Storing Customer Cards Without Using a HirePOS Payment Provider
If you need to keep a customer's payment card on file but don't want to use one of HirePOS's integrated payment providers, you still have options.
The important part is making sure the card is stored securely and that you understand how you will use it later.
Why HirePOS doesn't store readable card details
Secure card storage is designed so that you don't need to see the full card number again after it has been entered.
Modern payment providers use tokenisation. The provider securely stores the actual card details and gives the system a token representing that card. The token can then be used for authorised future charges without exposing the card number to HirePOS or your staff.
This is why HirePOS does not provide a general-purpose field for storing readable credit card details.
Never store full card details in HirePOS notes, comments, custom fields, documents or other free-text areas. These areas are not designed for payment card storage. CVV/CVC security codes must also never be stored after authorisation.
If you don't want to use an integrated provider
First consider what you need to do with the card later.
Option 1: Use a separate secure payment provider
You can use a PCI-compliant payment provider separately from HirePOS to store the customer's card and process authorised charges when required.
For example, Stripe can currently be used independently of HirePOS. Customer cards can be securely stored within Stripe and later charged through the Stripe Dashboard. Your normal EFTPOS terminal can still be used for your everyday card-present transactions.
This can be a good option if you are happy with your existing EFTPOS arrangement and only need a separate facility for securely storing and occasionally charging customer cards.
Option 2: Talk to your existing EFTPOS or merchant provider
Your existing payment provider may have its own facility for securely storing customer cards and processing card-not-present transactions.
Ask them whether they support:
Tokenised or card-on-file storage
Card-not-present transactions using a stored card
Pre-authorisations or security holds, if required for your hire process
A secure customer-facing method of collecting the card details
If they provide these facilities, you may be able to keep your existing payment arrangement while managing stored cards through their system.
Option 3: If you need to retrieve the card number later
This is where your options become much more limited.
If your intended process is:
Store the customer's full card number → retrieve it later → manually key it into an EFTPOS terminal
then a normal tokenised card-storage solution will generally not provide that workflow. Hiding the full card number after storage is an intentional part of keeping it secure.
HirePOS does not provide a facility for storing retrievable raw card details.
If your payment process genuinely requires this, you will need to speak with your payment provider or another specialist provider about an appropriate PCI-compliant solution for storing and handling card information.
The simplest way to think about it
Your requirement | Your options |
|---|---|
Store a card and charge it later through HirePOS | Use a supported integrated payment provider |
Keep your existing EFTPOS but securely store and charge cards elsewhere | Use a separate PCI-compliant provider such as Stripe |
Keep everything with your existing EFTPOS/payment provider | Ask them about tokenised card storage and card-not-present payments |
Retrieve full card numbers later and manually enter them elsewhere | HirePOS cannot provide this. Discuss a compliant solution with your payment provider |
Keeping your existing HirePOS workflow
Choosing a separate card-storage solution doesn't mean you need to stop using HirePOS for the rest of your hire and payment workflow.
You can continue managing your customers, hires, invoices and payments in HirePOS while using an appropriate external provider for the secure storage and processing of customer cards.
The trade-off is simply that HirePOS won't be able to manage or charge those externally stored cards for you unless the provider is integrated with HirePOS.
Whichever approach you choose, make sure you have the customer's appropriate permission to store their card and to make any subsequent charges.
