

Verifone
By VeriFone, Inc
The typical implementation process for Verifone software:
Contract and Agreement: Merchant contacts Verifone, reviews product needs, and signs required agreements (including KYC and onboarding forms).
Site/Device Registration: Details such as business info, store locations, device counts, and hierarchy assignments are submitted; bulk site/device onboarding is available through Excel template uploads for large rollouts.
Role and User Setup: Merchant configures roles, permissions, and user accounts for management of payment systems and cloud dashboard access.
Software & Hardware Deployment: Devices are shipped or provisioned; software updates and integrations are managed remotely via Verifone’s cloud services. Self-service onboarding 24/7 is available for rapid activation.
Testing & Activation: Devices and integrations are registered, tested with payment flows, and activated using Verifone’s onboarding tools.
Verifone can be extensively customized to fit specific business needs, with support spanning hardware, software, branding, integration, payment types, device management, and analytics.
API-Driven Integrations: Verifone offers a RESTful API and branded SDKs, enabling developers to build custom payment flows, automate transactions, integrate with third-party systems, and centralize data across e-commerce, mobile, in-app, and in-person payments.
White-Label and Brand Customization: User interfaces, checkout flows, and billing experiences can be fully branded and personalized for customer-facing touchpoints, using templates and customizable modules, supporting internationalization and business logic extensions.
Device Application Flexibility: Businesses can configure, add, and update custom applications on Verifone terminals (e.g., loyalty programs, mobile wallets, multi-currency support, gift card systems, EBT, and customer-specific POS features) using proprietary file templates and packaging tools.
Role-Based Access & User Permissions: Enterprise customers can implement custom account hierarchies, device assignment logic, and granular user roles, adapting system governance to organizational requirements.
Connector and Plugin Options: One-click plugins and code snippets facilitate connecting Verifone’s gateway directly into existing web platforms, or as part of broader integrated commerce stacks for omnichannel businesses.
Marketplace and App Bundles: Verifone Marketplace provides curated merchant and consumer apps, including business productivity tools and custom-made bundles tailored for various verticals (retail, fuel, SMBs, healthcare, convenience).
Advanced Reporting & Analytics: Custom dashboards and BI tools allow merchants to build business-specific insights, transaction analysis, and workflow automations via Verifone’s cloud system or by exporting data through API endpoints.
Security and Compliance Customization: Integration with AI and fraud monitoring tools (e.g., via AI Agent connectors), PCI DSS compliance modules, and support for custom authentication (OAuth, enterprise SSO) can be tailored for strict regulatory environments.
Verifone provides a suite of training and support resources for new users, combining self-paced learning, live webinars, technical customer service, onboarding tools, and specialized documentation.
Self-Paced Online Tutorials: New users have access to online training modules, including video guides and interactive walkthroughs for device setup, payment acceptance, user creation, reporting, and troubleshooting.
Live Webinar Training: Scheduled webinars offer in-depth sessions on POS operations, management tools, and feature navigation, suited for both technical and non-technical staff.
Specialized Documentation: Industry-specific documents and checklists (e.g., petroleum and convenience store guides, POS management, cashier/manager training) are available for detailed site implementation and operational steps.
Self-Service Onboarding Portal: Merchants can activate devices, complete initial setup, and track orders using a 24/7 self-service portal, speeding up deployment and streamlining onboarding.
Technical Support: Access to global phone support (1-800-VERIFONE and regional numbers), email support, and helpdesk portals for urgent production issues and ongoing troubleshooting.
Role-Based Access & User Permissions: Admins can assign users, create onboarding roles, and delegate setup responsibilities to authorized staff or service contractors using Verifone’s management platforms.
On-Site Setup Support: For complex deployments, Verifone offers in-person configuration assistance and training by certified teams or authorized service contractors.
Verifone employs multiple layers of security measures to protect sensitive payment and user data, adhering to both global standards and advanced encryption protocols.
PCI DSS Level 1 Compliance: Verifone is audited annually for Payment Card Industry Data Security Standard (PCI DSS) Level 1, the highest possible certification for card processing security, and extends this protection to in-store, online, and cross-channel payments.
End-to-End Encryption (E2EE) and P2PE: All transaction data is encrypted the moment it is captured, using robust industry-approved point-to-point encryption (P2PE) protocols and validated solutions, ensuring cardholder data is safe throughout payment processing.
AES DUKPT Implementation: Verifone co-developed and implemented the AES DUKPT cryptographic key management standard, which delivers quantum-resistant encryption with unique keys per transaction—providing the highest level of protection against attack and enabling billions of secure transactions per device lifetime.
Hardware Security Standards (PCI PTS): Devices comply with PCI PIN Transaction Security (PTS), supporting secure reading, data exchange, cryptographic algorithms (AES, TDES, RSA, ECDSA, SHA), and secure key management protocols (DUKPT, Master Key/Session Key).
Tokenization: Verifone uses tokenization to replace sensitive card data with randomized tokens, minimizing risk during storage or processing in merchant environments.
Regular Audits and Security Updates: The company conducts ongoing internal and third-party audits, applies timely security patches, and enforces strict device and software management policies.
Fraud Prevention and Compliance Engine: Integrated AI-driven fraud management tools, compliance monitoring, and rule-based filtering reduce exposure to fraud risk and violations.
Privacy Policy and Data Minimization: Verifone’s privacy commitment includes GDPR adherence and minimizes retention of SMS consents, logs, and other data to limit exposure and support legal compliance.
Incident Response Protocols: The company has well-defined procedures for rapid detection and mitigation of potential breaches, including access restrictions, password updates, and full system reviews if events occur.
Verifone releases software and security updates regularly, with critical fixes and feature enhancements managed centrally and remotely through automated systems.
Updates typically include bug fixes, security patches, legal/compliance changes, and new functionalities, and are released several times per year for core products.
Devices check for updates at scheduled intervals (often every few hours for configuration changes or overnight for firmware/software upgrades).
Critical or mandatory updates (especially those affecting compliance or security) may be pushed immediately to all customers.
Remote Software Download (VRSD): Most updates are managed remotely via Verifone’s cloud infrastructure, allowing automated, unattended distribution to POS terminals, controllers, and PIN pads.
Centralized Device Management: Merchants and IT teams use Verifone’s Device Management platform to monitor update status, schedule rollouts, manage app/library versions, and apply parameter/configuration changes across estates.
Manual Update Option: For specialized deployments, admins can trigger software/firmware updates directly from device management menus or POS screens.
Rollback & Logging: System logs track update activity, and configuration backups allow restoration in case of problems during an upgrade.
Verifone’s policy on data ownership and portability is shaped by strong compliance with global privacy standards (like GDPR), giving customers significant control as data controllers, while Verifone acts as a processor or platform provider for merchant-collected data.
Merchants (business customers) are generally recognized as the data controllers for all business-generated and customer-related personal data processed through Verifone’s systems.
Verifone acts as the data processor, handling data exclusively on behalf of the merchant and under their instructions, especially for payment information, transaction histories, and business operations.
Upon contract termination, each party must return the other’s confidential information; merchants retain ownership and responsibility for their transaction and customer data.
Verifone reserves right to process certain personal data (e.g., employee contact info, technical usage data) as data controller for operational, compliance, and fraud prevention purposes, and merchants are informed of these flows.
Merchants have the right to request copies of relevant personal and transaction data for themselves or for data subjects, in accordance with GDPR and applicable privacy laws.
Data portability is supported through export/import tools (including XML/CSV exports for product, payment, and customer records in portal platforms like 2Checkout).
According to standard terms, merchants are responsible for retrieving stored data before any service termination—Verifone does not guarantee data retrieval after service ends.
Data subjects have statutory rights (under GDPR and similar mandates) to access, rectify, erase, object to, restrict, and port their personal data upon request via dedicated support channels.
Verifone’s terms for scaling up or down are designed for flexibility, allowing businesses to rapidly adjust capacity, services, and device counts based on current organizational needs. These features are supported by scalable subscription models, dynamic pricing, contract modifications, and cloud-based management tools.
Services and device quantities can be added at any time using Verifone’s cloud portal, with onboarding and activation managed through a self-service dashboard.
Tiered and volume-based pricing ensures that costs adjust automatically based on the number of users, devices, transactions, or storage consumption—supporting seamless business growth without renegotiation.
Advanced cloud management allows provisioning of new locations, payment types, or business integrations rapidly by authorized admins.
Subscription upgrades start a new contract cycle according to the upgraded product's terms, with support for change management and renewal alignment.
Merchants can remove locations, deactivate devices, or scale down service tiers using centralized platform administration, freeing unused capacity or reducing recurring costs.
Downgrading or reducing active service tiers generally takes effect at the next billing cycle for subscription products; unused hardware may be returned or repurposed, depending on contract specifics.
Contract modifications and cancellations follow the terms for the relevant product or subscription; merchants keep control over what services and features are retained or dropped.
Unlimited or time-limited contracts let merchants specify the desired renewal/commitment period for each service tier, allowing focus on monthly, annual, or flexible billing.
Contract changes (upgrades, renewals, product switches) are made via the dashboard; changes to contract period affect only new purchases/subscriptions.
Verifone contract renewal and cancellation terms are structured to offer auto-renewals, advance notice requirements, and clear obligations for early termination, with certain fees or conditions depending on product and contract type.
Auto-Renewal: Most Verifone contracts (including merchant, service, and subscription agreements) renew automatically for set periods (usually 12 months) unless either party gives formal written notice in advance.
Notification Requirement: Parties wishing not to renew must notify the other (often 30–90 days before renewal date, typically 3 months for enterprise product/service agreements).
Term Options: Contracts can be “unlimited” (renewing perpetually on a monthly or yearly cycle) or “limited” to a specific number of periods/months; switching products may reset contract settings to match the new product/version.
Upgrades/Renewals: When upgrading to new products/services, a contract renewal or new period starts based on the new terms, overriding prior contract settings for the remainder cycles.
Merchant-Initiated Termination: Merchants may terminate by submitting written notice (typically 30–90 days for most services).
Early Cancellation Fees: If cancellation occurs before the minimum period or extension term expires, merchants may be responsible for paying a defined percentage of the remaining contract fees (e.g., 100% for remaining year, 62.5% for remainder of longer periods).
Subscription Products: Cancellation can be performed via Verifone’s portal, with cancellations typically processed either immediately or up to 28 days from request, depending on the subscription expiration date.
Notice Periods: Standard contracts require three months’ advance notice for early termination, with earlier cancellations subject to pro-rated or full period charges depending on timing.
Automatic Termination: Either party may terminate immediately for material breach (with a 30-day cure period), insolvency, force majeure events lasting over 90 days, or business cessation.
Post-Termination: After termination, merchants must cease use of Verifone services/software, retrieve stored data, and may need to certify the stoppage of software usage on devices.
Verifone software meets many industry-leading compliance standards to ensure security, privacy, and reliability for merchants and end users.
PCI DSS Level 1: Verifone is certified at the highest level of Payment Card Industry Data Security Standard (PCI DSS), covering encrypted cardholder data, secure transactions, and merchant/processor responsibilities.
PCI PTS v7: All Verifone hardware is being upgraded to the latest PCI PIN Transaction Security (PTS) version 7 by 2025, delivering advanced protection against physical, logical, and skimming attacks.
GDPR: Verifone’s privacy, data handling, and data subject rights processes align with the EU General Data Protection Regulation (GDPR), including the right to access, port, and erase personal data.
SSAE Accreditation: Verifone platforms and operations are certified for SSAE (Statement on Standards for Attestation Engagements), confirming controls around security, privacy, and data processing.
EMC, RF, SAR Regulatory Compliance: Devices comply with international standards such as EN (Europe), IEC, and IEEE for electromagnetic compatibility, wireless/RF emissions, power safety, and SAR (Specific Absorption Rate) for Wi-Fi/BT, RFID, GPS, and 2G/3G/4G radios.
Export Controls: Verifone mandates compliance with applicable national and international export control laws and financial sanctions regulations.