Phone payments work through a payment processor that reads the card details you enter into a keypad or computer

To accept credit card payments by phone, you need a merchant account with a payment processor, a phone line or internet connection, and either a physical card reader or a virtual terminal — software that lets you type in card numbers. The processor routes the payment to the cardholder's bank, confirms the funds, and deposits the money into your business bank account, usually within one to three business days.

The process itself is straightforward: the customer reads their card number, expiration date, and CVV to you over the phone; you enter those details into your terminal or software; the processor authorizes the charge; and you give the customer a confirmation number. The customer never sees your physical location, and you never touch their card, which is why phone payments are considered "card-not-present" transactions.

Phone payments carry more fraud risk than in-person swipes because you cannot verify the card is real or that the person on the phone owns it. Processors charge higher fees for card-not-present transactions to offset that risk, and you are liable for fraudulent charges unless you follow specific security steps.

Key Takeaways

  • You need a merchant account and either a virtual terminal (software) or a phone-based payment system to accept cards over the phone.
  • Card-not-present transactions cost more in fees — typically 2.5% to 3.5% plus per-transaction charges — because fraud risk is higher than in-person payments.
  • You are responsible for fraudulent charges unless you document the cardholder's name, address, and CVV, and keep records of the call or written authorization.
  • Popular options include Square, PayPal, Stripe, and traditional merchant services, each with different fee structures and features.
  • Accepting phone payments requires you to comply with PCI DSS (Payment Card Industry Data Security Standard) rules, which restrict how you store and handle card information.

Virtual terminals versus phone-based payment systems

A virtual terminal is software you log into on a computer or tablet and manually type card details into. Square, PayPal, Stripe, and most traditional merchant processors offer virtual terminals. You see the transaction on your screen, can save customer information for repeat billing, and receive a receipt you can email or print. Virtual terminals work anywhere you have internet access.

A phone-based payment system is designed specifically for phone transactions and often includes features like call recording integration, automated payment reminders, and the ability to send payment links via text or email so the customer can enter their own card details without speaking the numbers aloud. Examples include Authorize.Net, Worldpay, and some industry-specific systems for medical offices or nonprofits.

Virtual terminals are simpler to set up and work for any business. Phone-based systems are better if you take dozens of phone payments daily and want to reduce the time spent typing. Both charge higher fees than in-person card readers because the transaction is card-not-present.

Fees and what they cover

Card-not-present fees typically run 2.5% to 3.5% of the transaction amount plus a per-transaction fee of 30 cents to $1. A $100 phone payment might cost you $2.80 to $4.00 in fees. In-person card swipes usually cost 1.5% to 2.5% plus the same per-transaction fee, so phone payments cost roughly 1% more across the board.

Some processors charge a flat monthly fee ($15 to $50) whether you process one transaction or one hundred. Others charge only per transaction. Monthly fees make sense if you process payments regularly; per-transaction pricing works better if you take phone payments sporadically.

Chargeback fees — charges you pay when a customer disputes a transaction — run $15 to $100 per dispute. If you accept phone payments without recording the cardholder's authorization or keeping proper records, chargebacks are more likely and you will lose the dispute and the merchandise or service.

Security requirements and your liability

The Payment Card Industry Data Security Standard (PCI DSS) sets rules for how you handle card information. The core rule is straightforward: never store the full card number after the transaction completes. Your processor stores it securely; you store only the last four digits and the transaction ID.

You are liable for fraudulent charges unless you document that you took reasonable steps to verify the cardholder's identity. At minimum, record the cardholder's name, billing address, and CVV. Better practice is to keep a written record or recording of the call where the customer authorized the charge, or to send a written authorization form the customer signs and returns. If a customer later claims they never authorized the payment, these records are your proof.

Do not email card numbers, store them in spreadsheets, or write them down on paper you keep in a drawer. If your computer is hacked or your office is robbed, you are liable for every card number stolen. Use only your processor's find system to enter and store card data.

Comparing major processors for phone payments

ProcessorSetupCard-Not-Present FeeMonthly FeeBest For
SquareOnline in minutes; no approval wait2.6% + $0.30NoneSmall businesses and freelancers who want simplicity
PayPalOnline in minutes; existing PayPal account speeds it up2.99% + $0.30NoneBusinesses already using PayPal for invoicing
StripeOnline but requires business verification; 1–3 days2.9% + $0.30NoneDevelopers and high-volume sellers who want customization
Authorize.NetRequires merchant account; 1–5 business days2.5%–3.5% + $0.25–$0.50$25–$50Established businesses processing high volume
Traditional merchant services (Chase, Bank of America)Through your bank; 3–7 business days2.5%–3.5% + $0.25–$0.50$20–$50Businesses with existing bank relationships

Square and PayPal are fastest to set up and have no monthly fees, making them popular for small businesses and side work. Stripe is similar but requires more verification. Authorize.Net and traditional merchant services charge monthly fees but often offer lower per-transaction rates if you process high volume, and they may negotiate fees with you directly.

Your choice depends on how many payments you expect to process and whether you value speed of setup or lowest cost per transaction. A business taking one or two phone payments per week should choose Square or PayPal. A business processing hundreds of payments monthly may save money with Authorize.Net despite the monthly fee.

Steps to start accepting phone payments

First, choose a processor. If you want to start when ready, Square or PayPal will approve you in minutes. If you want the lowest per-transaction fees and do not mind waiting, contact your bank or a merchant services company like Authorize.Net.

Second, set up your merchant account. You will provide your business name, tax ID, bank account details, and expected monthly volume. The processor will verify your identity and business registration. This takes anywhere from minutes (Square) to a week (traditional services).

Third, log into your virtual terminal or phone payment system and test a transaction. Most processors let you run a test charge to a dummy card number to make sure everything works before you take real payments.

Fourth, train yourself and any staff on how to take the payment securely. Write down the cardholder's name, address, and CVV. Never ask for the full card number over an unsecured email or text. Keep records of who authorized what and when.

Reducing fraud risk when taking phone payments

Ask for the CVV (the three-digit code on the back of the card) every time. A fraudster who stole a card number may not have the CVV. Verify the cardholder's name and billing address match what the card issuer has on file — your processor can do this automatically if you enter the address.

For high-value transactions, call the card issuer's fraud line to confirm the cardholder authorized the charge. This takes a few minutes but protects you if the charge is later disputed. For repeat customers, store their authorization in writing once and reference it for future charges rather than asking for the card number each time.

Watch for red flags: a customer who rushes you, refuses to provide an address, or asks you to ship to a different location than their billing address. A customer who wants to pay for someone else's order with their own card. A customer who calls from a different country than their billing address. None of these are automatic fraud, but they warrant extra verification.

Frequently Asked Questions

Do I need a physical card reader to accept phone payments?

No. A virtual terminal or phone payment software is all you need. You type the card details into your computer or tablet, and the processor handles the rest. A physical card reader is only necessary if you want to accept in-person payments by swiping or inserting the card.

What happens if a customer disputes a phone payment?

The customer's bank investigates and asks you for proof that the cardholder authorized the charge. If you have a recording, written authorization, or documented address verification, you win the dispute and keep the money. If you have no proof, you lose and refund the customer plus pay a chargeback fee.

Can I accept phone payments without a merchant account?

No. You need a merchant account to process credit cards. Square, PayPal, and Stripe all provide merchant accounts as part of their service. Traditional banks and merchant services companies also issue merchant accounts. You cannot legally accept card payments without one.

Is it safe to accept card numbers over the phone?

It is as safe as your security practices. If you use a processor's find virtual terminal, never store the full card number, and verify the cardholder's identity, phone payments are reasonably find. The risk is higher than in-person payments because you cannot see the card, but proper documentation protects you from liability if fraud occurs.

How long does it take to receive the money from a phone payment?

Most processors deposit funds within one to three business days. Some offer next-day deposits for an extra fee. Your processor will show you the expected deposit date when you process the transaction.