Great Lakes Council, BSA Home

Join Scouts

Credit Card Security & Privacy Statements

Credit Card Security Privacy Statement

Credit cards processed while on the Great Lakes Council website are processed by Doubleknot. Doubleknot's data security standards are adopted from the Payment Card Industry Data Security Standard (PCI DSS).  PCI DSS is a worldwide information security standard defined by the Payment Card Industry Security Standards Council. The Payment Card Industry Security Standards Council is an organization whose members include American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. Inc. International.  The standard is for organizations that process payments to prevent fraud through increased controls around data and its exposure to compromise.  While PCI DSS is not law, Doubleknot is required to maintain PCI DSS Level 3 compliance to process payment transactions.  Doubleknot maintains PCI DSS Level 3 compliance for all payment transactions and all personally identifiable data.

Validation of Doubleknot's compliance is performed by Security Metrics, Inc. and compliance is assessed quarterly.  The validation of compliance covers the following twelve topics of data security and within each topic there are number of requirements that must be met.  Failure to meet any single requirement results in non-compliance.

  1. Maintain a firewall configuration to protect data
  2. Do not use vendor-supplied defaults for system passwords and other security parameters
  3. Protect stored personally identifiable and payment data
  4. Encrypt transmission of personally identifiable and payment data across open, public networks
  5. Use and regularly update anti-virus software
  6. Develop and maintain secure systems and applications
  7. Restrict access to personally identifiable and payment data by business need-to-know
  8. Assign a unique ID to each person with computer access
  9. Restrict physical access to personally identifiable and payment data
  10. Track and monitor all access to network resources, personally identifiable data and payment data
  11. Regularly test security systems and processes
  12. Maintain a policy that addresses information security

Enforcement of compliance is done by the entities facilitating our payment transactions. Thus compliance is enforced by the card brands we accept, Visa, MasterCard, Discover and American Express, and our acquirers, PayPal, Inc. and Authorize.net, Inc.  Meaning, if Doubleknot becomes non-compliant one or more of the card brands we accept or our acquirers can stop our ability to process payments, increase our audit requirements and/or assess a fine of up to $500,000.

Doubleknot has maintained PCI DSS compliance since 2006.

Great Lakes Council, Inc., Boy Scouts of America (GLCBSA) Privacy Policy describes the type of information that is collected and how it used when a customer registers or pays for items on our website.

What our Privacy Policy Covers
This Privacy Policy covers GLCBSA treatment of personal information such as, but not limited to, your name, address, telephone numbers and email address that GLCBSA collects when you are on our web site and when you use our services.

This policy does not apply to the practices of companies, such as software publishers, that GLCBSA does not own or control or to people that GLCBSA does not employ.

This web site may contain links or references to other web sites outside of our control. Please be aware that GLCBSA has no control over these sites and our Privacy Policy does not apply to these sites.

Collecting Information
When you process a payment through our web site, we will ask for your credit card details. We securely pass that information on to a payment processor to handle the authorization and charging of your order total to this account. See “Credit Card Security” link also on our web site.

Using and Sharing the Information
We collect information and do not share your personal information with, or sell or rent it to any other party. In the unlikely event that your information is requested through a subpoena, we would be obliged to share only the information requested.

Changes to this Privacy Policy
GLCBSA may, at its discretion, amend this policy from time to time. If we make substantial changes in the way we use your personal information we will notify you by posting a prominent announcement on our pages.