Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

How to Collect Credit Cards via Phone without PCI Compliance

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
704
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

Merchants seeking to accept credit cards by phone without expanding their PCI-DSS compliance scope face risks from human operators, written notes, computer entry, and call recordings that may capture sensitive payment data. Phone payments are card-not-present transactions, but the involvement of staff can bring otherwise out-of-scope systems into PCI scope if they see, record, or store cardholder information. A recommended approach is to route customers through an interactive voice response system that collects card numbers and CVVs directly by keypad while operators are excluded from the sensitive portion of the call. The system can then encrypt and tokenize the information and send it to a payment service provider, while DTMF masking prevents keypad tones from being overheard or retained in recordings. Combining IVR-based collection, tone masking, and third-party tokenization can help vendors support phone payments while reducing exposure to protected payment data and associated compliance obligations.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.