Taking phone & mail orders securely
A MOTO payment — keying a customer's card on their behalf for a phone or mail order — is one of the most sensitive things a business can do with card data. Brippo's manual card entry is built so that sensitive card details never touch your device, your store, or your staff's notes. This page explains how that works, what it means for your PCI DSS obligations, and exactly what you can share with your bank or acquirer to show you handle cards responsibly.
The words you'll see
Four terms are worth knowing before the detail below.
- MOTO: Mail Order / Telephone Order — a payment where you type the customer's card details for them, because they aren't present to tap or insert a card.
- PCI DSS: The Payment Card Industry Data Security Standard — the global rulebook every business that handles card payments must follow. It's maintained by the independent PCI Security Standards Council, founded by the major card networks.
- Cardholder data: The sensitive parts of a card — the full card number (the "PAN") and never-store values like the CVV / security code. Keeping this data safe is what PCI DSS is about.
- Tokenization: Replacing the real card number with a random stand-in (a "token") that is useless to an attacker. Brippo works only with tokens.
How Brippo keeps card data safe
Every manual card entry follows the same path — designed so the real card number goes straight to certified infrastructure and never lingers anywhere you'd have to protect.
- 1
The card is captured in a secure, certified field
When you open Manual card entry, the card number, expiry and security code are typed into a hardened input provided by Brippo's certified payment layer — not an ordinary text box. Your device's app cannot read the digits you type.
- 2
It goes straight to certified infrastructure
Those details travel directly, over an encrypted (TLS) connection, to Brippo's PCI DSS Level 1 certified payment infrastructure — the highest and most demanding certification level in the standard. They do not pass through your store, your servers, or Brippo's general systems.
- 3
You get back a token, never the card number
The certified layer instantly returns a token — a random reference to the card. Everything after that point (taking the payment, receipts, reports) uses only the token. The real card number is never handed back to your device.
- 4
Nothing sensitive is stored
Brippo does not keep the card number or the security code — not on your phone, not in your store's database, not on Brippo's servers. There is nothing sensitive left behind to be lost, leaked, or stolen.
- 5
The charge is completed inside a certified environment
The payment is authorised and settled within Brippo's certified payment environment, which carries the full weight of PCI DSS controls — encryption, access control, continuous monitoring and independent annual audits — so you don't have to build or maintain any of it yourself.
What this means for your PCI scope
PCI DSS applies to every business that stores, processes, or transmits card data. The single biggest factor in how much of the standard applies to you — your "scope" — is how much card data your own systems ever touch.
Because Brippo's manual card entry ensures your systems never store, process, or transmit a raw card number, your scope is reduced to the minimum. In practice, most businesses using Brippo for phone and mail orders can validate their compliance with the simplest form of the PCI Self-Assessment Questionnaire (SAQ) — a short annual checklist — instead of a full on-site audit. The demanding technical controls live inside Brippo's certified infrastructure, which is independently assessed every year.
Your part in staying compliant
Brippo removes the hardest parts, but PCI compliance is always a shared responsibility. Your side is short:
- Complete your annual SAQ: fill in the Self-Assessment Questionnaire your acquirer or payment provider asks for and sign the Attestation of Compliance. Brippo's architecture is designed so you qualify for a short SAQ — but completing it is your responsibility.
- Keep Brippo up to date: run the current version of the Brippo app and extension so you always have the latest security fixes.
- Protect access: use device passcodes or biometrics, strong dashboard passwords, and give staff only the access they need.
- Handle cards well on the call: follow the simple do's and don'ts below.
Handling cards safely during a phone order
These habits keep card data out of places PCI DSS cares about — and out of reach of anyone who shouldn't see it.
- Do key the card straight into Brippo while you're on the call, then move on.
- Don't write the card number or security code on paper, sticky notes, or a spreadsheet.
- Don't photograph, save, or store card details anywhere — and never keep the security code (CVV). By design, even Brippo can't.
- Don't accept card details by email or chat. Enter them live, then delete any message that contains them.
- Do confirm the customer authorises the charge before you submit. Brippo shows a reminder — and for MOTO, chargeback liability sits with the merchant.
- Do use a trusted, up-to-date device on a network you control.
Proving your compliance
If your bank, acquirer, or a partner asks you to show that card payments are handled compliantly, you can point them to three things:
- This page: a plain-language description of the tokenization architecture — where card data goes, and, more importantly, where it doesn't.
- Brippo's Attestation of Compliance (AOC): evidence that the payment infrastructure Brippo runs on is certified to PCI DSS Level 1. Request a copy from our support team.
- Your completed SAQ: the short questionnaire you fill in with your acquirer — which this whole design is built to keep simple.
Official PCI resources
Everything below comes straight from the PCI Security Standards Council — the authority on PCI DSS — so you can read the rules first-hand and give your bank primary sources.
PCI Security Standards Council
The official body behind PCI DSS. Start here for authoritative, vendor-neutral guidance.
Document Library
Download the PCI DSS standard, every Self-Assessment Questionnaire (including SAQ A), the PCI DSS Quick Reference Guide, and the "Protecting Telephone-based Payment Card Data" supplement.
Glossary of terms
Plain definitions for PAN, tokenization, SAQ, AOC and the rest of the PCI vocabulary.
PCI Perspectives
The Council's blog — news, practical guidance, and resources aimed at small businesses.
Talk to Brippo
Need the paperwork or a hand answering your bank's questions? Our team will help.

