51ÊÓÆµ

How to Use HTTPS Protocol and SSL Certificates to Protect Your Online Store

When customers buy something from your store, they share their private dataÌý— name, email, credit card detailsÌý— with you. AsÌýaÌýmerchant, you want toÌýkeep this vulnerable data secure from hackers, scammers, andÌýdata thieves.ÌýThat isÌýcrucial forÌýbuilding trust with your audience.

You can andÌýshould protect your customer data andÌýincrease theÌýtrust inÌýyour business withÌýHTTPS protocol andÌýanÌýSSL certificate.ÌýNot only can those tools improve security andÌýincrease your trustworthiness, they can also help your store rank better inÌýsearch engines.

±õ´ÚÌý²â´Ç³Ü sell online with 51ÊÓÆµ, you’ll beÌýpleased toÌýknow that your customer data isÌýalready protected. Yet, using anÌýSSL certificate can have aÌýfew additional benefits.

InÌýthis post, we’ll show you how theÌýHTTPS protocol andÌýSSL certificates work, andÌýhow you can get them forÌýyour website.

How toÌýsell online
Tips from e-commerce experts forÌýsmall business owners andÌýaspiring entrepreneurs.
Please enter aÌývalid email address

Understanding SSL Certificates andÌýtheÌýHTTPS Protocol

OnÌýtheÌýinternet, all data isÌýtransferred from device toÌýdevice according toÌýcertain rules orÌýprotocols.

For websites, this protocol isÌýcalled HyperText Transfer Protocol (HTTP). ItÌýtransfers theÌýdata that your customers enter onÌýyour website toÌýtheÌýserver that hosts your website, andÌýthen itÌýhelps toÌýsend theÌýresponse toÌýtheÌýbrowser. For example, theÌýuser presses aÌýbutton andÌýaÌýnew page opens, orÌýthey fill inÌýtheÌýemail registration form andÌýsee theÌýconfirmation ofÌýaÌýsuccessful registration.

The problem with HTTP isÌýthat itÌýdoesn’t protect anyÌýdata that’s transferred from browsers toÌýservers. Any data going through HTTP isÌýessentially “naked”.

AÌýgood analogy isÌýtoÌýthink ofÌýtwo students passing notes across aÌýclassroom. Any ofÌýtheir classmates can read, copy, orÌýeven replace theÌýnote. It’s theÌýsame with your customer data: aÌývillain can steal credit card details andÌýmoney from it.

That’s why aÌýnew protocol was created forÌýprotecting data: HTTPS (HyperText Transfer Protocol Secure). With HTTPS, all data transfers between aÌýuser andÌýaÌýweb server are encrypted. This encryption isÌýsoÌýcomplex that itÌýisÌýnearly impossible toÌýhack andÌýuse theÌýdata.

InÌýorder toÌýuse theÌýHTTPS protocol, your site first needs anÌýSSL (Secure Socket Layer) certificate.

AnÌýSSL certificate isÌýessentially aÌýkey forÌýencrypting data. ItÌýprotects data onÌýthree levels:

  1. Data encryption.ÌýHackers won’t beÌýable toÌýsee what information aÌýuser entered onÌýtheÌýsiteÌýor toÌýtrack user actions onÌýaÌýpage. Think ofÌýitÌýasÌýaÌýnote written with aÌýcipherÌý—Ìýit can only beÌýread byÌýsomeone who knows theÌýkey.
  2. Data integrity.ÌýHackers can’t replace orÌýdistort theÌýtransmitted data. Further, without knowing theÌýkey, itÌýisÌýimpossible toÌýwrite, edit,Ìýor manipulate theÌýdata, just like inÌýaÌýciphered note situation.
  3. Authentication.ÌýSSL ensures that aÌýuser isÌýonÌýaÌýtrusted site ²¹²Ô»åÌý²Ô´Ç³Ù onÌýaÌýhacker’s page. IfÌýjust two participants know theÌýkey, they are sure toÌýknow from whom they received theÌýnote. AÌýstranger cannot pass their own note andÌýget theÌýinformation byÌýcheating.

You can see ifÌýaÌýsite isÌýprotected byÌýanÌýSSL certificate via theÌýHTTPS protocol inÌýtheÌýURL address. Most browsers indicate itÌývisually inÌýtheÌýform ofÌýaÌýlock icon:

SSL certificates are distributed byÌýspecial organizationsÌý— certification centers.

Who Should Use SSL (and Why)

SSL isÌýrequired forÌýsites where users were entering sensitive informationÌý—Ìýsuch asÌýcredit card details. E-commerce stores that doÌýnot want toÌýlose their customers have been using theÌýHTTPS protocol forÌýaÌýwhile already.

But often, online stores only protect registration andÌýcheckout pagesÌýwith SSL, because those are theÌýonly places whereÌýtheir customers share personal data. The rest ofÌýtheÌýwebsite often works onÌýtheÌýinsecure HTTP.

Today, HTTPS isÌýaÌýmust forÌýevery web page. There’s aÌýnumber ofÌýreasons forÌýit.

Browsers flag unprotected sites

Chrome andÌýFirefox, two ofÌýtheÌýmost popular browsers inÌýtheÌýworld, visually mark sites that don’t use SSL.

For now, only aÌýgray information icon isÌývisible. But inÌýtheÌýfuture, browsers theÌýsecurity indicator toÌýaÌýred triangle forÌýpages onÌýHTTP. Your customers are used toÌýseeing this asÌýaÌý“warning” indicator.

Consequently, not using SSL can make people afraid ofÌýbuying from your website.

Using SSL improves rankings

Back inÌý2014, Ìýthat itÌýwould consider using SSL asÌýaÌýranking signal. This meant that sitesÌýusingÌýSSL would get aÌýboost inÌýsearch engine traffic.

Payment service requirements

AÌýgrowing number ofÌýpayment services have HTTPS asÌýaÌýrequirement forÌýworking with them. For example,ÌýÌý·É´Ç°ù°ì²õ only with HTTPS.

ItÌýincreases trust

Concerns over payment securityÌýis one ofÌýtheÌýtop 10Ìýreasons forÌýshopping cart abandonment. When you add anÌýSSL certificate toÌýyour store, you visually communicate toÌýusers that their payment data are safe.

More trust, ofÌýcourse, equals more sales.

±õ´ÚÌý²â´Ç³Ü want your customers toÌýeasily find your store inÌýsearch engines andÌýtrust you more easily, don’t put off switching toÌýHTTPS.

How toÌýGet anÌýSSL Certificate andÌýSwitch toÌýHTTPS

ToÌýswitch toÌýHTTPS, you first need toÌýbuy andÌýinstall anÌýSSL certificate onÌýtheÌýwebsite. This process can beÌýeither simple orÌýmore complex forÌýsome stores, depending onÌýtheÌýkind ofÌýsite you have.

1.ÌýYou’re using anÌý51ÊÓÆµ Instant Site

Anyone who has registered with 51ÊÓÆµ gets aÌýwebsite with aÌýbuilt-in online store.

You might know this asÌýtheÌý51ÊÓÆµ Instant Site.

±õ´ÚÌý²â´Ç³Ü use this site, then you already have anÌýSSL certificate byÌýdefault. AnÌýonline store onÌýanÌý51ÊÓÆµ Instant Site conforms toÌýtheÌýinternational standards forÌýsecure data transmission.

Try itÌýright nowÌý—Ìýhead over toÌýyour Instant Site andÌýlook closely atÌýtheÌýaddress bar inÌýtheÌýbrowser. You will see aÌýgreen lock icon with theÌýmessage “Secure” next toÌýtheÌýURL. Rest assured that your online store isÌýsecure.

DoÌýyou want toÌýlink your Instant Site toÌýyour custom domain (soÌýthat itÌýredirects toÌýmysite.com ²¹²Ô»åÌý²Ô´Ç³Ù mysite.ecwid.com)?

You get aÌýfree SSL certificate forÌýthis action asÌýwell. Just follow these steps:

  1. , then goÌýtoÌýSettings →ÌýInstant Site andÌýclick onÌýtheÌý“Change Address” button.
  2. Click onÌýtheÌý“Use your domain” field andÌýfollow ³Ù³ó±ðÌý¾±²Ô²õ³Ù°ù³Ü³¦³Ù¾±´Ç²Ô²õ that appear on-screen.

2.ÌýYou’ve added 51ÊÓÆµ onÌýyour own website

You can set upÌýanÌý51ÊÓÆµ store onÌýany site andÌýbeÌýcool with customer data security. For example, this can beÌýaÌýWordPress blog, anÌýAdobe Muse website, orÌýyour own static HTML page.

InÌýcase you’ve taken this route, you don’t need toÌýworry about theÌýsafety ofÌýyour customers’ data atÌýall. Since theÌýdata isÌýtransferred via our highly protectedÌýservers, all theÌýdata isÌýkept andÌýprocessed onÌý51ÊÓÆµâ€™s own .

±õ´ÚÌý²â´Ç³Ü added 51ÊÓÆµ toÌýyour own website that doesn’t have anÌýSSLÌýcertificate, your customers will not see theÌýsecure “lock” icon anywhere except during checkout, which they might find frustrating.

Here are aÌýfew ways you can buy andÌýuse SSL certificates forÌýdifferent website builders:

Wix:ÌýYou can use anÌýSSL certificate forÌýfree with Wix. You’ll have toÌýfirst enable this certificate byÌýgoing into theÌýsettings, then .

Weebly:Ìýyou can .

Joomla, WordPress, Drupal:Ìýyou’ll need toÌýbuy anÌýSSL certificate from your domain registrar orÌýaÌýhosting provider andÌýinstall itÌýonÌýyour website using ³Ù³ó±ðÌý¾±²Ô²õ³Ù°ù³Ü³¦³Ù¾±´Ç²Ô²õ (you’ll probably need aÌýdeveloper):

Self-built websites:Ìýbuy anÌýSSL certificate from your hosting provider/domain andÌýinstall itÌýyourselves orÌýwith theÌýhelp ofÌýyour ITÌýguy.

Follow ³Ù³ó±ðÌý¾±²Ô²õ³Ù°ù³Ü³¦³Ù¾±´Ç²Ô²õ below toÌýlearn about theÌýdifferent types ofÌýSSL certificates andÌýwhere toÌýbuy them.

Types ofÌýSSL certificates

Essentially, there are 3Ìýtypes ofÌýcertificates. They differ inÌýspeed ofÌýissuance andÌýtheÌýextent ofÌýtheÌýseller’s inspections.

1.ÌýCertificates With Domain Validation (DV)

The simplest option. Once you buy aÌýDVÌýSSL certificate, you’ll get aÌýlink toÌýverify theÌýdomain ownership onÌýyour listed email address.

DVÌýisÌýissued almost instantly. ItÌýisÌýalso theÌýcheapestÌýoption,Ìýwith some sellers even offering itÌýforÌýfree.

2.ÌýCertificates With Organization Validation (OV)

ToÌýget anÌýOVÌýSSL certificate, you need toÌýconfirm theÌýexistence ofÌýyour corporation orÌýLLC, byÌýgiving theÌýcertificate-issuing authority theÌýnecessary documents.

AnÌýOVÌýSSL certificate can take 1-3Ìýdays toÌýget. This certificate always needs toÌýbeÌýpaidÌýfor.

3.ÌýCertificate With Extended Validation (EV)

AnÌýEVÌýcertificate can beÌýrecognized byÌýtheÌýname ofÌýtheÌýcompany onÌýaÌýgreen background near theÌýwebsite address. You might have seen them onÌýfinancial websites:

Before anÌýEVÌýSSL can beÌýissued, theÌýcertifying authority carries out aÌýthorough check. ItÌýcan take 3-10Ìý»å²¹²â²õ,Ìý²¹²Ô»å even more,Ìýto get anÌýEVÌýcertificate.

This certificate isÌýbest suited forÌýbanks andÌýpayment systems.

DV, OV, EVÌý–Ìýr±ð²µ²¹°ù»å±ô±ð²õ²õ ofÌýwhat kind ofÌýSSL certificate you choose, understand that they all protect your data .ÌýThis isÌýwhy you can use theÌýcheapest optionÌý—ÌýaÌýbasic SSL with domain verificationÌý—Ìýwithout worrying about your security. You’ll need toÌýrenew your SSL certificate regularlyÌý— ifÌýtheÌýcertificate isÌýnot renewed next year, not only doÌýyou lose your protection, but theÌýsite might not even open forÌýmost users.

AnÌýSSL certificate will cost around $50/year. Some providers sell more expensive variants, but you should avoid overspending. The basic data security offered remains theÌýsame, regardless ofÌýwhether you buy aÌý$50ÌýorÌýaÌý$150ÌýSSL.

Although some providers offer free SSL certificates, they are severely “watered down” variants withoutÌýany benefits. You should not buy theÌýfirst one you see.

SSL certificates are issued byÌý“trust centers”. Some ofÌýtheÌýmore popular trust centers are:

You can buy certificates issued byÌýthese centers from domain registrars, hosting websites,Ìýand SSL resellers. InÌýaddition,Ìýthere are also free certificates.

Below, we’ll help you understand theÌýoptions better.

1.ÌýBuy anÌýSSL certificate from domain registrar orÌýhosting service

Most domain registrars andÌýhosting services sell SSL certificates asÌýwell. InÌýsome cases, theÌýregistrar might even issue aÌýfree certificate asÌýaÌýgift orÌýpurchase.

Buying from aÌýdomain registrar orÌýaÌýhosting service works great since itÌýmakes itÌýeasy toÌýswitch from HTTP toÌýHTTPS.

Here are some popular options:

±õ´ÚÌý²â´Ç³Ür domain registrar orÌýweb host also offers SSL certificates, weÌýrecommend buying one from them, even ifÌýitÌýisÌýslightly more expensive. This will save you hours when itÌýcomes time toÌýinstall theÌýcertificate andÌýswitch toÌýHTTPS.

2.ÌýGet aÌýfree SSL certificate

±õ´ÚÌý²â´Ç³Ür web host/registrar does not sell SSL certificates orÌýifÌýyour budget isÌýlimited, you can opt forÌýaÌýfree certificate. Free certificates come inÌýonly one flavorÌý—ÌýDomain Validation (DV). ThatÌýis enough toÌýprotect theÌýdata.

WeÌýrecommend theÌýfollowing services:

Cloudflare

Ìýoffers free SSL certificates with upÌýtoÌý15Ìýyears ofÌýsubscription. Apart from data protection, itÌýhas other benefits like basic protection from DDoSÌýattacks andÌýtheÌýautomatic speedingÌýup ofÌýyour website.

There are disadvantages asÌýwell:

These drawbacks are not critical,Ìýand inÌýgeneral, Cloudflare isÌýoptimal forÌýthose who are not ready toÌýspend money onÌýanÌýSSL certificate but want toÌýstart protecting their customer data. ±õ´ÚÌý²â´Ç³Ü choose between remaining onÌýHTTP orÌýgetting anÌýSSL certificate from Cloudflare, weÌýrecommend you toÌýchoose theÌýsecond option.

ToÌýget anÌýSSL certificate from Cloudflare, Ìýand follow .

Let’s Encrypt

This isÌýaÌýfree service without Cloudflare’s cons, but itÌýhas its own limitations.

Ìýoffers certificates forÌýthree months only, soÌýyou’ll have toÌýset upÌýautomatic renewal, which will require access toÌýyour website’s server settings (available onÌýÌýhostings like Amazon AWS, Linode, Digital Ocean). That means you’ll likely need aÌýsystem administrator.

There are two options forÌýgetting anÌýSSL certificate from Let’s Encrypt:

  1. Manually onÌýÌývia theÌý
  2. Semi-automatically orÌýautomatically (depending onÌýyour online store’s server software) via .

3.ÌýBuy anÌýSSL certificate from aÌýreseller

±õ´ÚÌý²â´Ç³Ü don’t want toÌýspend time onÌýadjusting aÌýLet’s Encrypt certificate andÌýdon’t feel like using Cloudflare, you can buy anÌýSSL certificate from one ofÌýtheÌýresellers:

Choose anyÌýreseller you like, andÌýremember that there’s not much sense inÌýbuying theÌýmost expensive option since they will all protect your website just fine.

How toÌýNot Lose Traffic When You Switch toÌýHTTPS

When you switch from HTTP toÌýHTTPS, theÌýsite address changes forÌýsearch robots (from Ìý→Ìýhttps://yoursite.com). This can negatively affect your rankings inÌýsearch engines.

Read Ìýfor maintaining your ranking,Ìýand even making itÌýbetter. WeÌýstrongly recommend you read them toÌýavoid losing customers ifÌýyou install anÌýSSL certificate onÌýyour own. You can also ask theÌýsupport team ofÌýyour site builder ifÌýthese conditions were met with their HTTP →ÌýHTTPS migration.

***

Let’s sum upÌýour recommendations:

Ìý

About The Author
Anna is a content creator at 51ÊÓÆµ. She loves big cities, pasta and Woody Allen's films.

Start selling on your website