When customers buy something from your store, they share their private dataÌý— name, email, credit card detailsÌý— with you. AsÌýaÌýmerchant, you want toÌýkeep this vulnerable data secure from hackers, scammers, andÌýdata thieves.ÌýThat isÌýcrucial forÌýbuilding trust with your audience.
You can andÌýshould protect your customer data andÌýincrease theÌýtrust inÌýyour business withÌýHTTPS protocol andÌýanÌýSSL certificate.ÌýNot only can those tools improve security andÌýincrease your trustworthiness, they can also help your store rank better inÌýsearch engines.
±õ´ÚÌý²â´Ç³Ü sell online with 51ÊÓÆµ, you’ll beÌýpleased toÌýknow that your customer data isÌýalready protected. Yet, using anÌýSSL certificate can have aÌýfew additional benefits.
InÌýthis post, we’ll show you how theÌýHTTPS protocol andÌýSSL certificates work, andÌýhow you can get them forÌýyour website.
Understanding SSL Certificates andÌýtheÌýHTTPS Protocol
OnÌýtheÌýinternet, all data isÌýtransferred from device toÌýdevice according toÌýcertain rules orÌýprotocols.
For websites, this protocol isÌýcalled HyperText Transfer Protocol (HTTP). ItÌýtransfers theÌýdata that your customers enter onÌýyour website toÌýtheÌýserver that hosts your website, andÌýthen itÌýhelps toÌýsend theÌýresponse toÌýtheÌýbrowser. For example, theÌýuser presses aÌýbutton andÌýaÌýnew page opens, orÌýthey fill inÌýtheÌýemail registration form andÌýsee theÌýconfirmation ofÌýaÌýsuccessful registration.
The problem with HTTP isÌýthat itÌýdoesn’t protect anyÌýdata that’s transferred from browsers toÌýservers. Any data going through HTTP isÌýessentially “naked”.
AÌýgood analogy isÌýtoÌýthink ofÌýtwo students passing notes across aÌýclassroom. Any ofÌýtheir classmates can read, copy, orÌýeven replace theÌýnote. It’s theÌýsame with your customer data: aÌývillain can steal credit card details andÌýmoney from it.
That’s why aÌýnew protocol was created forÌýprotecting data: HTTPS (HyperText Transfer Protocol Secure). With HTTPS, all data transfers between aÌýuser andÌýaÌýweb server are encrypted. This encryption isÌýsoÌýcomplex that itÌýisÌýnearly impossible toÌýhack andÌýuse theÌýdata.
InÌýorder toÌýuse theÌýHTTPS protocol, your site first needs anÌýSSL (Secure Socket Layer) certificate.
AnÌýSSL certificate isÌýessentially aÌýkey forÌýencrypting data. ItÌýprotects data onÌýthree levels:
- Data encryption.ÌýHackers won’t beÌýable toÌýsee what information aÌýuser entered onÌýtheÌýsiteÌýor toÌýtrack user actions onÌýaÌýpage. Think ofÌýitÌýasÌýaÌýnote written with aÌýcipherÌý—Ìýit can only beÌýread byÌýsomeone who knows theÌýkey.
- Data integrity.ÌýHackers can’t replace orÌýdistort theÌýtransmitted data. Further, without knowing theÌýkey, itÌýisÌýimpossible toÌýwrite, edit,Ìýor manipulate theÌýdata, just like inÌýaÌýciphered note situation.
- Authentication.ÌýSSL ensures that aÌýuser isÌýonÌýaÌýtrusted site ²¹²Ô»åÌý²Ô´Ç³Ù onÌýaÌýhacker’s page. IfÌýjust two participants know theÌýkey, they are sure toÌýknow from whom they received theÌýnote. AÌýstranger cannot pass their own note andÌýget theÌýinformation byÌýcheating.
You can see ifÌýaÌýsite isÌýprotected byÌýanÌýSSL certificate via theÌýHTTPS protocol inÌýtheÌýURL address. Most browsers indicate itÌývisually inÌýtheÌýform ofÌýaÌýlock icon:
SSL certificates are distributed byÌýspecial organizationsÌý— certification centers.
Who Should Use SSL (and Why)
SSL isÌýrequired forÌýsites where users were entering sensitive informationÌý—Ìýsuch asÌýcredit card details.
But often, online stores only protect registration andÌýcheckout pagesÌýwith SSL, because those are theÌýonly places whereÌýtheir customers share personal data. The rest ofÌýtheÌýwebsite often works onÌýtheÌýinsecure HTTP.
Today, HTTPS isÌýaÌýmust forÌýevery web page. There’s aÌýnumber ofÌýreasons forÌýit.
Browsers flag unprotected sites
Chrome andÌýFirefox, two ofÌýtheÌýmost popular browsers inÌýtheÌýworld, visually mark sites that don’t use SSL.
For now, only aÌýgray information icon isÌývisible. But inÌýtheÌýfuture, browsers theÌýsecurity indicator toÌýaÌýred triangle forÌýpages onÌýHTTP. Your customers are used toÌýseeing this asÌýaÌý“warning” indicator.
Consequently, not using SSL can make people afraid ofÌýbuying from your website.
Using SSL improves rankings
Back inÌý2014, Ìýthat itÌýwould consider using SSL asÌýaÌýranking signal. This meant that sitesÌýusingÌýSSL would get aÌýboost inÌýsearch engine traffic.
Payment service requirements
AÌýgrowing number ofÌýpayment services have HTTPS asÌýaÌýrequirement forÌýworking with them. For example,ÌýÌý·É´Ç°ù°ì²õ only with HTTPS.
ItÌýincreases trust
Concerns over payment securityÌýis one ofÌýtheÌýtop 10Ìýreasons forÌýshopping cart abandonment. When you add anÌýSSL certificate toÌýyour store, you visually communicate toÌýusers that their payment data are safe.
More trust, ofÌýcourse, equals more sales.
±õ´ÚÌý²â´Ç³Ü want your customers toÌýeasily find your store inÌýsearch engines andÌýtrust you more easily, don’t put off switching toÌýHTTPS.
How toÌýGet anÌýSSL Certificate andÌýSwitch toÌýHTTPS
ToÌýswitch toÌýHTTPS, you first need toÌýbuy andÌýinstall anÌýSSL certificate onÌýtheÌýwebsite. This process can beÌýeither simple orÌýmore complex forÌýsome stores, depending onÌýtheÌýkind ofÌýsite you have.
1.ÌýYou’re using anÌý51ÊÓÆµ Instant Site
Anyone who has registered with 51ÊÓÆµ gets aÌýwebsite with aÌý
You might know this asÌýtheÌý51ÊÓÆµ Instant Site.
±õ´ÚÌý²â´Ç³Ü use this site, then you already have anÌýSSL certificate byÌýdefault. AnÌýonline store onÌýanÌý51ÊÓÆµ Instant Site conforms toÌýtheÌýinternational standards forÌýsecure data transmission.
Try itÌýright nowÌý—Ìýhead over toÌýyour Instant Site andÌýlook closely atÌýtheÌýaddress bar inÌýtheÌýbrowser. You will see aÌýgreen lock icon with theÌýmessage “Secure” next toÌýtheÌýURL. Rest assured that your online store isÌýsecure.
DoÌýyou want toÌýlink your Instant Site toÌýyour custom domain (soÌýthat itÌýredirects toÌýmysite.com ²¹²Ô»åÌý²Ô´Ç³Ù mysite.ecwid.com)?
You get aÌýfree SSL certificate forÌýthis action asÌýwell. Just follow these steps:
- , then goÌýtoÌýSettings →ÌýInstant Site andÌýclick onÌýtheÌý“Change Address” button.
- Click onÌýtheÌý“Use your domain” field andÌýfollow ³Ù³ó±ðÌý¾±²Ô²õ³Ù°ù³Ü³¦³Ù¾±´Ç²Ô²õ that appear
on-screen.
2.ÌýYou’ve added 51ÊÓÆµ onÌýyour own website
You can set upÌýanÌý51ÊÓÆµ store onÌýany site andÌýbeÌýcool with customer data security. For example, this can beÌýaÌýWordPress blog, anÌýAdobe Muse website, orÌýyour own static HTML page.
InÌýcase you’ve taken this route, you don’t need toÌýworry about theÌýsafety ofÌýyour customers’ data atÌýall. Since theÌýdata isÌýtransferred via our highly protectedÌýservers, all theÌýdata isÌýkept andÌýprocessed onÌý51ÊÓÆµâ€™s own .
±õ´ÚÌý²â´Ç³Ü added 51ÊÓÆµ toÌýyour own website that doesn’t have anÌýSSLÌýcertificate, your customers will not see theÌýsecure “lock” icon anywhere except during checkout, which they might find frustrating.
Here are aÌýfew ways you can buy andÌýuse SSL certificates forÌýdifferent website builders:
Wix:ÌýYou can use anÌýSSL certificate forÌýfree with Wix. You’ll have toÌýfirst enable this certificate byÌýgoing into theÌýsettings, then .
Weebly:Ìýyou can .
Joomla, WordPress, Drupal:Ìýyou’ll need toÌýbuy anÌýSSL certificate from your domain registrar orÌýaÌýhosting provider andÌýinstall itÌýonÌýyour website using ³Ù³ó±ðÌý¾±²Ô²õ³Ù°ù³Ü³¦³Ù¾±´Ç²Ô²õ (you’ll probably need aÌýdeveloper):
Follow ³Ù³ó±ðÌý¾±²Ô²õ³Ù°ù³Ü³¦³Ù¾±´Ç²Ô²õ below toÌýlearn about theÌýdifferent types ofÌýSSL certificates andÌýwhere toÌýbuy them.
Types ofÌýSSL certificates
Essentially, there are 3Ìýtypes ofÌýcertificates. They differ inÌýspeed ofÌýissuance andÌýtheÌýextent ofÌýtheÌýseller’s inspections.
1.ÌýCertificates With Domain Validation (DV)
The simplest option. Once you buy aÌýDVÌýSSL certificate, you’ll get aÌýlink toÌýverify theÌýdomain ownership onÌýyour listed email address.
DVÌýisÌýissued almost instantly. ItÌýisÌýalso theÌýcheapestÌýoption,Ìýwith some sellers even offering itÌýforÌýfree.
2.ÌýCertificates With Organization Validation (OV)
ToÌýget anÌýOVÌýSSL certificate, you need toÌýconfirm theÌýexistence ofÌýyour corporation orÌýLLC, byÌýgiving theÌý
AnÌýOVÌýSSL certificate can take
3.ÌýCertificate With Extended Validation (EV)
AnÌýEVÌýcertificate can beÌýrecognized byÌýtheÌýname ofÌýtheÌýcompany onÌýaÌýgreen background near theÌýwebsite address. You might have seen them onÌýfinancial websites:
Before anÌýEVÌýSSL can beÌýissued, theÌýcertifying authority carries out aÌýthorough check. ItÌýcan take
This certificate isÌýbest suited forÌýbanks andÌýpayment systems.
DV, OV, EVÌý
AnÌýSSL certificate will cost around $50/year. Some providers sell more expensive variants, but you should avoid overspending. The basic data security offered remains theÌýsame, regardless ofÌýwhether you buy aÌý$50ÌýorÌýaÌý$150ÌýSSL.
Although some providers offer free SSL certificates, they are severely “watered down” variants withoutÌýany benefits. You should not buy theÌýfirst one you see.
SSL certificates are issued byÌý“trust centers”. Some ofÌýtheÌýmore popular trust centers are:
- Comodo
- Symantec
- Digicert
- Geotrust
You can buy certificates issued byÌýthese centers from domain registrars, hosting websites,Ìýand SSL resellers. InÌýaddition,Ìýthere are also free certificates.
Below, we’ll help you understand theÌýoptions better.
1.ÌýBuy anÌýSSL certificate from domain registrar orÌýhosting service
Most domain registrars andÌýhosting services sell SSL certificates asÌýwell. InÌýsome cases, theÌýregistrar might even issue aÌýfree certificate asÌýaÌýgift orÌýpurchase.
Buying from aÌýdomain registrar orÌýaÌýhosting service works great since itÌýmakes itÌýeasy toÌýswitch from HTTP toÌýHTTPS.
Here are some popular options:
Ìý– $57/yr per websiteÌý– free toÌý$49,9/yrÌý– starts from $9/yrÌý– $12,95/yr– free SSL when buying hosting
±õ´ÚÌý²â´Ç³Ür domain registrar orÌýweb host also offers SSL certificates, weÌýrecommend buying one from them, even ifÌýitÌýisÌýslightly more expensive. This will save you hours when itÌýcomes time toÌýinstall theÌýcertificate andÌýswitch toÌýHTTPS.
2.ÌýGet aÌýfree SSL certificate
±õ´ÚÌý²â´Ç³Ür web host/registrar does not sell SSL certificates orÌýifÌýyour budget isÌýlimited, you can opt forÌýaÌýfree certificate. Free certificates come inÌýonly one flavorÌý—ÌýDomain Validation (DV). ThatÌýis enough toÌýprotect theÌýdata.
WeÌýrecommend theÌýfollowing services:
Cloudflare
Ìýoffers free SSL certificates with upÌýtoÌý15Ìýyears ofÌýsubscription. Apart from data protection, itÌýhas other benefits like basic protection from DDoSÌýattacks andÌýtheÌýautomatic speedingÌýup ofÌýyour website.
There are disadvantages asÌýwell:
- ItÌý·É´Ç°ù°ì²õ only inÌýnew browsers. ±õ´ÚÌý²â´Ç³Ür customers use older browsersÌý(older than Internet Explorer 11, Firefox 2,ÌýOpera 8,ÌýGoogle Chrome v5.0.342.0, Safari 2.1, Mobile Safari forÌýiOS 4.0, Android 3.0Ìý(Honeycomb), Windows Phone 7), they won’t see “https”Ìýon your website.
- One general certificate protects several sites atÌýtheÌýsame time. Though, itÌýwill protect your website just like anÌýindividual one.
- Cloudflare will ask you toÌýuse their own server dataÌýand your website traffic will beÌýgoing through theÌýCloudflare servers,Ìýwhich may cause aÌýdecrease inÌýloading speed (though not necessarily).
These drawbacks are not critical,Ìýand inÌýgeneral, Cloudflare isÌýoptimal forÌýthose who are not ready toÌýspend money onÌýanÌýSSL certificate but want toÌýstart protecting their customer data. ±õ´ÚÌý²â´Ç³Ü choose between remaining onÌýHTTP orÌýgetting anÌýSSL certificate from Cloudflare, weÌýrecommend you toÌýchoose theÌýsecond option.
ToÌýget anÌýSSL certificate from Cloudflare, Ìýand follow .
Let’s Encrypt
This isÌýaÌýfree service without Cloudflare’s cons, but itÌýhas its own limitations.
Ìýoffers certificates forÌýthree months only, soÌýyou’ll have toÌýset upÌýautomatic renewal, which will require access toÌýyour website’s server settings (available onÌýÌýhostings like Amazon AWS, Linode, Digital Ocean). That means you’ll likely need aÌýsystem administrator.
There are two options forÌýgetting anÌýSSL certificate from Let’s Encrypt:
- Manually onÌýÌývia theÌý
Semi-automatically orÌýautomatically (depending onÌýyour online store’s server software) via .
3.ÌýBuy anÌýSSL certificate from aÌýreseller
±õ´ÚÌý²â´Ç³Ü don’t want toÌýspend time onÌýadjusting aÌýLet’s Encrypt certificate andÌýdon’t feel like using Cloudflare, you can buy anÌýSSL certificate from one ofÌýtheÌýresellers:
Choose anyÌýreseller you like, andÌýremember that there’s not much sense inÌýbuying theÌýmost expensive option since they will all protect your website just fine.
How toÌýNot Lose Traffic When You Switch toÌýHTTPS
When you switch from HTTP toÌýHTTPS, theÌýsite address changes forÌýsearch robots (from Ìý→Ìýhttps://yoursite.com). This can negatively affect your rankings inÌýsearch engines.
Read Ìýfor maintaining your ranking,Ìýand even making itÌýbetter. WeÌýstrongly recommend you read them toÌýavoid losing customers ifÌýyou install anÌýSSL certificate onÌýyour own. You can also ask theÌýsupport team ofÌýyour site builder ifÌýthese conditions were met with their HTTP →ÌýHTTPS migration.
***
Let’s sum upÌýour recommendations:
- ±õ´ÚÌý²â´Ç³Ü use 51ÊÓÆµ Instant Site, you’re fine: theÌýentire website isÌýonÌýHTTPS.
- For Wix andÌýWeebly websites, enable your SSL certificate inÌýsettings.
- ±õ´ÚÌý²â´Ç³Ü sell onÌýyour own website, check with your domain/hosting provider ifÌýyou have anÌýSSL certificate. IfÌýno, request forÌýit.
- ±õ´ÚÌý²â´Ç³Ür domain/hosting provider doesn’t sell SSL certificates, get aÌýfree one onÌýÌýCloudflare orÌýbuy itÌýfrom aÌýreseller.
Ìý
- Data Privacy inÌýEcommerce: Emerging Trends andÌýBest Practices forÌý2024
- The State ofÌýEcommerce Payment Security
- How toÌýUse HTTPS Protocol andÌýSSL Certificates toÌýProtect Your Online Store
- Ecommerce Fraud: How toÌýProtect Your Store From Online Shopping Scams
- How ToÌýProtect Your Online Store From Cyber Threats