Dashboard

Taking phone & mail orders securely

A MOTO payment — keying a customer's card on their behalf for a phone or mail order — is one of the most sensitive things a business can do with card data. Brippo's manual card entry is built so that sensitive card details never touch your device, your store, or your staff's notes. This page explains how that works, what it means for your PCI DSS obligations, and exactly what you can share with your bank or acquirer to show you handle cards responsibly.

The short version. You never store or handle a raw card number. When you key a card into Brippo, the number is captured inside a secure, certified payment field and swapped for a harmless token inside a certified environment. Your systems only ever see the token — which keeps your PCI scope at the lightest tier available to most businesses.

The words you'll see

Four terms are worth knowing before the detail below.

How Brippo keeps card data safe

Every manual card entry follows the same path — designed so the real card number goes straight to certified infrastructure and never lingers anywhere you'd have to protect.

  1. 1

    The card is captured in a secure, certified field

    When you open Manual card entry, the card number, expiry and security code are typed into a hardened input provided by Brippo's certified payment layer — not an ordinary text box. Your device's app cannot read the digits you type.

  2. 2

    It goes straight to certified infrastructure

    Those details travel directly, over an encrypted (TLS) connection, to Brippo's PCI DSS Level 1 certified payment infrastructure — the highest and most demanding certification level in the standard. They do not pass through your store, your servers, or Brippo's general systems.

  3. 3

    You get back a token, never the card number

    The certified layer instantly returns a token — a random reference to the card. Everything after that point (taking the payment, receipts, reports) uses only the token. The real card number is never handed back to your device.

  4. 4

    Nothing sensitive is stored

    Brippo does not keep the card number or the security code — not on your phone, not in your store's database, not on Brippo's servers. There is nothing sensitive left behind to be lost, leaked, or stolen.

  5. 5

    The charge is completed inside a certified environment

    The payment is authorised and settled within Brippo's certified payment environment, which carries the full weight of PCI DSS controls — encryption, access control, continuous monitoring and independent annual audits — so you don't have to build or maintain any of it yourself.

What this means for your PCI scope

PCI DSS applies to every business that stores, processes, or transmits card data. The single biggest factor in how much of the standard applies to you — your "scope" — is how much card data your own systems ever touch.

Because Brippo's manual card entry ensures your systems never store, process, or transmit a raw card number, your scope is reduced to the minimum. In practice, most businesses using Brippo for phone and mail orders can validate their compliance with the simplest form of the PCI Self-Assessment Questionnaire (SAQ) — a short annual checklist — instead of a full on-site audit. The demanding technical controls live inside Brippo's certified infrastructure, which is independently assessed every year.

i
Your exact SAQ is set by your bank. The specific questionnaire that applies to you (for example SAQ A or SAQ A-EP) is decided by your acquiring bank based on your whole setup, not this one feature. Confirm it with them — see "Your part" below — and use the resources at the bottom of this page.

Your part in staying compliant

Brippo removes the hardest parts, but PCI compliance is always a shared responsibility. Your side is short:

Handling cards safely during a phone order

These habits keep card data out of places PCI DSS cares about — and out of reach of anyone who shouldn't see it.

Proving your compliance

If your bank, acquirer, or a partner asks you to show that card payments are handled compliantly, you can point them to three things:

Official PCI resources

Everything below comes straight from the PCI Security Standards Council — the authority on PCI DSS — so you can read the rules first-hand and give your bank primary sources.

i
A note on this page. This is general information to help you understand how Brippo handles card data — it isn't legal or compliance advice. Your specific PCI obligations and SAQ type depend on your full business setup and are determined by your acquiring bank. For a formal assessment, speak to your acquirer or a Qualified Security Assessor (QSA).