Payment Link

Payment Link · LPO excursions

Four process maps to refine six stories against

These maps turn the six Payment Link stories in GVI\PI 2026\4.0 into pictures a developer can argue with. They carry only what the stories, the 31 August communication flow and the 7 September decisions already say. Anything marked TBC is an open question for refinement, not a decision that has been taken.

The six stories

The maps

Map 1

What the excursion payment does today

The confirmed baseline and the three gaps 242188 has to close.

Map 2

Send a link, take the payment, show the status

The European-market path end to end, across eight systems.

Map 3

How payment status and token state move

Five existing payment statuses, and the token shape being recommended.

Map 4

What happens when the link fails

Resend, dead link, declined card, unpaid at end of tour.

Systems in the flow

SystemRoleWhere that comes from
TD Portal (TDP)TD/CrD sells the excursion, sends the link, sees statusStated in the stories
EnterpriseClient record; source of the lead-guest emailConfirmed in refinement, 2026-09-20
Backend / Order Processing ServicesOrder, order items, payment records (EOPTIONAL_ORDER_PAYMENT), token store, audit logStated in 242191
Payment ServiceReceives the TrustPayments result, updates payment recordsConfirmed in refinement, 2026-09-20
CDE-PaymentUIPCI-scope card entry; new unauthenticated landing pageStated in 240003
TrustPaymentsCard processorStated in 240003
Email servicePayment-link email, bounce signal, receipt (sender TBC)Sender TBC

Legend

Colour repeats the shape, so the maps read in greyscale and in print. A dashed box is an unknown; a dashed edge is an exception or a loop back.

Questions for refinement

Every numbered marker on a map points here.

#QuestionStoryOwner
Q1Token expiry rule and anchor: duration, departure date or end of tour242191Scott Sarris
Q2PCI and GDPR constraints on token content, storage, retention and audit log242191Scott Sarris
Q3Address verification on the landing page: required or not240003Scott Sarris
Q4Which system sends the GFOB receipt after TrustPayments confirms240003, separate storyTBC
Q5Where payment status and Resend live in TDP240009, 240008Product
Q6Whether a new payment status is needed, or link state lives on the token242191Dev
Q7Result path TrustPayments to Payment Service: callback contract, retries, idempotency242191Dev
Q8Which email service sends the link, and how bounces are received240005, 240008Dev
Q9Order creation before the market check: confirm the non-EU path is unaffected240005Dev
Q10Finance per-departure payment report: scope242191Finance
Q11Current-state research items 1 to 6 on Map 1242188Dev