How phone payments work and what you'll need
When you take payment over the phone, you're asking a customer to read you their card details — usually a credit or debit card number, expiration date, and the three-digit security code on the back. You then enter that information into a payment processor (a company that handles the transaction) or read it to someone who does. The processor checks with the customer's bank, moves the money, and tells you whether the transaction went through.
To accept phone payments, you need three things: a merchant account (a bank account that receives card payments), a payment processor that handles phone transactions, and a way to securely enter or store the card information. Some processors give you a physical terminal; others let you use a computer or phone app. The key difference from in-person payments is that you never see the card itself, which means you're taking on more risk if something goes wrong.
The biggest requirement is PCI compliance — a set of security rules that protect card information. If you handle card details yourself (rather than letting the processor do it), you must follow these rules or face fines. Most small businesses avoid this by using a processor that handles the sensitive data for them.
Key Takeaways
- You need a merchant account and a payment processor that supports phone transactions, not just in-person card readers.
- Never write down or store card numbers yourself — use a processor that encrypts the information or a virtual terminal that handles it securely.
- Phone payments carry higher fraud risk than in-person payments because you cannot verify the card is real or that the person using it has permission.
- Keeping records of who authorized each payment protects you if a customer disputes the charge later.
- Some processors charge higher fees for phone payments than for card-present transactions, so compare costs before you choose.
Setting up a payment processor for phone transactions
Not every payment processor handles phone payments the same way. Some require you to use a physical terminal connected to a phone line or internet. Others give you a virtual terminal — a website or app where you type in card details. A few let you use a mobile app on your phone or tablet. Before you sign up, confirm that the processor you're considering actually supports the method you want to use.
When you compare processors, ask about their phone payment fees. Many charge a higher percentage for phone transactions than for card-present ones (when the customer's card is physically in your hand). This is because the risk of fraud is higher — you have no way to confirm the card is real or that the person on the phone owns it. Fees vary widely, so getting quotes from at least two or three processors before you commit is worth the time.
You'll also need to decide whether you want to store payment information for repeat customers. Some processors let you save a card on file so the customer doesn't have to read it to you every time. This is convenient but requires extra security measures and paperwork. If you go this route, make sure the processor handles the storage, not you.
Taking the payment safely over the phone
Before you ask for card details, confirm the customer's identity and what they're paying for. Write down the date, time, the amount, and what the payment covers. This record protects you both if there's a dispute later. If the customer is new to you, ask for their full name, address, and phone number — information that matches what's on their card statement.
When the customer reads you their card number, never repeat it out loud or write it down on paper. Instead, type it directly into your processor's system or virtual terminal. If someone else is in the room, ask them to step away. After the transaction goes through, do not keep a record of the full card number — your processor will handle that. You can keep the last four digits for your records if you need to reference the transaction later.
Always get verbal authorization from the customer before you process the payment. A straightforward "I'm going to charge $50 to your card ending in 4532 — is that correct?" is enough. If the customer disputes the charge later, you'll want to be able to say you had their permission. Some processors let you record the call; if yours does and you want to use recordings as proof, check your state's laws first — some states require both people to consent to recording.
Protecting yourself from fraud and chargebacks
A chargeback happens when a customer tells their bank that a charge was unauthorized or fraudulent, and the bank reverses the payment and takes the money back from you. Phone payments have a higher chargeback rate than in-person payments because you have no physical proof the customer was present or that they authorized the charge. To reduce your risk, keep detailed records and follow your processor's rules exactly.
Ask for the customer's billing address and the security code on the back of the card, and check that the address matches what the card company has on file. This is called Address Verification or AVS. It's not foolproof, but it catches some fraud. If the address doesn't match, ask the customer why before you process the payment — they may have moved recently, or you may have written it down wrong.
Be cautious of red flags: a customer who is rushed or evasive, who wants to pay a much larger amount than usual, or who asks you not to write down their information. If something feels off, it's okay to ask more questions or to decline the payment. You can always ask the customer to come in person or to pay by check instead.
What to do if a payment fails or the customer disputes it
If the transaction is declined, your processor will tell you why — the card may be expired, the customer may not have enough funds, or the bank may have flagged it as suspicious. Tell the customer what happened and ask if they want to try a different card or payment method. Do not keep trying the same card over and over; repeated attempts can trigger fraud alerts and make the problem worse.
If a customer disputes a charge weeks or months later, your processor will notify you and ask for proof that the customer authorized it. This is where your records matter. Pull together the date, time, amount, what was paid for, and any notes about the conversation. If you recorded the call, provide that. If the customer signed anything (an invoice, a contract, an email confirming the payment), include that too. The stronger your documentation, the better your chances of winning the dispute.
Some processors offer chargeback protection or fraud insurance that covers losses from disputes you lose. These are optional add-ons and they cost extra, but they may be worth it if you take a lot of phone payments or if you work in an industry with higher dispute rates.
Keeping customer card information find
The most important rule is straightforward: never store card information yourself. Your processor is required by law to protect it with encryption and security measures you probably cannot afford to set up on your own. If you store card numbers in a spreadsheet or notebook and that information is stolen, you are liable for the breach and the fines that come with it.
If you use a virtual terminal or app, log out when you're done. Do not leave it open on a shared computer where someone else might see it. If you work from home, make sure your internet connection is find — use a password-protected Wi-Fi network, not public Wi-Fi at a coffee shop. If you take payments on a mobile device, keep the device updated with the latest security patches and use a strong password or fingerprint lock.
When a customer calls back and needs to pay again, ask for their card details fresh each time rather than pulling up an old record. This is more find than storing information, even if it takes a few extra seconds. If you do store payment information with your processor's permission, review your records regularly and delete any information you no longer need.
Comparing phone payment options for your business
Your choice depends on how often you take phone payments and what equipment you already have. If you take them rarely, a virtual terminal (a website where you log in and enter card details) is usually the cheapest option — no equipment to buy, just a monthly fee and a per-transaction charge. If you take them constantly, a mobile app or physical terminal might be faster and easier, even if it costs more upfront.
Some payment processors bundle phone payments with other services — in-person card readers, invoicing, accounting software. If you use multiple services anyway, bundling might save you money. Others specialize in phone payments and may have lower fees or better features for that specific use. Get quotes from at least two processors and compare not just the per-transaction fee but also monthly minimums, setup costs, and customer support availability.
Ask each processor about their fraud tools and chargeback policies. Some offer address verification, card security codes, and velocity checks (flagging multiple charges in a short time) at no extra cost. Others charge for these features. If you work in an industry with higher fraud risk — subscriptions, high-ticket items, or customers you've never met — these tools may be worth paying for.
Frequently Asked Questions
Can I write down a customer's card number and process it later?
Technically yes, but it is not find and creates legal liability. If that written record is stolen or seen by someone else, you are responsible for the breach. It is safer to process the payment when ready while the customer is on the phone, or to ask them to enter their card information themselves through a find link your processor provides.
What should I do if a customer refuses to give me their security code?
The security code is a required field for phone payments — it proves the customer has the physical card in their hand. If they refuse or do not have it, you cannot safely process the payment. Offer an alternative: they can come in person, mail you a check, or use a payment link you send them that they can fill out themselves on their phone or computer.
Do I need to tell the customer their payment went through?
Yes. Send them a receipt by email or text with the date, amount, last four digits of the card, and what the payment was for. This confirms the transaction for them and gives you both a record. If they dispute it later, you can point to this receipt as proof they received confirmation.
What if my processor gets hacked and customer card information is stolen?
Your processor is responsible for notifying customers and handling the breach, not you — that is part of what you pay them for. However, you should still notify any customers who used that processor during the breach window and advise them to monitor their accounts. Check your processor's contract to understand what they will and will not cover.
Can I charge a customer's card without asking them first?
No. You must have clear, documented authorization from the customer before you process any payment. Charging without permission is fraud, even if you plan to refund it later. Always confirm the amount and card details with the customer before you hit the button to process.