Skip to main content
PCI DSS Level 1 Certified

Secure Virtual Terminal your reps can't leak from

A virtual terminal is the browser screen your reps use to process card payments when customers aren’t in front of them. On most systems, the rep hears the card number and types it in — pulling their workstation, your network, and call recordings into PCI scope. With Paytia’s terminal, the rep starts the payment but the customer enters their own card number on their phone. The digits never reach your side. You keep your existing processor and phone system. You move from SAQ D to SAQ A.

Quick summary

A virtual terminal is a browser-based screen for card payments when the customer isn’t present — used for phone orders, invoices, mail orders, and deposits. On most systems, the rep types in the customer’s card number, placing the rep, their workstation, your network, and call recordings in PCI scope. This means SAQ D, which includes around 329 requirements. A secure virtual terminal uses the same workflow but shifts card entry to the customer’s phone. The rep stays on the line. No card data reaches your system or recordings. This drops your PCI scope to SAQ A, which has 22 requirements.

Last updated: August 12, 2026

What a virtual terminal actually is

A virtual terminal is a browser-based payment screen your staff log into. Its main job is to handle card payments when neither the customer nor the card is physically present. You enter an amount, a reference for reconciliation, then the card number, its expiry, and the security code. The request goes to a payment gateway, then on to the processor, which approves or declines the transaction.

It’s the digital version of a shop counter card machine—except there’s no card to swipe. You’ll find it used for phone orders, mail order forms, invoice settlements, booking deposits, and final balances at the end of a job. The appeal is clear. You don’t need hardware, no integration project, no developer.

Just a login and you can start taking payments the same day. That makes it fine for low-volume use—think a sole trader handling a few invoices a month. But the convenience comes with built-in challenges.

Why the ordinary design maximizes your PCI scope

In the standard setup, the person taking the payment hears the card number and types it into the system. That moment of exposure is where things get complicated. The platform your provider offers is PCI DSS certified, sure—but that certification only covers the provider’s platform. It doesn’t address the path the card number takes through your business. The second a rep hears the digits, they become a point of exposure. That means they’re in PCI scope. The rep types the number on a networked desktop. That workstation and its network segment now enter the scope too. If the call is recorded, the audio holds a spoken Primary Account Number, or PAN. That recording platform, its storage, backups, and disaster-recovery copies all fall under PCI DSS.

If the number is read back to confirm it, the recording holds it twice. If the rep pastes the number into a customer record, that system is in scope as well. All of this has to be documented. You have to ensure access is controlled, data is encrypted, logs are maintained, systems are patched, and everything is reviewed annually. That means completing the Self-Assessment Questionnaire D, or SAQ D. It’s the heaviest tier, covering roughly 329 requirements. Even SAQ C-VT is more lenient but still requires a dedicated, isolated computer used for nothing else. A contact center rep using a shared desktop that also runs a customer record system and a softphone doesn’t qualify. Nor does a home worker using a personal laptop. And there’s the human element to consider.

One dishonest rep in a busy line can capture dozens of card numbers in a shift. These data breaches often surface months later, when the numbers are sold in a batch. Call recordings are a common source of surprise. The platform that handles them may predate anyone thinking about card payments. It often belongs to IT, not compliance. And no one has audited the archive. Under PCI DSS version 4.0.1, a recording containing an audible card number is considered cardholder data. That means it has to be handled with the same protections as if the number were typed and stored electronically. For many businesses, this creates a compliance headache that’s both time-consuming and expensive.

What ours does differently

With Paytia’s virtual terminal, the rep never hears or types the card number. When the rep opens the terminal, they enter the amount, a reference, and any custom fields. They press a button to start the payment. The customer is then prompted to key their card on their own phone keypad. Each keypress makes a Dual-Tone Multi-Frequency tone. Paytia intercepts every tone before it reaches the rep’s audio or the recording, replacing it with a flat beep. The rep sees asterisks filling in on the screen and stays on the call throughout. They can answer questions, handle part payments, or provide reassurance.

The authorization request goes from Paytia’s PCI DSS Level 1 environment straight to your existing processor. The result appears on the rep’s screen. Because the rep never had the number, they couldn’t write it down, repeat it back, or paste it anywhere. The recording holds a conversation about a payment, but no cardholder data. There’s nothing to redact, nothing to pause, nothing to explain to an auditor. The card is tokenized in the same transaction. That means refunds go back to the original card, and repeat charges, instalments, and subscription renewals use the token. The customer keys their details once.

The token is safe to store in a customer record because it’s worthless outside Paytia’s vault. The virtual terminal runs in a browser. It works on a desk machine, laptop, or even a tablet for staff away from their desk. In person, the rep can hand the tablet across and the customer types their own card. Home workers get the same setup. No card data reaches them either. The result is a much narrower compliance footprint. Instead of SAQ D, you complete SAQ A, which has only 22 requirements. That’s a big difference in time and effort.

What changes on your assessment

Same terminal workflow, same processor, same phone system. Very different evidence pack.

PCI DSS Level 1 Service Provider certification

PCI DSS Level 1

The highest tier of PCI certification. The scope reduction happens the moment card data stops arriving at your systems — not when you sign the contract.

The difference isn't that we make PCI easier to evidence. It's that most of what you were evidencing stops being in scope. A recording system with no card data in it isn't a cardholder data environment. A rep desktop that never receives a card number doesn't need the lockdown, the isolation, or the annual penetration test that one does.

AreaTraditional terminalWith Paytia
Who keys the cardYour repThe customer
Self-assessmentSAQ D (329 requirements)SAQ A (22 requirements)
Call recordingsHold audible card numbersCard-data free
Rep workstationIn scope, full lockdownOut of scope
Remote workersScope follows them homeNothing to contain
Annual auditFull QSA assessmentEvidence of integration only

Who's running one, and what usually goes wrong

You’ll find Paytia's virtual terminal in use by a wide range of businesses. Property management companies use it to collect rent. Veterinary groups take payments while the owner is still in reception. Wholesale desks invoice account customers by phone. Nonprofits run phone donation campaigns, especially at year-end. Healthcare practices use it for copays and balance-after-insurance payments. These cases often involve dual compliance with HIPAA and PCI. Utilities and municipal services use it for service charges.

Education uses it for tuition. Legal and accounting practices use it for retainers. The common thread is a phone that rings and a card payment that must happen while the person is on the line. The trigger is usually external. A processor asks for a completed SAQ. A client requests a security questionnaire. A cyber insurer asks about recordings. An assessor listens in and spots a problem.

What usually goes wrong is not a failure of the system, but a failure to recognize the risks it creates. Many platforms were built for other purposes and only later adapted to handle payments. That means the recording systems, IT infrastructure, and even the rep’s desktop were never designed with PCI in mind. Reps are often the last line of defense but the most difficult to secure with technology. A single dishonest employee can compromise dozens of card numbers in a shift. And with recording systems that weren’t built for PCI, it’s easy for old call logs to become a hidden compliance risk. These mistakes aren’t uncommon. They’re often the reason a business starts looking for a solution like Paytia’s. It’s not about perfection, but about reducing the risks in a way that makes compliance more practical and less overwhelming.

Virtual terminal, payment link, or automated line

Depending on your needs, you can choose between three ways to handle payments. The virtual terminal is best when the customer is on the phone and ready to pay. It keeps the rep in the conversation for any questions, part payments, or reassurance. It works well for phone orders, invoice settlements, and final balances after a job. The rep never hears or types the card number, making this option both secure and easy to use. If the customer isn’t ready to pay or isn’t there at the moment, a payment link is a good choice. You send a branded link by text or email.

The customer pays on their own device in their own time. This suits invoices with payment terms and mail or email orders. It removes the pressure of a live call and gives the customer more control. It also keeps your rep out of the payment process entirely. For high-volume, low-touch scenarios, an automated phone payment line is the way to go. It uses an interactive voice response system. No rep is involved, no queue to wait in, and it runs at any hour.

It’s ideal for routine payments where there’s nothing to discuss or ask. It handles the transaction quickly and efficiently, without exposing your staff to card data. Each option has its own advantages. The virtual terminal is best for engagement and support. Payment links offer convenience and flexibility. The automated line is efficient and scalable. The choice depends on your business model, your customer base, and the volume of payments you handle.

What you need, and what it costs

To get started, you need a merchant account with a card-not-present facility. Most businesses already have one. Paytia routes authorization to whichever processor you use. Your rates, merchant identifier, settlement timing, and reporting all stay the same. There’s no migration, no change to your existing setup. The system works alongside any phone system you use. That includes on-premise switches, cloud contact centers, and softphones. Integration happens at the call-leg level.

There’s no need for a packaged connector or custom development. It fits into your workflow without disrupting it. There are three costs to consider. The first is the platform fee. The second is the card-not-present transaction rate, which is roughly 0.10 to 0.30 percent above card-present rates. That’s due to the higher risk associated with card-not-present transactions. Issuers price in the missing chip read. The third cost is compliance.

It’s not always shown in comparison tables, but it matters. For SAQ D, you’ll need assessor time, a penetration test across the rep estate, and remediation if card numbers are found in the recording archive. With Paytia, you avoid that. Most customers live within a week of setup. Reps need almost no training because the sixteen digits they used to type are simply gone. The savings in compliance time and risk are hard to quantify but real. You avoid the burden of SAQ D and the costs that come with it. You reduce the chance of data exposure and the stress of managing a compliance audit.

What this doesn't fix

This solution doesn’t eliminate card-not-present fraud or shift chargeback liability. Friendly fraud still happens. A real customer orders, gets the product or service, then claims they never made the call. Without the liability shift that 3-D Secure provides, the merchant absorbs the loss. 3-D Secure version 2 can be used as a step-up authentication method, provided the customer has a cell phone handy during the call. But it’s not a guarantee. It adds a layer of defense but doesn’t remove the risk entirely. The defenses you rely on are still operational.

Clear order confirmations, refunds only to the original card, and recorded confirmation of what was agreed—now safe to record—are key. So is a chargeback response that reaches the processor in time. Paytia isn’t a fraud screening platform. The processor’s rules still apply. You can set velocity limits, block known-bad card ranges, and use security-code and address checks. Those are the tools you have. PCI obligations remain. You still have to complete an SAQ every year.

Staff training is still required. Network security must be maintained on everything still in scope. An incident response plan is still needed. The scope is much smaller. It hasn’t disappeared. This doesn’t make your compliance work easy. It just makes it more manageable. It narrows the scope, reduces the risk, and simplifies the process. But it doesn’t eliminate the need to stay vigilant.

Frequently asked questions

What is a virtual terminal?+

A virtual terminal is a payment screen your staff log into through a browser to take card payments when the customer and card aren’t present. You use it without a physical card reader, entering an amount, a reference, and the customer’s card details manually. Each transaction is processed one at a time, and it’s commonly used for phone orders, mail orders, invoices settled by phone, deposits, and final balances.

Do I need a merchant account to use a virtual terminal?+

Yes, you need a merchant account to use a virtual terminal. The terminal is just the interface for capturing payment details—the actual processing still goes through a merchant account and payment processor. Most UK payment processors offer a card-not-present option on standard accounts, often with a separate MID. Paytia connects to the processor you already use, so your pricing, settlement schedule, and reconciliation stay the same.

Is a virtual terminal PCI compliant?+

A virtual terminal can be PCI compliant, but that doesn’t automatically make your business compliant. The platform provider might hold certification, but if your staff hear and type card numbers, then your environment—including workstations, network, call recordings, and any stored data—falls under PCI scope. You may be responsible for completing an SAQ D or at best SAQ C-VT, depending on your setup. The terminal being certified doesn’t eliminate your compliance duties.

What makes Paytia's virtual terminal different?+

Paytia’s virtual terminal is different because your rep never touches the card details. They open the terminal, enter an amount and reference, and start the payment. The customer types their own card on their phone keypad during the call. Paytia masks the tones, so your rep hears only flat beeps and sees a masked progress indicator. The rep can’t write the number down or leak it because they never had it to begin with.

Can I use a virtual terminal for recurring payments?+

Yes, you can use a virtual terminal for recurring payments. The first transaction tokenizes the card, and all subsequent charges use the token instead of the full number. This works for subscriptions, instalments, renewals, and ad-hoc repeat charges. The customer only keys their details once, and the real card number stays in Paytia’s vault. This setup ensures recurring billing doesn’t bring card data into your systems, keeping you out of PCI scope.

How much does a virtual terminal cost?+

A virtual terminal typically has two costs: the platform fee and the card-not-present transaction rate. The latter is usually 0.10 to 0.30 percent higher than card-present due to higher risk. The third cost many miss is compliance. If your reps hear card numbers, you may need an SAQ D, a penetration test, and possible remediation if past call recordings contain card data. We don’t disclose how Paytia’s platform fee is structured.

Can a virtual terminal take payments over the phone safely?+

Yes, a virtual terminal can safely take payments over the phone, but only if the card data bypasses the rep. On a standard terminal, the rep types the number the customer reads aloud, which means the number ends up in audio, call recordings, and systems. With Paytia, the customer types their own card on their phone while the rep stays on the line. Keypad tones are masked, so no card data appears in recordings or on the rep’s screen.

What's the difference between a virtual terminal and a payment link?+

A virtual terminal and a payment link differ mainly in timing. A terminal is used during a live call, where the customer is ready to pay immediately. A payment link lets the customer pay at their convenience on their own device, which suits invoices, follow-ups, and those who don’t want to key a card during a call. Most businesses use both, selecting the right option for each situation. Neither requires card data to reach your systems.

Does a virtual terminal work with 3-D Secure?+

A virtual terminal works with 3-D Secure where the customer has a cell phone during the call. With 3-D Secure version 2, the transaction can be authenticated as a step-up, shifting liability. If the customer doesn’t have a phone, the transaction falls back to unauthenticated card-not-present. That’s why fraud screening and tokenisation are especially important for this channel. Paytia activates 3-D Secure when possible and flags higher-risk transactions when it isn’t.

Can I use a virtual terminal on a tablet or in person?+

Yes, a virtual terminal can be used on a tablet or in person. It runs in a browser, so a tablet works just as well as a laptop. In person, a rep can hand the device to the customer who types their own card. The principle is the same as the phone flow, but with a screen instead of a keypad. This is common for home visits, on-site assessments, and at trade counters where the customer is present.

How long does it take to set up?+

Setting up a virtual terminal typically takes most customers about a week. You keep your existing processor and phone system; Paytia simply connects between them, so there’s no migration or system changes. Your reps need almost no training because the workflow changes little—just a screen with amount and reference, and a button to start the payment. The card number they used to type is now handled by the customer, so your reps don’t need to learn much new.

What is SAQ C-VT and does it apply to me?+

SAQ C-VT is a PCI self-assessment form for merchants using a virtual terminal on a single isolated computer with no card data stored. It’s shorter than SAQ D but comes with strict conditions, like a single dedicated machine with no other apps or stored data. Most contact centers don’t meet these requirements because reps use shared, networked desktops with customer systems and softphones. If that’s your situation, you’re on SAQ D regardless of what a terminal provider says.

See the terminal in action on a real call

We show you what your reps see, what your customers hear, and what lands in your call recording. Most customers go live within a week using their current processor and phone system.

PCI DSS Level 1
TCPA & HIPAA Aligned

Trusted by US law firms, insurers, healthcare organizations and regulated businesses that can't afford to get compliance wrong. Learn more about Paytia