Does Fitstop require franchisees to comply with PCI industry and government requirements?
Fitstop Franchise · 2024 FDDAnswer from 2024 FDD Document
Since you accept credit cards as a method of payment at your Franchise, you must comply with payment card infrastructure ("PCI") industry and government requirements. PCI security standards are technical and operational requirements designed to protect cardholder data. The standards apply to all organizations that store, process or transmit cardholder data and cover technical and operational payment system components involving cardholder data. Notwithstanding the credit card processing requirement, we do not represent, nor certify to you or your customers that the credit card processing service approved or provided by us or our affiliate is compliant, whether or not certified, with the PCI Data Security Standards.
Source: Item 8 — RESTRICTIONS ON SOURCES OF PRODUCTS AND SERVICES (FDD pages 19–23)
What This Means (2024 FDD)
According to Fitstop's 2024 Franchise Disclosure Document, franchisees are required to comply with payment card industry (PCI) and government requirements because they accept credit cards as a method of payment at their franchise. PCI security standards are in place to protect cardholder data and apply to all organizations that store, process, or transmit this data. These standards cover the technical and operational components of payment systems that involve cardholder data.
Even though Fitstop requires compliance with PCI standards, the FDD states that Fitstop does not represent or certify that the credit card processing service they approve or provide is compliant with PCI Data Security Standards. This means that while Fitstop mandates the use of credit card processing, it does not guarantee the security or compliance of those services.
For a prospective Fitstop franchisee, this means they must ensure their credit card processing systems and practices meet all PCI requirements. This includes understanding and implementing the necessary technical and operational security measures to protect cardholder data. Given that Fitstop does not certify the compliance of its approved services, franchisees should independently verify that their systems are secure and compliant with all applicable standards. This may involve hiring a qualified security assessor to conduct regular audits and ensure ongoing compliance.