Find where they have collected, destroy them, and change the process that produced them. Taking a number by any route you control puts you in a position you do not want.

Where they collect

Almost none of that was a decision. Customers volunteer card numbers by email and read them out on the phone, and somebody writes them down because the alternative in the moment is to be unhelpful.

Why this matters more than it feels

Not because anybody is likely to be inspected.

A card number sitting in an inbox is one compromised mailbox away from being taken, and mailboxes are compromised routinely.

A number in a job record is visible to everybody with access to that system, which is usually more people than anybody has thought about.

And the obligations attached to holding card data are considerably heavier than the obligations attached to never touching it, which is the reason the whole industry is arranged to keep you out of the flow.

The security code on the back is a separate matter entirely: it must not be retained after a transaction under any circumstances, and a form or note containing it is a problem regardless of everything else.

Find what you already have

The audit, which is uncomfortable and takes an afternoon.

Search your email for the obvious patterns, including messages you sent, since numbers are frequently forwarded internally.

Search your booking, job, or customer system for the same, looking particularly in free-text notes fields where nothing prevents it.

Go through paper: forms, order pads, and anything filed from before you took payment another way.

Check voicemail, shared drives, and any messaging application used with customers.

Businesses that do this reliably find more than they expected, in places nobody would have guessed.

Destroy them properly

Since deleting is not always deleting.

Paper goes through a shredder rather than a bin.

Email needs deleting from the folder and then from the deleted items, and note that a copy may exist in the sent folder of whoever forwarded it.

Records in a system may keep a revision history, so check whether editing a note actually removes the earlier version.

Backups will contain the data too, which you cannot easily purge, and the practical answer is to let those age out rather than to attempt surgery on them.

Note what you found and removed, which is useful if anybody ever asks and useful for checking the flow has actually stopped.

Change what produced them

Because an audit without a process change fills the same places again within a year.

The flow is almost always one of three: a form with a card field, a habit of taking numbers over the phone, or customers emailing them unprompted.

Replace the form field with a payment link, which most providers can generate per invoice.

Replace the phone habit with sending a link by message while the customer is on the call, which takes seconds and is now normal enough that customers expect it.

And where customers email numbers unprompted, reply asking them not to, delete it, and send a link instead.

Tell staff explicitly that they should not accept a card number by any route, since without that instruction they will keep being helpful.

A worked example

A business searched their systems after a supplier raised it and found card numbers in nineteen places: eleven emails, five notes in their booking system, two paper forms, and a voicemail.

Three of the emails included the security code, written on a form that had asked for it.

They destroyed everything found, removed the card fields from the paper form, and set up payment links from their existing provider.

Staff were told plainly not to write a number down and what to do instead, which was the part that made it stick.

A check six months later found two new instances, both from customers emailing unprompted, which is the residual case rather than a failure of the process.

The phone call problem

The hardest one, since a customer on the phone wanting to pay is a good problem to have.

The answer is a link sent while they are still on the line: by text or email, opened on their phone, completed while you wait.

That takes under a minute, works for almost everybody, and keeps the number entirely out of your hands.

Where a customer genuinely cannot use a link, some providers offer a telephone facility where the customer keys the number in without it being spoken to you.

Writing it on a pad and typing it into a terminal afterwards is the version to eliminate, since the pad is the problem.

Keep what you are allowed to keep

Since the aim is not to have no record of anything.

The last four digits, the card type, the amount, the date, and the provider's transaction reference are all fine and are what you actually need for a refund or a dispute.

The provider holds the rest and can act on it with the reference, which is the arrangement working as intended.

Where you offer repeat or subscription billing, the provider stores the card and gives you a token, which lets you charge again without ever holding the number.

Ask your provider how to do that if you are currently keeping details for repeat customers, since that is the most common reason businesses believe they have to.

The counter-case

This can be treated as more urgent than it is.

A business with two old paper forms in a filing cabinet has a small problem that takes ten minutes to resolve, not a crisis.

The obligations attached also vary considerably with how you take payment and how much, and a business using a hosted checkout has very little to worry about.

And where genuine volume or complexity is involved, this needs proper advice rather than a general article.

Search for what you have, destroy it, change the process, and tell staff what to do instead.

The afternoon

  1. Search email, including sent items.
  2. Search notes fields in every system.
  3. Go through paper and voicemail.
  4. Shred and delete properly.
  5. Remove card fields from forms.
  6. Set up payment links and use them on calls.
  7. Tell staff not to accept a number by any route.

Step seven is what makes the rest last, since the numbers arrive because somebody is trying to be helpful and will keep trying unless told what to do instead.

Setting payment up properly is covered in taking payment without handling card details.


Frequently asked questions

Where do card details accumulate?

Paper forms, emails from customers, notes in booking records, undeleted voicemail, a notebook by the phone, and photographs customers send. Almost none of it was a decision.

Why does it matter?

A number in an inbox is one compromised mailbox from being taken, and a number in a job record is visible to everybody with access to that system.

What about the security code?

It must not be retained after a transaction under any circumstances. A form or note containing it is a problem regardless of everything else.

How do I destroy them properly?

Shred paper, delete email from the folder and deleted items, check whether editing a note keeps a revision history, and let backups age out rather than attempting surgery.

What replaces taking numbers on the phone?

A payment link sent by text or email while the customer is still on the line, completed while you wait. It takes under a minute and keeps the number out of your hands.

What am I allowed to keep?

The last four digits, card type, amount, date, and the provider's transaction reference. That is what you need for a refund or dispute, and the provider holds the rest.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Numbers sitting in your inbox?

Search your sent items as well as your inbox. Forwarded internally is where most of them are.

Start a Conversation