, knowledge articles, and event listings.
API developer documentation: For technical integrations, GoCardless offers comprehensive API documentation to help developers get up and running quickly.
24/7 Support: GoCardless has an award-winning support team that works around the clock to answer queries as quickly as possible.
Implementation assistance: For businesses that need more hands-on help, GoCardless offers dedicated implementation support to guide users through the setup process.
Customer Success Management: GoCardless provides customer success managers to help businesses optimize their use of the platform and achieve their goals.
Professional Services: Additional services are available for businesses that need more tailored support or advanced features.
Onboarding guidance: GoCardless offers guidance on how to set up customers with Direct Debit, including email templates and best practices for customer communication.
Educational resources: The company provides guides and blog posts to help users understand various aspects of using GoCardless and implementing Direct Debit payments.
Partner integrations: GoCardless has integrated with over 300 popular billing platforms, CRMs, and accounting packages, which can simplify the onboarding process for businesses already using these systems.
Customization support: GoCardless offers assistance in customizing payment pages, branding, and other aspects of the service to fit specific business needs.
These resources and support options are designed to ensure that new users can quickly become proficient with the GoCardless platform and maximize its value for their business.
GoCardless has implemented several robust security measures to protect data:
ISO 27001 certification: GoCardless has been ISO 27001 certified since 2016, indicating their information security management system meets international standards.
Strong encryption: GoCardless uses 256-bit SSL encryption for all client-server communication, which exceeds the 128-bit standard required by the banking system.
Firewall protection: Their financial data server is separated from the application server by multiple firewalls.
Secure client monies accounts: All collected funds are held in secure client monies accounts with major banks like Royal Bank of Scotland, Barclays Bank, BNP Paribas, and others.
GDPR compliance: GoCardless has a global data risk management program built to GDPR standards, applying privacy best practices to protect personal data.
FCA authorization: GoCardless is authorized by the UK Financial Conduct Authority to provide payment services as an Authorized Payment Institution.
Vulnerability management: They have a process for handling and addressing security vulnerabilities, including a bug bounty program.
Access restrictions: GoCardless implements strict access controls, including two-factor authentication and VPN requirements for admin users.
Regular security audits: As part of their ISO 27001 certification, GoCardless undergoes annual reassessments by independent auditors.
Incident management: They have a dedicated team of site reliability engineers responsible for responding to technical and security incidents 24/7.
These measures demonstrate GoCardless's commitment to maintaining high standards of data protection and security for their users.
Continuous integration: GoCardless uses continuous integration for software changes, including automated evaluation of code quality and running of unit and integration tests.
Version control: Code and configuration files are managed using Github for version control, shared ownership and code review.
Regular releases: The GitHub repository for GoCardless CLI releases shows multiple beta versions and updates, indicating frequent iterative releases.
Security patches: All urgent security patches are applied immediately, while other updates are applied as soon as reasonably practical.
Change management process: Technical changes and their impact on security are evaluated as part of the project scoping and delivery workflow. This includes mandatory peer reviews of code.
Business and compliance changes: These are evaluated as part of routine weekly senior management meetings and quarterly Board meetings.
Configuration and change management: GoCardless follows a supplier-defined controls approach for configuration and change management.
Rolling and fixed-term contracts: GoCardless offers both rolling and fixed-term contracts.
Cancellation process: To cancel the contract, customers can simply email their Account Manager or the Support Team at [email protected], requesting cancellation.
Notice period: For Direct Debit payments, a bank will require at least 1 day's notice before the next payment date for cancellation.
Account closure requirements: GoCardless can only close an account if the merchant is no longer collecting payments.
Account closure process: To help close an account as quickly as possible, customers should ensure that all pending payments are completed.
Termination rights: GoCardless reserves the right to terminate or suspend the agreement under certain circumstances.
Consequences of termination: Upon termination, GoCardless may:
a. Reverse or cancel transactions, or advise customers to reverse or cancel transactions.
b. Suspend payouts to the merchant's nominated account.
Post-termination obligations: Even after termination, merchants are required to:
a. Keep detailed records of transactions for at least 18 months after stopping use of the GoCardless service[44b].
b. Pay any outstanding fees or amounts owed to GoCardless.
Changes to terms: For Micro-Enterprises, GoCardless must provide at least two months' notice for any changes to fees or terms. Customers have the right to terminate the agreement without charge during this notice period.
GoCardless adheres to several important compliance standards and regulations:
PCI DSS Compliance: GoCardless complies with the Payment Card Industry Data Security Standard (PCI DSS), which is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
ISO 27001 Certification: GoCardless has been ISO 27001 certified since 2016. This internationally recognized standard for information security management systems demonstrates their commitment to maintaining robust security practices.
Financial Conduct Authority (FCA) Authorization: GoCardless Ltd is authorized by the UK Financial Conduct Authority under the Payment Services Regulations 2017 (registration number 597190) for the provision of payment services.
GDPR Compliance: GoCardless operates a formal, GDPR-compliant data retention and deletion program. This includes documented standards for data retention and deletion, ensuring compliance with the European Union's General Data Protection Regulation.