Secure Virtual Terminal your agents can't leak from
How a payment runs
Four steps, none of them involving your agent and a card number.
Quick summary
A virtual terminal is a browser-based screen for card-not-present payments. It’s used for phone orders, mail orders, invoices and deposits. On an ordinary terminal, the agent keys the customer’s card number into the form. This puts the agent, their workstation, your network and call recordings in your cardholder data environment. That means SAQ D and around 329 controls. A secure virtual terminal uses the same process, but the customer enters the card number themselves on their phone. The tones are masked, so nothing card-related reaches your system or recordings. Result: SAQ A, 22 controls.
Last updated: 12 August 2026
What a virtual terminal actually is
A virtual terminal is a payment screen you log into in a browser. It’s a tool for businesses to take card payments when the customer isn’t physically present. This happens in a variety of situations — phone orders, mail orders, invoices paid over the phone, booking deposits, or final payments after a job is done.
You enter the amount, a reference for reconciliation, then the card number, expiry date and security code. The request is sent to a payment gateway, then to the acquirer, which approves or declines the transaction. It’s like a shop counter card machine, but without the need to swipe the card.
The appeal of a virtual terminal lies in its simplicity. You don’t need hardware, integration projects or developers. Just log in and start taking payments the same day. It’s especially useful for small businesses or sole traders who deal with a few payments a month.
Why the ordinary design maximises your PCI scope
The issue with standard virtual terminals lies in how card numbers are handled. When the agent hears the digits, they become part of the payment process and, by extension, part of your PCI scope. If an agent types the number on a networked desktop, that workstation and the network it connects to also fall under PCI requirements. This applies to call recordings too. If the card number is spoken into the call, the audio recording becomes a repository of sensitive data, which means the recording platform, storage systems, backups and disaster recovery copies are all in scope.
All of this must be documented, access-controlled, encrypted, logged, patched and audited. That’s what the Self-Assessment QuestionnaireD covers — 329 controls, the most extensive set in the PCI framework. There’s a shorter version, SAQ C-VT, but that requires a single dedicated machine used for nothing else. A contact centre agent using a shared desktop with a customer record system and a softphone doesn’t meet that requirement. The same goes for a home worker using a personal laptop. The agent is the biggest risk.
One dishonest hire can collect dozens of card numbers in a shift, and the theft often goes unnoticed until months later. Call recordings are another common problem. The system might have been in place before payments were introduced, managed by IT rather than compliance, and never audited. Under PCI DSS 4.0.1, an audible card number in a recording is classified as cardholder data. That means it has to be treated with the same care as any other sensitive financial information.
What ours does differently
With Paytia’s virtual terminal, the customer types their card number directly on their own phone keypad. The agent’s role is to open the payment screen, enter the amount, reference and any custom fields, then start the payment process. The customer is prompted to key in their details, and each keypress is captured as a Dual-Tone Multi-Frequency tone. Paytia intercepts these tonesbefore they reach the agent’s audio or the call recording, replacing them with a flat beep. The agent sees asterisks on screen as the customer types, but they never hear the number.
The transaction is processed from Paytia’s PCI DSS Level 1 environment directly to your existing acquirer. The result appears on the agent’s screen, but the agent was never in a position to write down, repeat or paste the card details. The call recording captures the conversation about the payment but contains no cardholder data. There’s nothing to redact, pause or explain to an auditor. The card is tokenised in the same transaction, so refunds, repeat charges or subscription renewals can be processed using the token.
The customer only needs to type their details once, and the token can safely be stored in a customer record because it has no value outside Paytia’s vault. The system runs in a browser, so it works on any desk machine, laptop or tablet. In person, a representative can hand over the tablet, and the customer types in their card themselves. Home workers get the same setup, with no card data reaching them either. SAQ A, with 22 controls.
What changes on your assessment
Same terminal workflow, same acquirer, same phone system. Very different evidence pack.

PCI DSS Level 1
The highest tier of PCI certification. The scope reduction happens the moment card data stops arriving at your systems — not when you sign the contract.
The difference isn't that we make PCI easier to evidence. It's that most of what you were evidencing stops being in scope. A recording system with no card data in it isn't a cardholder data environment. An agent desktop that never receives a PAN doesn't need the lockdown, the isolation, or the annual penetration test that one does.
| Area | Traditional terminal | With Paytia |
|---|---|---|
| Who keys the card | Your agent | The customer |
| Self-assessment | SAQ D (329 controls) | SAQ A (22 controls) |
| Call recordings | Hold audible card numbers | Card-data free |
| Agent workstation | In scope, full lockdown | Out of scope |
| Home workers | Scope follows them home | Nothing to contain |
| Annual audit | Full QSA assessment | Evidence of integration only |
Who's running one, and what usually goes wrong
Pinnacle Group, a UK facilities management business with a multi-site contact centre, is one organisation that has made the switch. They use virtual terminals to take card payments for housing association rent, social care contributions and local authority schemes. Before they adopted Paytia, agents typed in card numbers into a terminal while calls were recorded for quality and compliance. That meant the agent estate, call recordings and data handling systems were all in PCI scope. After switching, the capture moved to the customer’s own keypad.
The recordings now contain no card data, and the agent estate is out of scope. Their compliance burden dropped from SAQ D to SAQ A, and they removed about 95 per cent of their PCI scope. No one noticed the change, but the risk was significantly reduced. The common issue for many companies is that call recordings are an afterthought. The platform used for calls predates the introduction of payments, and it’s managed by IT rather than compliance.
The archive of recordings is rarely audited. When auditors do come in, they often find spoken card numbers lurking in old files. That’s a problem under the new PCI DSS version. Agents are another weak point. Even with the best training, one dishonest person can cause a breach.
Virtual terminal, payment link, or automated line
There are three ways to use Paytia, depending on the situation. The virtual terminal is best when the customer is on the phone and ready to pay immediately. It keeps the agent in the conversation for any queries, part payments or reassurance. The customer types their details on their own phone, and the agent sees the progress on screen.
The second option is the payment link. This is suitable when the customer isn’t ready to pay during the call or isn’t physically present. You send a branded link by text or email. The customer pays on their own device at their own convenience.
This works well for invoices with payment terms, mail or email orders, and situations where you need to confirm payment later. The third option is the automated phone payment line — an IVR systemthat handles high volumes with little or no agent involvement. It’s for situations where there’s nothing to discuss, no need for a queue, and the payment can be processed at any hour. Each of these options is secure and PCI compliant. The choice depends on your customer journey and operational needs.
What you need, and what it costs
To use Paytia, you need a merchant account that supports card-not-present transactions. Most businesses already have one of these. Paytia routes the payment authorisation to the acquirer you already use. Your rates, merchant identifier, settlement timing and reporting remain unchanged. There’s no migration needed.
The system works alongside any phone system— whether you use an on-premise switch, a cloud contact centre or softphones. Integration happens at the call-leg level, so there’s no need for a packaged connector or special hardware. The cost consists of three elements. First, there’s the platform fee. Second, you pay the card-not-present transaction rate, which is typically 0.1 to 0.3 per cent higher than card-present rates because issuers charge more for the missing chip and PIN.
Third, there’s the cost of compliance. This isn’t usually shown in comparison tables — it includes assessor time for the SAQ, a penetration test across the agent estate, and remediation if card numbers are found in the recording archive. Most customers see the change take effect within a week. Agents need almost no training because the only thing they used to type — the sixteen-digit card number — is simply gone.
What this doesn't fix
Paytia doesn’t eliminate card-not-present fraud or shift chargeback liability. Friendly fraud can still happen — a real customer makes a purchase and later claims they never did. Without the liability shift provided by 3-D Secure, you’ll still be responsible for those disputes. Paytia supports 3-D Secure version 2 as a step-up option when the customer has a mobile during the call. But it’s not a fraud screening platform.
The rules your acquirer sets still apply. You can use velocity limits, block known-bad card ranges, and apply security code and address checks, but those are your tools, not ours. Your PCI obligations still exist. You must complete an SAQ every year, keep staff trained, maintain network security on everything still in scope, and have an incident response plan. The scope is much smaller now, but it hasn’t gone away.
Paytia reduces your compliance burden, but it doesn’t remove it. You still need to take the usual steps — clear order confirmations, refunds only to the original card, recorded confirmation of agreements, and timely chargeback responses. Those defences work just as well as they ever did. Paytia just removes the part where card numbers go through your systems, your agents and your call recordings.
Frequently asked questions
What is a virtual terminal?+
A virtual terminal is a payment screen that staff log into through a browser to take card payments when the customer and card are not present. It doesn’t require a physical card reader, and your team enters the amount, a reference, and then the card details. Each transaction is sent to the acquirer for authorisation one at a time. This method is used for phone orders, mail orders, invoices settled by phone, deposits and final balances. It allows you to accept payments without the customer being on-site.
Do I need a merchant account to use a virtual terminal?+
Yes, you need a merchant account to use a virtual terminal. The terminal itself is just the interface for capturing the payment, while the actual money still flows through your merchant account and an acquirer. Most UK acquirers offer a card-not-present facility on a standard account, sometimes with a separate merchant identifier and pricing. Paytia connects into the acquirer you already use, so your rates, settlement schedule and reconciliation process remain unchanged.
Is a virtual terminal PCI compliant?+
A virtual terminal can be PCI compliant if the provider holds the necessary certification, but that doesn’t automatically make your business compliant. If your agents are hearing the card number and typing it in, then their workstation, network and any recordings become part of your cardholder data environment. This usually means you're handling an SAQ D, which has around 329 compliance controls, or at best an SAQ C-VT. The compliance of the terminal itself doesn’t affect your overall compliance status.
What makes Paytia's virtual terminal different?+
Paytia’s virtual terminal is different because the agent never handles the card. They open the terminal, enter the amount and reference, and start the payment. The customer then keys their own card details on their phone keypad during the call. Paytia masks the keypad tones so the agent hears only flat beeps and the recording captures nothing. The agent sees a masked progress indicator and the authorisation result. They can’t write down, repeat or leak the number because they never see it.
Can I use a virtual terminal for recurring payments?+
Yes, you can use a virtual terminal for recurring payments. On the first transaction, the card is tokenised and stored securely in Paytia’s vault. Every subsequent charge uses that token rather than the actual card number. This supports subscriptions, instalment plans, renewals and any ad-hoc repeat charges. The customer only needs to enter their details once. Since the real card number never reaches your systems, it stays out of your PCI scope.
How much does a virtual terminal cost?+
A virtual terminal has two main costs and one that is often overlooked. The first is the platform fee for the terminal itself. The second is the card-not-present transaction rate, which is usually about 0.1 to 0.3 per cent higher than card-present rates. The third cost is compliance — this includes the time an assessor spends on an SAQ D assessment, a penetration test across your agent estate and any remediation if card numbers are found in recordings. Don’t assume how the platform fee is structured.
Can a virtual terminal take payments over the phone safely?+
Yes, a virtual terminal can take payments over the phone safely — provided the card details bypass the person on the call. On a standard terminal, the customer reads the number aloud and the agent types it, meaning the card data ends up on the audio, screen and in the recording for hours or longer. With Paytia, the keypad tones are masked, so the agent hears only flat beeps. The digits go directly to the payment platform, leaving nothing in the recording to redact later.
What's the difference between a virtual terminal and a payment link?+
The difference between a virtual terminal and a payment link is the timing. A terminal processes a payment during a live call, used when a customer is ready to pay now. A payment link lets them settle at their convenience on their own device. It’s ideal for invoices, follow-ups and anyone who prefers not to key a card mid-call. Most businesses run both options from one account and choose based on the situation. Neither method requires the card data to reach your systems.
Does a virtual terminal work with 3-D Secure?+
Yes, a virtual terminal can work with 3-D Secure, but only if the customer has their mobile phone with them during the call. When 3-D Secure version 2 is available, it’s used as a step-up process and can shift the liability. If the customer doesn’t have their phone, the transaction falls back to unauthenticated card-not-present. This is why fraud screening and tokenisation are more important on this channel than online. Paytia uses 3-D Secure when available and flags higher-risk transactions when it isn't.
Can I use a virtual terminal on a tablet or in person?+
Yes, a virtual terminal works on a tablet or in person. It runs in a browser, so a tablet is just as effective as a laptop. When used in person, a representative hands the device over and the customer types their own card. It follows the same principle as the phone flow but with a screen instead of a keypad. This is useful for home visits, on-site assessments and trade counters. The process keeps the card data secure and out of your systems.
How long does it take to set up?+
Most customers are live within a week. You keep your existing acquirer and phone system — Paytia sits between them, so there’s no migration and no need to remove existing systems. Agents need almost no training since the workflow barely changes. They still see a screen with the amount and reference, and press a button to start the payment. The only difference is that the sixteen digits they used to type are now gone.
What is SAQ C-VT and does it apply to me?+
SAQ C-VT is a PCI self-assessment questionnaire for merchants using a virtual terminal to take card-not-present payments. It applies only if you’re using an isolated single computer with no card storage. The requirements are strict: one dedicated machine, no other apps running, no stored data. Contact centres rarely qualify because agents use networked desktops with customer systems and softphones. If that’s your setup, you're on SAQ D, no matter what a terminal provider says.
“I wanted something that was as simple to set up and use as a virtual terminal or a point-of-sale card reader - but also had the flexibility to adapt as our usage and functional needs grow. I'm delighted to say that Paytia has achieved precisely that.”
Alison Wade
Head of Income and Performance, Pinnacle Group
Read the case study →Used by British American Tobacco · Howard Kennedy · CITB · Clinical Partners · Trinity Hall College
Since 2016
Building secure payments
PCI DSS Level 1
Highest certification
99.99%
Platform uptime
£400M+
Transactions processed
See it in action on a real call
We show you what your agents see, what your customers hear, and what lands in your call recording. Most customers are live within a week on their existing acquirer and phone system.
Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia
Related solutions
Other ways to take payments in this channel.
DTMF Masking
Also called DTMF suppression. The customer types their card on their phone keypad. We mask the tones in the live audio so the agent doesn't hear them and the recording stays clean.
Learn moreMOTO Payments
Take Mail Order / Telephone Order payments without the card number reaching your agents, your recording, or your systems.
Learn moreAgent-Assisted Payments
Your agent stays on the live call while the customer keys their card. We mask the tones so no card data reaches the recording or the agent's audio.
Learn more