Future commerce, payments, and communications¶
Purpose¶
This document records how AndreaWeb can progress from a manually confirmed catalog into a professional commerce and communications platform without forcing payment automation into the MVP.
It is a direction document, not authorization to open financial accounts, publish personal contact details, accept money, change DNS, or deploy an integration. Provider availability, onboarding requirements, fees, tax treatment, and Colombian regulations must be checked again when implementation begins.
Stage 1 — MVP inquiry and manual payment¶
The initial storefront is a catalog and cart, but the final customer action is an inquiry rather than an online purchase.
Customer flow¶
- The customer adds products and variants to the Medusa-backed cart.
- The storefront creates a Spanish WhatsApp message containing:
- cart or inquiry reference;
- product and variant names;
- quantities;
- displayed unit prices and provisional subtotal;
- a reminder that availability, delivery, and final total require confirmation.
- An email inquiry is offered as a fallback.
- Andrea confirms actual stock, delivery or pickup arrangements, timing, and final amount with the customer.
- Andrea sends the approved Nequi or Bre-B payment instructions directly through the conversation.
- Andrea verifies receipt inside the official financial application. A screenshot or customer message is not proof of cleared funds.
- Andrea records the confirmed sale and adjusts inventory in Medusa before shipping or delivering the items manually.
- Andrea sends the customer the appropriate thank-you and fulfillment message.
Important inventory behavior¶
Opening WhatsApp or email must not create a paid order, decrement inventory, or reserve stock. Until we add a proper inquiry/reservation workflow, two customers may ask about the same last item. Andrea remains the authority who confirms availability and manually reconciles inventory.
A later Medusa customization can store an inquiry record, snapshot cart contents, and optionally place an expiring stock reservation. Reservation duration, cancellation, expiry, and conversion to an order must be defined before enabling this.
Nequi and Bre-B safety¶
- Prefer a business-facing Nequi identifier, Nequi Negocios QR, or a Bre-B commerce/alias key rather than publishing Andrea's document number or personal banking details.
- Keep the destination identifier in deployment configuration, not source code.
- Bre-B payments are initiated inside the customer's participating financial application using a key or QR. The Banco de la República warns that receiving a Bre-B payment does not require opening a link and that Bre-B does not send payment links by text message.
- Verify the recipient name and the settled transaction in the official application before fulfillment.
- Do not build a form that collects banking passwords, Nequi credentials, card data, or one-time codes.
Stage 2 — support or “tip jar”¶
Andrea may want a simple way for visitors to support her work without purchasing a product. This should remain separate from the product cart and order lifecycle.
Desired behavior¶
- A clearly optional
Apoyar el trabajo de Andrea/Support Andrea's workaction. - Prefer a payment-provider-hosted link so AndreaWeb never handles card data.
- Use either preset contribution amounts or provider-supported pay-what-you-want pricing.
- State what the payment represents. Do not call it a charitable donation or imply a tax deduction unless legal and tax advice establishes that status.
- Collect the minimum personal information needed.
- Return to
/gracias/apoyoor/en/thank-you/supportonly after a provider-confirmed success state. - Do not treat a browser redirect alone as proof of payment; use the provider's verified status or webhook where available.
Provider direction¶
Stripe Payment Links are conceptually suitable, but Stripe's current global availability list does not include Colombia for ordinary local business onboarding and payouts. Stripe therefore remains an option only if Andrea has an eligible supported business/account structure and a Colombian payout path that Stripe explicitly approves at that time.
Before custom development, evaluate whether Wompi, Mercado Pago Colombia, Nequi Negocios, or another locally supported provider offers an appropriate hosted payment link. A local hosted link may cover the support use case long before a full Medusa checkout integration is justified.
Stage 3 — automated storefront checkout¶
If product demand justifies it, replace or supplement the inquiry action with a real payment flow. The customer should still be able to choose WhatsApp when the product or delivery arrangement needs discussion.
Candidate providers¶
| Candidate | Why evaluate it | Important questions |
|---|---|---|
| Wompi Colombia | Official documentation supports cards, PSE, Nequi, Botón de Transferencia Bancolombia, DaviPlata, and other Colombian methods | Andrea's onboarding eligibility, settlement account, fees, refunds, webhook reliability, hosted checkout versus direct API, Medusa provider availability |
| Mercado Pago Colombia | Established regional provider with hosted and API checkout options | Colombian settlement, enabled payment methods for Andrea's account, fees, refunds/chargebacks, checkout localization, Medusa integration quality |
| Stripe | Strong developer experience, hosted links, and a mature Medusa payment provider | Colombia is not currently listed for ordinary local business support; confirm business eligibility and payout support before designing around it |
| Bre-B | Immediate interoperable Colombian transfers using keys or QR | Treat as a manual payment rail until Andrea's financial institution or an approved payment provider offers a merchant API with verifiable transaction status |
| Nequi Negocios | Familiar local customer experience, business QR, and payment-link possibilities | Determine whether the business product alone is sufficient or whether Wompi should provide the automated API and status lifecycle |
| PSE / Botón Bancolombia | Familiar bank-transfer options in Colombia | Prefer access through a supported gateway such as Wompi rather than building direct bank-specific handling without a compelling reason |
Wompi is the leading candidate for the first Colombian automated checkout evaluation, not a final selection. Its official documentation describes asynchronous transaction states; the application must verify the final status rather than interpreting the initial response as payment success.
Provider abstraction¶
Commerce code should depend on Medusa payment sessions and internal payment states rather than scatter provider-specific assumptions throughout the storefront.
If no maintained Medusa provider exists for the selected Colombian gateway, implement a narrowly scoped Medusa Payment Module provider with:
- server-side credentials only;
- signed webhook verification;
- idempotent event processing;
- explicit pending, authorized/approved, declined, cancelled/voided, refunded, and error states;
- safe retry and reconciliation commands;
- provider transaction identifiers stored with the payment;
- no storage of raw card, bank, Nequi, or authentication credentials;
- sandbox and contract tests before production enablement.
The thank-you page must distinguish among inquiry received, payment pending, and payment confirmed. Fulfillment and inventory decrement occur only through the reviewed Medusa order/payment workflow.
Selection criteria¶
Before choosing a provider, document and compare:
- eligibility for Andrea as an individual, independent professional, or registered business;
- settlement to her actual Colombian bank or deposit account;
- onboarding documents and expected approval time;
- transaction, withdrawal, refund, and chargeback fees;
- COP support and settlement timing;
- Nequi, PSE, Bre-B, Bancolombia, cards, and international-customer coverage;
- hosted payment links, embedded checkout, API, webhooks, and sandbox quality;
- refund, cancellation, dispute, and reconciliation tools;
- maintained Medusa integration or effort to build and own one;
- customer-support quality and operational status history;
- privacy, security, accounting, and DIAN invoicing implications;
- ability to support both product orders and voluntary support payments without confusing their accounting treatment.
Professional domain email¶
A domain email should be part of the professional launch even if commerce remains manual.
Recommended initial setup¶
- Primary mailbox:
andrea@andreazambrano.co - Public portfolio aliases:
architecture@andreazambrano.coand, if desired,arquitectura@andreazambrano.co - Store alias:
cementos@andreazambrano.co - Customer-service alias:
soporte@andreazambrano.coorsupport@andreazambrano.co - General bilingual alias if useful:
contacto@andreazambrano.co
Start with one real mailbox and route the role addresses to it as aliases. Separate mailboxes are useful only when another person or workflow needs independent access. This keeps cost and administration low while presenting stable professional addresses that can later be reassigned without changing the public site.
Email requirements¶
- Evaluate a reputable hosted email provider rather than operating a mail server on the OVH VPS.
- Preserve all existing Namecheap DNS records during setup.
- Configure and validate MX, SPF, DKIM, and DMARC records.
- Enable multifactor authentication and recovery methods owned by Andrea.
- Keep personal correspondence separate from automated application mail.
- If Medusa later sends order or inventory notifications, use a dedicated sender such as
notificaciones@andreazambrano.cothrough a transactional email provider with its own scoped credentials. - Publish only addresses Andrea approves and add basic anti-spam handling.
WhatsApp Business¶
Andrea should evaluate the WhatsApp Business app before the site begins attracting public inquiries.
Initial business-app use¶
- Use a dedicated business number if practical, preserving her personal number and boundaries.
- Complete the business name, description, hours, location/service area, website, and professional email.
- Configure greeting, away, and quick-reply messages in Colombian Spanish.
- Use labels for stages such as
Nueva consulta,Disponibilidad confirmada,Pendiente de pago,Pagado,En preparación,Entregado, andCerrado. - Consider its catalog as a conversational convenience, while Medusa remains the authoritative catalog and inventory source.
- Keep the site's WhatsApp number in server-only environment data. The storefront BFF should redirect a validated cart inquiry without embedding the number in page HTML or browser bundles. This reduces passive crawling but does not make a customer-facing destination secret, so a dedicated business number remains the recommended boundary.
Later platform integration¶
If message volume outgrows the manually operated app, evaluate the WhatsApp Business Platform for templates, shared access, and programmatic status messages. This introduces Meta business verification, template rules, consent requirements, cost, webhook security, and customer-support workflows, so it is not part of the MVP.
Never send unsolicited marketing messages or upload customer contacts without an approved consent and privacy process.
Suggested implementation sequence¶
- Launch inquiry-only cart with WhatsApp and email fallback.
- Establish Andrea's business-facing Nequi/Bre-B receiving identifier and a documented manual reconciliation checklist.
- Create the domain mailbox and role aliases with authenticated email DNS.
- Move public inquiries to WhatsApp Business and configure labels/quick replies.
- Add a hosted support-payment link if an eligible Colombian provider meets the requirements.
- Compare Wompi and Mercado Pago using real onboarding, fees, sandbox, settlement, and refund information.
- Build a Medusa payment provider only after selecting the gateway and defining order, payment, inventory, refund, and fulfillment state transitions.
- Run sandbox and limited production tests before offering automated checkout broadly.
Decisions to make later¶
- Andrea's legal/account type for receiving commercial payments and issuing any required invoices.
- Public business name for cement products.
- Approved WhatsApp Business number and whether it is separate from her personal number.
- Approved Nequi/Bre-B receiving mechanism and what information may be published.
- Domain email provider, primary mailbox, aliases, and recovery ownership.
- Whether support payments are enabled and how they are described/accounted for.
- Whether Wompi or Mercado Pago can onboard Andrea and settle to her preferred account.
- Whether automated checkout replaces WhatsApp or remains an additional option.
Primary references¶
- Stripe global availability
- Wompi Colombia payment methods
- Wompi payment-source security guidance
- Mercado Pago Colombia Checkout API
- Banco de la República: Bre-B
- Banco de la República: Bre-B frequently asked questions
- Nequi Negocios QR
- WhatsApp Business