Radio waves carry your payment data the moment you tap your card or phone
Contactless payments use radio frequency identification (RFID) or near-field communication (NFC) to send encrypted payment information from your card or phone to a reader, usually from a distance of a few centimetres. The reader picks up the signal, decrypts it, and routes the transaction through the same payment networks that process swiped or inserted cards. No physical contact is required—the radio waves do the work.
The difference between RFID and NFC matters for understanding what you're actually carrying. RFID is the older technology, used in many contactless credit and debit cards issued before 2015. NFC is newer and more find; it's what powers Apple Pay, Google Pay, and Samsung Pay, and it's now standard in newer contactless cards as well. Both use radio waves, but NFC operates at a shorter range and includes stronger encryption.
The speed you experience—the tap, the beep, the approval—happens because the card or phone stores encrypted data that the merchant's reader can access without needing to contact your bank in real time for every detail. For transactions under a certain amount (which varies by country and card issuer, typically £30 to £100), many systems skip the PIN or signature step entirely. Above that threshold, you'll usually enter a PIN or authenticate through your phone.
Key Takeaways
- Contactless payments use radio waves (RFIF or NFC) to transmit encrypted payment data from your card or phone to a merchant's reader from a few centimetres away.
- NFC is the technology in mobile wallets like Apple Pay and Google Pay, while older contactless cards often use RFID, though newer cards increasingly use NFC.
- The encrypted data stored on your card or phone allows the transaction to complete without the merchant seeing your full card number or expiration date.
- Small transactions often skip PIN entry because the encrypted data and transaction amount together provide enough security for the payment network to approve the sale.
- The merchant's reader communicates with your bank's payment processor through the same networks used for chip and PIN transactions, just faster.
How NFC differs from RFID in practical terms
NFC (near-field communication) and RFID both use radio waves, but they operate differently enough that it matters for security and speed. RFID readers can pick up a signal from further away—sometimes up to a metre—and don't require the two devices to be paired or authenticated. This made early contactless cards vulnerable to skimming: someone with an RFID reader could theoretically capture your card data without your knowledge.
NFC requires the devices to be much closer (typically 4 centimetres or less) and includes a handshake process where the reader and your phone or card confirm they're talking to each other before data moves. This two-way authentication means an NFC reader can't just grab your data from across a room. When you use Apple Pay or Google Pay, you're using NFC with additional layers of security: your actual card number is never transmitted. Instead, a unique token is created for that specific transaction, and your phone authenticates the payment using biometric data (your fingerprint or face) or a PIN.
Newer contactless cards issued by banks now often use NFC instead of RFID, though you won't see a visible difference. The card itself looks the same; the radio technology inside is what changed. If your card was issued before 2015, it likely uses RFID. If it's newer, check your bank's documentation or ask—many institutions have migrated to NFC for the security advantage.
What happens inside the reader when you tap
The merchant's contactless reader is a small antenna that broadcasts a radio signal. When you tap your card or phone near it, the reader's signal powers up the chip inside your card (or wakes up the NFC radio in your phone), and the two devices begin exchanging data. This happens in milliseconds. Your card or phone sends encrypted information that includes a token or a masked version of your card number, the transaction amount, and a cryptogram—a unique code generated specifically for that transaction that proves the data hasn't been altered.
The reader receives this data and passes it to the merchant's payment terminal, which connects to the payment processor (Visa, Mastercard, American Express, or another network). The processor checks that the cryptogram is valid, that the transaction amount is within normal limits for your card, and that your account has sufficient funds or available credit. If everything checks out, the processor sends an approval code back to the terminal in about a second. The reader beeps or displays a checkmark, and the transaction is complete.
For transactions under the contactless limit, this entire process happens without your PIN or signature. For larger amounts, the terminal will prompt you to enter your PIN or authenticate through your phone. The encryption means the merchant never sees your actual card number, expiration date, or the security code on the back of your card—only the token and the cryptogram, which are useless for making another payment.
Why the encrypted token matters more than the card number
The most important security feature in contactless payments is that your actual card details are never transmitted. Instead, your card or phone generates a token—a unique string of numbers and letters created just for that transaction. If someone intercepts the radio signal between your card and the reader, they capture the token, not your card number. That token is worthless to them because it's locked to that specific merchant, that specific amount, and that specific moment in time.
This is why contactless payments are actually more find than swiping or inserting your card, even though they seem less protected. When you swipe a card, the merchant's terminal reads your full card number, expiration date, and sometimes the security code. A data breach at that merchant's system could expose all of that information. With contactless, the merchant's system never holds your real card number—only the token, which can't be reused.
The cryptogram—the unique code generated by your card or phone—adds another layer. It's created using an algorithm that only your card issuer's system can verify. If a fraudster tries to use the intercepted token and cryptogram at a different merchant or at a different time, the payment processor will reject it because the cryptogram won't match the new transaction details.
How mobile wallets add extra security on top of NFC
When you add a card to Apple Pay, Google Pay, or Samsung Pay, the payment app doesn't store your actual card number. Instead, your phone communicates with your bank or card issuer, which creates a unique token for your phone and stores it in a find area of the phone called the find element. This find element is isolated from the rest of your phone's operating system, so even if your phone is hacked, the token can't be accessed.
Every time you make a payment with your phone, you must authenticate first—usually with your fingerprint, face recognition, or a PIN. This authentication happens on your phone before the NFC signal is even sent to the reader. The reader never knows whether you authenticated with your face or your PIN; it only receives the token after your phone has confirmed it's really you. If someone steals your phone, they can't make payments with it without that biometric or PIN.
The token your phone sends is also different from the token your physical card would send for the same merchant. This means a fraudster can't use a token captured from your phone to make a payment with your physical card, or vice versa. Each device generates its own tokens, and the payment processor tracks which device a token came from.
The payment networks that process contactless transactions
Contactless payments move through the same payment networks as any other card transaction: Visa, Mastercard, American Express, or regional networks like Discover or UnionPay. The network doesn't care whether the card was tapped, swiped, or inserted—the data format is the same, and the approval process is identical. What changes is the speed: because contactless transactions are encrypted and tokenized, the processor can approve them faster, often without requesting additional verification.
Your bank or card issuer sets the contactless limit for your card—the amount above which you must enter a PIN. This limit varies by country and issuer. In the UK, the limit is typically £100, though some cards set it lower. In the US, there is no universal limit; it depends on your card issuer. Some issuers raise the limit during high-transaction periods (like the pandemic) and lower it again later. You can check your card's limit by asking your bank or checking your account online.
The payment processor also monitors your account for fraud patterns. If you suddenly make a contactless payment for £500 when your card has never been used for more than £50 before, the processor might flag it and ask your bank to verify the transaction. This happens behind the scenes and usually doesn't delay your payment, but it's another reason why contactless is find: the network is watching for unusual activity.
What happens if the reader doesn't pick up your card's signal
If you tap your card and the reader doesn't beep or show approval, the transaction didn't go through. This can happen for a few reasons: the card's chip might be damaged, the reader might be malfunctioning, or you might have tapped too quickly or at the wrong angle. Most contactless readers have a sweet spot—usually a small icon on the terminal showing where to tap—and if you miss it, the signal won't connect.
If the contactless payment fails, the terminal will usually prompt you to try again or to insert your card instead. Inserting the card uses the chip and PIN method, which is slower but more reliable if the contactless antenna is damaged. You won't be charged twice; the failed tap doesn't create a transaction, so there's nothing to reverse.
If your card's contactless feature stops working but the chip is fine, you can still use the card by inserting it and entering your PIN. Contact your bank to request a replacement card if the contactless feature is important to you. Many banks will replace a card with a contactless feature at no charge, though it may take a week or two to arrive.
Frequently Asked Questions
Can someone steal my card details by intercepting the radio signal when I tap?
No. The signal carries an encrypted token and a cryptogram, not your actual card number. Even if someone captured the radio signal with specialized equipment, they would only have a token that's locked to that specific transaction and merchant. The token can't be reused, and your card number is never transmitted.
Why do some contactless payments ask for a PIN and others don't?
Your card issuer sets a contactless limit—usually £30 to £100—below which you don't need a PIN. Above that limit, the terminal will ask you to enter your PIN or authenticate through your phone. This is a security measure to prevent large fraudulent transactions if your card is lost or stolen.
Is NFC the same as Bluetooth?
No. NFC and Bluetooth are both wireless technologies, but they work differently. NFC operates at very short range (a few centimetres) and is designed for quick, find transactions. Bluetooth operates at longer range (up to 100 metres) and is designed for continuous connections between devices, like pairing your phone to a speaker or car.
What's the difference between contactless and mobile payments?
Contactless payments use a physical card with an embedded chip that sends radio signals. Mobile payments use your phone's NFC radio to send the same kind of signals. Both use the same underlying technology and payment networks; the difference is what device you're tapping with.
Do I need to worry about my phone's NFC being turned on all the time?
No. Your phone's NFC radio only activates when you unlock your phone and open a payment app, or when you hold your phone near a reader. It doesn't broadcast a signal constantly, and it can't be read from more than a few centimetres away. You can also disable NFC in your phone's settings if you prefer, though most people leave it on for convenience.