Virtual Terminals: Taking Payments by Phone and Mail Safely
A virtual terminal is a secure, browser-based interface that lets you accept credit and debit card payments without a physical card reader. Instead of swiping or tapping, you manually key in the card details your customer provides over the phone, by mail, or by fax. If your business regularly takes phone payments or mail orders, a virtual terminal is often the simplest and most cost-effective tool for the job—no extra hardware required.
What Exactly Is a Virtual Terminal?
Think of it as a payment form that lives in your web browser. You log in through a secure merchant portal, enter the customer's card number, expiration date, CVV, and billing address, then submit the transaction. The payment processor handles authorization in real time, and you get an instant approval or decline—just like a countertop terminal would deliver, minus the physical card.
Because no card is physically present, these are classified as card-not-present (CNP) transactions. That distinction matters for both pricing and security, which we'll cover below.
What Is MOTO, and How Does It Relate?
MOTO stands for Mail Order / Telephone Order. It's an industry category that describes any transaction where the cardholder and their card are not physically present at the point of sale. MOTO has been around since long before the internet—catalog retailers and call centers have used it for decades.
A virtual terminal is the modern tool most merchants use to process MOTO payments. When you key in a card number a customer reads to you over the phone, that's a MOTO transaction processed through a virtual terminal. The two terms are closely linked, but they're not identical: MOTO describes the type of sale; the virtual terminal is the tool you use to complete it.
When Should Your Business Use a Virtual Terminal?
Virtual terminals make the most sense when a traditional card reader isn't practical. Common use cases include:
- Phone orders: Service businesses, restaurants, and retailers that take orders by call.
- Mail or fax orders: Any business that receives written order forms with card details.
- Remote invoicing: Collecting payment after you've sent an invoice, without requiring an online payment link.
- Backup processing: If your primary terminal goes down, a virtual terminal keeps you running from any computer.
- Field or office staff: Teams who need to charge clients from a laptop without carrying hardware.
If the vast majority of your sales happen in person with a card present, you probably don't need a virtual terminal as your primary solution. But even then, having one available as a backup is worth considering.
Understanding Keyed Transactions
Keyed transactions—where card data is typed in manually—carry a higher risk of fraud than swiped or chip transactions, simply because there's no way to verify the physical card exists. Payment processors account for this risk, which is why keyed transactions often come with slightly different pricing than card-present sales.
To reduce fraud exposure on keyed transactions, you should:
- Always collect the CVV (the three- or four-digit security code).
- Run an Address Verification Service (AVS) check, which compares the billing address the customer provides against what's on file with their bank.
- Be cautious with unusually large or rushed orders from new customers.
- Keep clear records of each transaction, including the customer's contact information.
MOTO and PCI Compliance: The Security Basics
Accepting keyed card data comes with real security responsibilities. The Payment Card Industry Data Security Standard (PCI DSS) applies to any merchant that handles cardholder data, and MOTO merchants have specific obligations worth understanding.
Key security practices for virtual terminal and MOTO processing:
- Never store raw card data. Writing a customer's card number on a notepad or saving it in a spreadsheet is a serious compliance violation. Use your processor's tokenization or vault features instead.
- Use a dedicated, secure device. Avoid processing payments on shared computers loaded with unrelated software or browser extensions.
- Access controls matter. Limit who on your team can log into the virtual terminal, and use unique logins for each user—never share credentials.
- Complete your SAQ. Most MOTO merchants qualify for a simplified PCI self-assessment questionnaire (typically SAQ C-VT), but you still need to complete it annually.
- Be careful on calls. Some businesses pause call recordings when a customer reads card numbers aloud, to avoid storing sensitive audio data.
Bottom line on PCI: Your payment processor's virtual terminal is built to be secure on their end—but your responsibility is to protect card data on your side of the transaction.
What to Look for in a Virtual Terminal
Not all virtual terminals are created equal. When evaluating options, look for:
- A clean, easy-to-use interface your staff can learn quickly
- Built-in AVS and CVV verification
- Tokenization or a secure customer vault for repeat billing
- Detailed reporting and transaction history
- Role-based access controls
- Integration with your existing accounting or CRM tools, if needed
Ready to Start Taking Phone Payments?
A virtual terminal is one of the most versatile tools in a merchant's payment toolkit—low friction, no extra hardware, and available from any browser. Whether you're processing a handful of phone orders a week or running a full mail-order operation, the right setup can make MOTO payments simple and secure.
If you'd like help finding the right virtual terminal solution for your business—and making sure your MOTO pricing and PCI setup make sense—reach out to our team for a free consultation. We'll walk you through your options with no pressure and no jargon.
Want your exact numbers?
Send us your last processing statement and we'll show you your true effective rate — and what you'd save — side by side.
Get a free statement analysis →