Select one or more tags, then press “Search Plugins”

Find Plugin with any / all of the selected criteria
Search Plugin

Relqor — Gateway For Worldline Sips Wordpress Plugin - Rating, Reviews, Demo & Download

Relqor — Gateway For Worldline Sips Wordpress Plugin - Rating, Reviews, Demo & Download
No ratings yet
Free
Follow for free plugins, new theme releases and theme news

Plugin Description

Relqor redirects your customers to the hosted payment page of your bank, built on Worldline Sips 2.0 (Paypage POST connector):

  • Mercanet (BNP Paribas)
  • Sherlock’s (LCL)
  • Sogenactif (Société Générale)
  • Worldline Sips (generic)

Reliability first:

  • The order is marked as paid only by the signed automatic response (server to server), after the HMAC-SHA-256 seal, the merchant ID, the key version, the transaction reference and the amount have all been checked.
  • The customer return page never changes an order.
  • Idempotent processing, a lock per order, and never a step backwards (a late abandon never cancels a more recent payment attempt).
  • 3-D Secure v2 is handled by the bank’s payment page; the result is recorded in the order notes.
  • Classic checkout and WooCommerce checkout blocks, HPOS compatible.
  • Your secret key is never logged or sent to the browser, and never shown in full (only its last 4 characters, to recognise it).

Relqor is an independent plugin. It is not affiliated with Worldline, BNP Paribas, LCL or Société Générale. Sips, Mercanet, Sherlock’s and Sogenactif are trademarks of their respective owners.

External services

This plugin relies on the online card payment service of the bank you select in its settings. All four are built on the same Worldline Sips 2.0 platform, provided by Worldline to the banks. The service is required: without it no payment can be taken. Using it is governed by the contract you (the merchant) sign with your bank (or with Worldline for the generic Worldline Sips offer) and by your card acceptance contract; the plugin does not create any contract. The bank’s payment page, not your store, collects the card details; it also sees the customer’s IP address and browser, like any website.

When the service is used

  1. When the customer confirms the order, the plugin only records a payment attempt; nothing is sent yet.
  2. On the “Pay for order” page, the plugin builds a signed form and the customer’s browser posts it to the bank’s payment page (paymentInit). Your server makes no outgoing request to the bank. The first display uses the reference created with the order; each new display (refresh, back button) creates a new reference.
  3. After the payment, the bank’s server posts the signed result to your store (automatic response, ?wc-api=relqor_sips_notify). This is the only message that can change the order status.
  4. If the customer clicks “Continue” on the bank’s page, their browser posts the same signed result back to your store (?wc-api=relqor_sips_return); it only shows a message and never changes the order.

Data sent to the bank

Order amount (in cents) and currency (euro), order number, a payment reference (RQ<order>A<attempt>N<random>), your merchant ID and secret key version, the return and notification URLs of your store, the sales channel (INTERNET), the requested response encoding, the customer’s billing e-mail address (only if it is valid and at most 128 characters) and the store language (2-letter code, when supported by the payment page). The data is signed with HMAC-SHA-256; the secret key itself is never sent. The plugin does not send the customer’s name, postal address, phone number or IP address.

Data received and stored

From the signed response the plugin uses the response code, fraud score colour, reference, order number, amount, currency, merchant ID, key version, capture mode and, for the order note only, the authorisation number, card brand, 3-D Secure result, guarantee indicator and acquirer response code. The reference becomes the order’s transaction ID. The masked card number and card token are never stored. The WooCommerce log (source relqor-sips) records the IP address of the server that sent the automatic response.

Payment page addresses (test / production)

  • Worldline Sips: payment-webinit.simu.sips-services.com / payment-webinit.sips-services.com
  • Mercanet: payment-webinit-mercanet.test.sips-services.com / payment-webinit.mercanet.com
  • Sherlock’s: sherlocks-payment-webinit-simu.secure.lcl.fr / sherlocks-payment-webinit.secure.lcl.fr
  • Sogenactif: payment-webinit.simu.sogenactif.com / payment-webinit.sogenactif.com

Legal pages

Worldline Sips (Worldline, provider of the Sips platform used by all four banks):

  • Legal notice: https://worldline.com/en/compliancy/imprint
  • Terms of use of the Worldline website: https://worldline.com/en/compliancy/terms-of-use
  • Privacy notice: https://worldline.com/en/compliancy/privacy
  • Worldline’s role as data processor for Sips (section “RGPD”): https://docs.sips.worldline-solutions.com/en/WLSIPS.324-SIPS-Information-Systems-Security-2.0.html
  • Service terms: your Worldline Sips or bank contract.

Mercanet (BNP Paribas):

  • Legal notice: https://mabanquepro.bnpparibas/fr/banque-contacts-pro/engagement-chartes-et-conventions/mentions-legales
  • Mercanet offer (requires a card acceptance contract): https://mabanquepro.bnpparibas/fr/notre-offre-pro/comptes-cartes-et-services/solutions-d-encaissement/encaissement-internet-et-mobile/offre-e-commerce-mercanet
  • Personal data protection: https://banqueentreprise.bnpparibas/protectiondonnees (notice in English: https://secure.banqueentreprise.bnpparibas/en/footer/dataprotection.html)
  • Service terms: your Mercanet contract with BNP Paribas.

Sherlock’s (LCL):

  • Legal notice: https://www.lcl.fr/informations-legales
  • Sherlock’s offer (governed by the Sherlock’s membership contract and the “Vente à Distance Sécurisée” contract): https://www.lcl.fr/professionnel/solutions-encaissement-magasin-distance/sherlocks
  • Personal data protection: https://www.lcl.fr/politique-protection-des-donnees
  • Service terms: your Sherlock’s contract with LCL.

Sogenactif (Société Générale):

  • Legal notice: https://entreprises.sg.fr/mentions-legales
  • Sogenactif 2.0 general terms: https://entreprises.sg.fr/static/ent/Entreprises/Medias/PDF/Conditions-Generales/CG_Sogenactif2.0_25_juillet_2022.pdf
  • Personal data protection: https://entreprises.sg.fr/static/Entreprises/Medias/PDF/Politique_de_traitement_des_donnees_personnelles_.pdf
  • Service terms: the general terms above and your Sogenactif contract with Société Générale.

Screenshots

No screenshots provided


Reviews & Comments