Billing

PCI compliance for a small ride company: card numbers by phone, paper card forms, and which SAQ you file

Updated 8 min read

Overview

A small ride company validates PCI compliance with a self-assessment questionnaire (SAQ) that its card processor assigns. Riders who type cards into a hosted payment page fit SAQ A. A dispatcher who keys phone card numbers into a processor's virtual terminal on an isolated computer fits SAQ C-VT. Recorded calls, texted numbers, or card numbers kept in files can move the office to SAQ D, the longest questionnaire.

On this page

A small ride company proves PCI compliance by completing a self-assessment questionnaire (SAQ) for its card processor, and the questionnaire depends on how card numbers reach the office. A rider who types a card into a hosted payment page fits SAQ A. A dispatcher who keys a number from a phone call into a processor’s website can fit SAQ C-VT. Card numbers in call recordings, texts, notes, or spreadsheets can move the office to SAQ D, the catch-all form. The guide to charging private-pay riders by card covers authorizations, deposits, and chargebacks. This page covers the card data itself.

Who decides which PCI form a ride company files?

Your card processor decides, working from the card brands’ rules. The PCI Security Standards Council writes the Payment Card Industry Data Security Standard (PCI DSS) and the questionnaires, but its January 2025 notice on SAQ A says the council does not set who has to validate. That is left to the card brands, acquirers, and payment facilitators, and it tells businesses to ask them which tools they may use. Visa’s own page says Visa manages enforcement and validation, that a merchant’s total Visa volume over 12 months sets its merchant level, and that acquirers must make sure merchants validate at the right level.

PCI DSS v4.0.1 is the version in force. The requirements marked as best practice until March 31, 2025 have been mandatory since that date. The council opened a feedback period on v4.0.1 from June 3 to July 20, 2026 as it starts work on the next version, so the questions below still apply.

A compliant processor does not make you compliant. The questionnaires say that using a compliant third-party provider does not remove your responsibility for your own compliance. They also ask you to keep a list of every provider that touches card data and a written agreement with each one.

Which SAQ fits a ride company?

Most ride companies land on SAQ A, SAQ C-VT, SAQ P2PE, or SAQ D, depending on how the card number arrives.

How card numbers reach youQuestionnaireWhat the form assumes
Rider enters the card on a hosted payment page or pay linkSAQ AYou never store, process, or transmit card data electronically
Dispatcher keys the number into the processor’s web terminalSAQ C-VTOne isolated computer, no card reader, no storage software
Dispatcher keys the number into a validated encrypting terminalSAQ P2PEOnly the terminal ever sees the clear-text number
Numbers kept in files, recordings, texts, or on a shared networkSAQ DAnything that fits no other form

SAQ A is for businesses that outsource every card function to a compliant processor and keep only paper reports or receipts. It covers e-commerce and mail or telephone order, and it does not cover face-to-face sales. Since the January 2025 edition, which took effect March 31, 2025, a company that embeds its processor’s payment form in its own website must also confirm that the site is not open to attacks from scripts.

SAQ C-VT is the form for a dispatcher who keys one transaction at a time into a processor’s website. Its eligibility list comes down to four conditions:

  • The virtual terminal is your only way of taking cards. It is provided and hosted by a compliant provider and reached through a web browser.
  • The computer is isolated. It is not connected to other locations or systems, which a firewall or network segmentation can achieve.
  • The computer holds nothing extra. No software that stores card data, and no attached card reader.
  • No other copy exists electronically. Any card data you keep is on paper, and the paper was not received electronically.

SAQ P2PE describes a telephone order business that keys the number only into a terminal from a validated, PCI-listed point-to-point encryption solution. SAQ B covers imprint machines and standalone dial-out terminals that connect to nothing else. SAQ D is for every business that meets no other form’s criteria, including one that stores cardholder data electronically.

Do card numbers taken over the phone put the whole office in scope?

Not the whole office, only the systems the card number passes through plus anything connected to them, so the goal is a short path. The council’s telephone guidance, Protecting Telephone-Based Payment Card Data (version 3.0, November 2018), follows the number to decide what is in scope. It describes a simple setup first. On a single traditional phone line, an entity is generally not responsible for card data spoken over the outside line, and the connection to the processor over the public phone network is generally out of scope. If an answering machine captures the number, or the person answering writes it down, that counts as storage and brings the entity’s own processes into scope. Where the office uses internet phones, its own systems and networks that carry the call are in scope.

In its larger call-center example, the spoken number enters the phone system, travels across the office’s network to the agent, gets keyed into the processor’s virtual terminal, and is then captured and stored by the call recorder. Every system in that path is in scope, because each has the potential to store, process, or transmit card data.

Two habits keep the path short:

  • Keep the dispatcher’s payment computer single-purpose. The council’s small merchant guide says not to browse the web or check email or social media on the device used for payments, and not to attach a card reader to a computer that runs a virtual terminal.
  • Never type a number anywhere else. A trip note, a spreadsheet, or an email stores it electronically, which the C-VT eligibility list rules out.

What happens when you record calls?

A recording that captures a spoken card number is stored card data, and the security code can never be kept. In the council’s call flow, the recorder captures the account data and stores it. The rule against keeping the security code after authorization applies even when the data is encrypted, and in a phone environment the code counts whenever it is taken during a call. The supplement tells every entity other than a card issuer to make every possible effort to remove the code from the telephone environment. It adds that even with encryption in place, an entity should not store the code after authorization.

Pause-and-resume is the common fix. The recording stops while the caller reads the card and restarts once the payment data has been sent. The supplement describes two kinds:

  • Manual. The dispatcher pauses and restarts the recording by hand. It depends on remembering at exactly the right moment, and the supplement says the entity needs constant monitoring, including supervisors regularly listening to recorded calls to confirm no card data got through.
  • Automated. The recording pauses when the dispatcher opens a payment screen or clicks a payment field. The council points entities toward removing codes automatically, with no step left to staff.

A working pause-and-resume tool can take the recorder and its storage out of scope. It does not take the dispatcher’s computer or the rest of the phone environment out of scope. Consent rules for recording are a separate question, covered in the phone system guide.

How should paper card forms and texted card numbers be handled?

Keep paper locked, destroy it when it is no longer needed, and do not take card numbers by text or email. For paper, the questionnaires apply requirements 9.4.1 to 9.4.6 to any office that stores it. The SAQ’s completion guidance describes meeting them by keeping the paper in a locked drawer, cabinet, or safe, destroying it when it is no longer needed for business purposes, and writing a policy so employees know how. Paper is destroyed by cross-cut shredding, incineration, or pulping, and held in secure containers until then. The council’s small merchant guide gives a rule for a form you must keep: mark through the card data with a thick black marker until it is unreadable, then lock the paper in a drawer or safe that few people can open.

The security code never belongs on a form you keep. FAQ 1280 (October 2023) bars keeping it once the purchase is authorized, even encrypted and even with the customer’s permission, and the credit card authorization form leaves the field off for that reason.

For texts and email, requirement 4.2.2 says a card number must be protected with strong cryptography whenever it is sent through end-user messaging such as email, text, or chat. When a number arrives unsolicited through a channel that was not meant for card data, the requirement’s notes let the office choose between two paths. It can bring the channel into its PCI scope and secure it, or it can delete the number and put measures in place so the channel is not used for card data. The guide’s advice for email is the practical one: process the payment, delete the message, do not reply with the card details, and tell the sender you prefer another route, such as the phone, fax, or mail.

What does a PCI non-compliance fee mean?

It is your processor passing a cost to you, and the amount and triggers are whatever your merchant agreement says. Visa states that when a merchant or service provider does not comply with PCI DSS or fails to fix a security issue, Visa may assess the acquirer. The acquirer pays and may not represent that Visa imposed the assessment on the merchant. Visa may waive the assessment when a forensic investigation after a breach finds no sign of non-compliance before or at the time of the breach.

Do these five things this week:

  1. Ask your processor which SAQ it expects, when it is due, and where to submit it.
  2. Pick the route card numbers will take, such as a pay link, a virtual terminal, or an encrypting terminal, and stop every other route.
  3. Find out whether your phone system records calls and how the payment part of a call is handled.
  4. Lock up or shred paper card forms, and write a short policy for staff.
  5. List every provider that touches card data and keep each agreement.

Taking cards in HealthRide

HealthRide lets riders and facilities pay by card through a secure card processor, using a payment link, a QR code, or a saved card, so a dispatcher does not have to take a card number over the phone. Checks and cash recorded by your office land in the same ledger as card payments. See payments.

Frequently asked questions

Does PCI apply to a ride company that takes only a few card payments a week?
Yes. Visa says PCI DSS compliance is required of every entity that stores, processes, or transmits Visa cardholder data, and that merchant level, which sets the validation required, comes from total Visa volume over 12 months. A small ride company usually completes a short self-assessment questionnaire, but your processor tells you which one and when it is due.
Which SAQ does a ride company use if the dispatcher takes card numbers by phone?
SAQ C-VT fits when the dispatcher keys one transaction at a time into a processor's web virtual terminal on a computer used for nothing else, with no card reader, no software that stores card data, and no other electronic copy of the number. If the office uses a validated point-to-point encryption terminal instead, SAQ P2PE is the match.
Can I store a card's security code after the ride is paid?
No. A card verification code has to be discarded once the charge it was collected for is authorized, and PCI rules say that holds whether or not the code is encrypted and whether or not the customer agrees. Take the code when you run the card, and leave it off any form you keep.
Does recording phone calls break PCI rules?
It does when the recording captures a spoken card number, because the recording becomes stored account data. The security code can never be kept after authorization. The usual fix is to pause the recording while the caller reads the card, and the PCI Council says an automatic pause is safer than relying on staff to remember.
Can a family text me a card number?
Avoid it. PCI DSS requires strong cryptography whenever a card number is sent through end-user messaging such as text, email, or chat. If a number arrives unsolicited, the office can bring that channel into its PCI review and secure it, or delete the number and stop the channel from being used for cards.
Does using a PCI-compliant processor make my company compliant?
No. The questionnaires state that using a compliant third-party provider does not make an entity compliant or remove its responsibility for its own compliance. They also ask you to list every provider that touches card data and to keep a written agreement with each one.
What is a PCI non-compliance fee?
It is a charge your processor adds under its own merchant agreement when you have not filed the questionnaire it expects. Visa's assessment lands on the processor, which pays it and may not tell the merchant that Visa imposed it, so the merchant agreement decides whether and how you are charged. Read the fee clause and file the SAQ it names.

Official resources

HealthRide plans the whole day in one click and bills every ride.