site banner

Small-Scale Question Sunday for November 9, 2025

Do you have a dumb question that you're kind of embarrassed to ask in the main thread? Is there something you're just not sure about?

This is your opportunity to ask questions. No question too simple or too silly.

Culture war topics are accepted, and proposals for a better intro post are appreciated.

1
Jump in the discussion.

No email address required.

When I receive these emails, I open up my computer and phone, load the PDF on my computer, scan the QR with my phone, load the site, copy the URL, email the URL to myself, then open it on my computer. Am I missing something essential about how this is supposed to work?

There are a tiny number of use cases where it makes some sense. If you're expecting students to receive e-mail through school accounts only accessible from (public) school computers, you don't want them putting private or especially financial information (b/c PCI DSS almost universally prohibits that) on those computers no matter how sure you've keylogger-proofed them, and you can't trust students to transfer even prettified URLs from one computer to another by mark I eyeball. Then your workflow, stupid as it seems, makes sense; the only trusted computer most people bring with them is the phone, and scanning a QR code in is the only viable way to pull the URL in.

In rarer cases, the school (or vendor) might be required to pretend that's the use case, either by regulation or internal norm, even if nobody does it.

Of course, if you were building such a system and not hilariously incompetent, PDFs support links, and you can just offer both. In many cases, the IT administration, or their leadership, is just incompetent. It's a funny joke, but it's not a joke.

But instead of using Square or something that charges 3% or so, they use a payment processor I've never heard of before that charges $1 per transaction, mostly for transactions of $5 - $10. Is it providing a real service of protecting the schools from liability somehow?

Most vendors have a minimum flat fee; the difference for a 10 USD transaction would be closer to 0.4 USD at current fees. Sometimes this can have better processing, or review standards on chargebacks, or have given them a good enough deal on payment processing systems or security reviews that it's worth the slightly higher fee, especially if the school uses the same system for large transactions for non-physical goods or for some (overtly) credit-like system, which can get messy from the lowest-overhead-common-denominator. PoS systems in particular can be very expensive (>1k USD/unit, usually need to be replaced every 2-5 years depending on use levels), which can be a massive hassle and expense for an organization that has to authorize individual purchases in a slow method but can get a contract with service requirements through at the same rate. This can even pop up if you aren't seeing those point of sale units: I've seen a volunteer org that only used a physical payment processing system once a month for sports game consumable sales have to do some very complex math to figure out what made economic sense.

But if they're charging you for the fees, it's as likely or more likely that they like the system because it lets them pass the charge onto purchasers explicitly, which ranges from disfavored to banned by terms of service to potentially illegal depending on payment processor and state (and even type of card). Officially, this can get into somewhat gray areas really quickly, but it's very rare for the rules to be enforced and a lot of actual accountants don't know the rules.

Interesting, thank you!

The colleagues I've spoken with and I are generally pretty hostile to any processes that require a phone (like two step authentication and emergency notifications), since they do not provide us with phones, and there are areas of the school that do not have reception. It's interesting that someone might think of their phone as more secure in some important sense. I have made transactions by phone, but it is an absolute last resort.

It does kind of make sense that the entire point is that the purchaser has to pay the fee, they are very explicit about that, and write on flyers things like Hot Dog: $6 ($5 to school, $1 to payment processor). I got a permit to visit a government park area, where the receipt said something like: $2.00 ($0 to for access to the area, $2.00 for the reservation system). The school seems pretty serious about never paying taxes on anything, it's possible that somehow this system, while much more expensive, is somehow easier for the Finance office than normal payment processors.

Normal surcharges, like when a restaurant announces on the menu an additional 4% for using a card makes more intuitive sense to me, because someone can avoid it by paying cash. Or sales taxes, since they can sometimes be avoided (though I'd much rather they were integrated into the price, as I've seen in Eastern Europe). It seems especially petty because there is no option to pay in cash for either the park pass or the school food.