PCI DSS Level 1 Certified

Take card payments over the phone without the PCI nightmare

Taking a card payment on a call sounds simple — until you realise the card number in your agent's ear is now in PCI DSS scope, along with your call recording, your CRM notes, and anywhere else it lands. We route the card capture through our PCI DSS Level 1 infrastructure so the number never reaches your agents or your systems at all. Same call, same customer, none of the scope. Works with your existing phone system and merchant account.

Taking card payments over the phone, honestly

Most UK businesses need to take a card payment over the phone at some point. A customer can't get to your website. They called to ask a question and decided to buy. You're chasing an overdue invoice. A donor wants to pledge on the spot. A patient needs to pay their excess. It's routine business — but the moment the card number leaves the customer's mouth and hits your ear, you've changed your compliance position.

PCI DSS treats any place card data touches as in scope. That includes your agent's headset, your telephony, your call recording, your CRM notes, and any paper the agent wrote on. An unprotected phone payment puts you in SAQ D — 329 controls, annual audits, mandatory training, documented evidence for every touchpoint. Most businesses taking a few phone payments a week shouldn't be running an SAQ D programme, and most don't realise they're meant to.

The fix isn't to stop taking phone payments. It's to stop the card data reaching you. That's what we do.

Three ways to take a card payment over the phone

Pick the one that fits the call. All three drop you to SAQ A.

What goes wrong when you do it the obvious way

The obvious way — customer reads the card number, agent types it into a payment terminal or CRM field — puts you in full PCI DSS scope. That's not a theoretical compliance issue. It means every call recording with a card number in it becomes a protected asset. It means the agent's desktop is in scope, so is the network it sits on, so is the building, so is every screen someone could glance at. It means your annual SAQ is 329 questions, not 22.

It also means the customer is reading a 16-digit card number, a 3-digit CVV, and an expiry date out loud — usually in an open-plan office, a café, a car, their front room with the kids around. That's uncomfortable for them and bad for your conversion rate. The most polite customers go quiet and ask to call back later; the less polite ones say no thank you and end the call.

Every workaround we've seen businesses build — pause-and-resume recording, post-call redaction, "secure" rooms, headset muting — solves one piece and leaves the others. It's cheaper, faster, and safer to not take the card data in the first place.

What changes when the card data bypasses you

Same call, same customer, same payment. Different compliance position.

AreaCard data reaches youCard data bypasses you
PCI SAQSAQ D — 329 controlsSAQ A — 22 controls
Call recordingIn scope, redact every callCard-data free, no changes
Agent workstationHardened desktop, locked buildStandard company laptop
Staff trainingAnnual mandatory PCI trainingNone required
Paper formsLocked, tracked, shreddedNot needed
Annual auditQSA-led, multi-dayIntegration evidence only
Breach exposureEvery recording is a riskNothing sensitive to lose

Who we built this for

If you take phone payments more than occasionally, you're probably on this list.

Small and mid-sized retailers

Phone orders alongside your website. Customer couldn't check out online, rang the number, wants to pay. Sorted in a minute.

B2B trade counters

Wholesale orders, deposits, pro-formas paid by phone. The sales team closes the call and the payment in the same conversation.

Professional services

Legal, accounting, consulting — invoices paid by phone after a service call. No more reading card numbers back to verify.

Healthcare and clinics

Co-pays, excess payments, treatment-plan instalments. Agent-assisted keeps the human in the loop through the payment.

Utilities and councils

High-volume routine bill payments. IVR handles the simple ones; agent-assisted handles the calls that need a person.

Charities and not-for-profits

Donor pledges, recurring gifts, subscription renewals. Donors don't read their card to a volunteer on a landline.

Frequently asked questions

Can I take card payments over the phone in the UK?

Yes. It's legal, it's common, and most UK businesses need to do it at some point. The card schemes call it MOTO (Mail Order / Telephone Order) and your acquirer — Barclaycard, Worldpay, Tyl by NatWest, Elavon, or others — can enable it on your merchant account, usually as a separate MID or as a tick-box on an existing one. What's changed in recent years is how you can do it without landing in full PCI DSS scope. The short answer is: don't let the card number reach your agents, your recording, or your systems in the first place.

Is it legal for me to write down a customer's card number?

Writing a card number on paper isn't illegal, but it puts you in breach of PCI DSS — the card schemes' security standard you agreed to when you signed up with your acquirer. A breach can mean fines, elevated fees, or termination of your merchant account. More practically, any paper with a card number on it immediately becomes a PCI-scope asset: it needs to be locked, tracked, shredded, and documented. The cost of doing it properly usually outweighs the cost of not writing it down at all. Use a compliant capture method and skip the paperwork.

Do call recordings count as storing card data?

Yes. If your call recording captures a customer reading their card number out loud, that recording is now in PCI scope. You have to treat it the same as any other place card data lives — encrypted, access-controlled, retention-limited, evidence-logged. Redacting it after the fact isn't straightforward and isn't always accepted by auditors. The cleaner answer is to stop card data reaching the recording in the first place, which is what DTMF masking does.

What's the difference between agent-assisted and IVR phone payments?

An agent-assisted phone payment keeps a human on the call while the customer keys their card. Useful when the call needs a conversation — sales, collections, support, complex orders. An IVR payment is fully automated: the customer calls a number, a recorded voice walks them through, no agent involved. Useful for high-volume routine payments where the customer just wants to pay a bill and move on. Most businesses end up using both: IVR for simple recurring payments, agent-assisted for anything that needs a person.

How much does it cost to take card payments over the phone?

Two costs. The first is your acquirer's transaction fee — MOTO interchange is roughly 0.1–0.3% higher than card-present because card-not-present fraud risk is higher. Your acquirer sets this, not us. The second is the technology for keeping you compliant — which is where we come in. We charge per transaction or per seat depending on volume. Both together are almost always cheaper than running your own PCI DSS SAQ D compliance programme, which is where you land if you take the card number directly.

What happens if a customer disputes a phone payment?

Card-not-present transactions carry full chargeback liability on you — there's no signature or PIN to show the issuer the customer authorised it. Dispute rates tend to be higher on phone payments than in-person. You can mitigate with 3DS2 where the customer can authenticate via their banking app, fraud screening, and clear call scripts that confirm the amount and reference. Our platform layers these in so you're not flying blind.

Do I need a special phone system?

No. Our platform works with traditional PBX, SIP trunks, cloud phone systems (3CX, Genesys, Five9, Amazon Connect, NICE CXone, 8x8, RingCentral, Talkdesk), and plain office handsets. We integrate at the API or SIP layer. Most deployments go live within a week — the telephony side barely changes, because we drop into what you already have.

Phone payments, without the scope and without the faff

Tell us what your calls look like and we'll show you the simplest way to take the payment without card data reaching you. Most customers go live within a week on the phone system they already own.

PCI DSS Level 1
Cyber Essentials Plus

Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia

Related solutions

Other ways to take payments in this channel.