All terms
Security & Compliance

Card-on-File

Securely storing a customer's tokenized payment credentials for future purchases, subscriptions, or one-click checkout. Done compliantly, card-on-file boosts conversion and retention while keeping raw card data out of your hands.

Clear consent and clear descriptors are essential with card-on-file: customers should always understand when and why a stored card will be charged.

Card on file means the customer has agreed to let a business keep their card details so it can charge them later without re-entering the number. Common card-on-file transactions include subscriptions, memberships, saved cards for one-click checkout, and account top-ups.

For security, the card number itself should not sit on the merchant's systems. It is replaced with a token that only works with the merchant's payment provider, so a breach of the merchant's database does not expose usable card numbers. The card security code (CVV) is never stored at all.

Common questions

What does card on file mean?
It means a business has your permission to store your card details, usually as a secure token, so it can charge you later for things like subscriptions or repeat orders without asking for the card again.
Is it safe to keep a card on file?
It is safe when the business uses tokenization and a PCI-compliant payment provider. The real card number is replaced with a token that is useless outside that provider, and the CVV is never stored.
What is the difference between card-on-file and recurring billing?
Card-on-file is the stored credential. Recurring billing is one way of using it: charging the stored card on a fixed schedule. A stored card can also be used for one-off purchases the customer starts themselves.

Related terms

Ready to get approved?

Tell us about your business. A high-risk specialist will map the fastest path to live payments.