Send a payment link instead of taking the number verbally. If you must take it by phone, enter it directly into a terminal or portal and never write it down, store it, or repeat it in an email.

What usually happens

A customer agrees on the phone and offers to pay a deposit. There is no card machine to hand, so the number gets written on whatever is nearest.

Later it is typed into a terminal or a portal, and the note is thrown away, or put in a drawer, or left on the desk.

Everybody involved understands this is not ideal. It happens because the alternative was not set up in advance and the customer is on the phone now.

Why it is riskier than it feels

A written card number is a complete set of credentials, usually with the expiry and security code beside it, in a place with no protection at all.

It can be photographed, copied, or simply taken. A notepad by a phone in a workshop is accessible to anybody who walks past.

And the obligations that apply to handling card data apply to you the moment you write one down, in a way that no small business is equipped for.

The exposure is not theoretical. It is a straightforward opportunity that exists for as long as the note does.

The better arrangement

A payment link, sent while the customer is still on the phone.

Most payment providers generate one in a few clicks: an amount, a reference, and a link you send by text or email. The customer pays on their own device, on the provider's page, and you see it arrive.

No number is spoken, written or stored. The evidence trail is better than a handwritten note, and the customer gets a receipt automatically.

It takes about the same time as writing the number down, once it is set up. The setting up is the part that has to happen before you need it.

A worked example

A repair business that had taken phone payments on a notepad for years, with numbers transcribed into a terminal at the end of each day.

The notes were shredded, mostly, and occasionally sat overnight.

Their payment provider's annual questionnaire asked whether card data was ever written down. Answering honestly changed which self-assessment applied to them and brought requirements they could not meet.

The fix took twenty minutes: enabling payment links in an account they already had, and a rule that nobody writes a number down for any reason.

The unexpected benefit was speed. Deposits now arrived while the customer was still on the phone rather than being processed that evening, and a proportion of the ones that used to fall through no longer did.

If you must take it verbally

Sometimes a customer cannot use a link, and there is a right way to handle it.

  1. Type it directly into the terminal or portal as they read it.
  2. Never write it on anything, including as a temporary note.
  3. Do not repeat the number aloud in a room with other people.
  4. Do not record the call, or pause the recording if you do.
  5. Do not accept it by email or text, and delete it if somebody sends it.
  6. Keep only the last four digits if you need a reference at all.

The fourth catches businesses using call recording for training or quality, which captures card details permanently unless it is paused.

The counter-case

Where a link is impractical.

An elderly or less confident customer who is uncomfortable with a link and would rather read the number to a person. Refusing costs you the deposit and the relationship.

A customer with no smartphone and no email, which is a smaller group than it used to be and not zero.

And a situation where the payment must happen immediately and the link is not being opened.

In all of those, the verbal method with the rules above is acceptable. What is not acceptable is writing it down, which is a separate decision from taking it verbally.

Stored cards for repeat customers

A related question that arises for anybody with regular clients.

Storing a card yourself, in any form, is the arrangement to avoid. Your payment provider can store it against a customer record and give you a token, which is what you use for subsequent charges.

You can then take a payment without ever seeing the number, and the customer's card is held by a company equipped to hold it.

What that requires is the customer's agreement, recorded, saying what you may charge and when. A stored card used without clear permission produces disputes.

What to do about the ones already in a drawer

Worth handling rather than ignoring.

Old job sheets, notebooks and files frequently contain card numbers written down years ago and forgotten.

Find them and destroy them. Shredding is sufficient; putting them in a bin is not.

Check email as well, both sent and received, because customers do send card details by email and those messages sit indefinitely in a system that was never meant to hold them.

Searching for a few common patterns turns up more than most businesses expect.

Refunds and the same problem

The mirror image, and it catches businesses that have solved the payment side.

Refunding somebody who paid by card should go back to the same card, through the same system, without anybody handling a number.

Where a business has taken a payment properly but then refunds by asking for bank details over the phone, or by cheque, the arrangement has become more complicated than it needed to be.

Refund through the original transaction wherever possible. It is faster for the customer, it costs less in fees on most providers, and it leaves a clean record linking the refund to the sale.

The exception is a payment taken in cash or by transfer, where there is no original transaction to reverse and a bank transfer is the sensible route.

Telling customers how you take payment

Worth stating on the quote, because it prevents the situation arising.

One line saying deposits are taken by a secure link sent by text or email sets the expectation before the phone call.

Customers who know what to expect have their phone to hand, and the number never comes up.

The related principle about card data never touching your own systems is covered in taking payment without handling card details.


Frequently asked questions

What usually happens?

A customer offers to pay on the phone, there is no machine to hand, and the number gets written on whatever is nearest and processed later.

Why is that riskier than it feels?

A written number is a complete set of credentials with no protection, accessible to anybody who walks past, and it brings obligations no small business is equipped for.

What is the better arrangement?

A payment link sent while they are still on the phone. No number spoken or written, a better evidence trail, and an automatic receipt for the customer.

What if I must take it verbally?

Type it directly into the terminal as they read it, never write it down even temporarily, do not repeat it aloud, and pause any call recording.

Can I store a card for a repeat customer?

Not yourself. Your provider can store it and give you a token, so you can charge without seeing the number. That needs the customer's recorded agreement.

What about numbers already written down?

Find and shred them, including in old job sheets and notebooks, and search your email, because customers do send card details that way.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Card numbers on a notepad by the phone?

A payment link takes the same time and removes the whole exposure, once it is set up.

Start a Conversation