Clear consent and clear descriptors are essential with card-on-file: customers should always understand when and why a stored card will be charged.
Card on file means the customer has agreed to let a business keep their card details so it can charge them later without re-entering the number. Common card-on-file transactions include subscriptions, memberships, saved cards for one-click checkout, and account top-ups.
For security, the card number itself should not sit on the merchant's systems. It is replaced with a token that only works with the merchant's payment provider, so a breach of the merchant's database does not expose usable card numbers. The card security code (CVV) is never stored at all.
Common questions
- What does card on file mean?
- It means a business has your permission to store your card details, usually as a secure token, so it can charge you later for things like subscriptions or repeat orders without asking for the card again.
- Is it safe to keep a card on file?
- It is safe when the business uses tokenization and a PCI-compliant payment provider. The real card number is replaced with a token that is useless outside that provider, and the CVV is never stored.
- What is the difference between card-on-file and recurring billing?
- Card-on-file is the stored credential. Recurring billing is one way of using it: charging the stored card on a fixed schedule. A stored card can also be used for one-off purchases the customer starts themselves.