← All articles

Protecting customer card data in a small store

Protecting customer card data in a small store

A regular calls in an order and reads their card number over the phone. The clerk writes it on the notepad by the register to run later, and the page stays there all week. Card data security in a small business is mostly about handling, not hacking: keep numbers off paper, run equipment that encrypts at the reader, control your passwords, and check the reader for tampering. Those habits close off most of the realistic risk.

That notepad, by the way, is now the least secure thing in the store. Not the safe, not the back door. The notepad.

Where do small stores actually get burned?

Not by movie hackers. The realistic failure list is short: card numbers written on paper or typed into a notes file, terminals too old to encrypt properly, one password shared by everyone since the store opened, and physical tampering with the reader itself. All four are cheap to fix.

Paper first. A card number in handwriting has no protection at all, no encryption, no audit trail, no way to know who read it. If phone orders are part of your business, ask your processor about tools built for that job, which keep the number tokenized inside secured systems instead of sitting next to the tape dispenser.

Old equipment next. A modern reader scrambles card data the instant a card is dipped or tapped, so nothing readable ever exists in your store. A terminal from a decade ago may not. If you don't know which kind you have, that's the first phone call to make. You can compare it against the current card readers and terminals NRS Pay offers.

How do you spot a skimmer on your card reader?

A skimmer is a device a criminal attaches to a card reader to copy card data, sometimes an overlay that looks like part of the machine. The defense isn't gadgetry. It's familiarity. You look at that reader every day; a skimmer has to change something, and the person most likely to notice is you.

Make these part of the routine:

  • Glance at the reader every morning and know what normal looks like.
  • Give any protruding part a gentle wiggle; factory parts don't shift.
  • Check that security seals or screws haven't been disturbed.
  • Keep the reader in sight of staff and cameras, not in a blind corner.
  • If someone arrives unannounced to "service" the terminal, call your processor's real number before letting them touch anything.

That last one matters more than people expect. A clipboard and a confident walk get people surprisingly far.

What about Wi-Fi, passwords, and the back office?

If you offer customer Wi-Fi, keep it separate from the network your payment equipment uses. Change the default password on your router the day it comes out of the box, and do the same for any back-office system. Give each employee who touches settings their own login, so you can tell who did what, and shut off access the day someone leaves.

None of this is exotic. It's the digital version of not leaving the register drawer open.

One more habit: never build your own records of card numbers. No spreadsheet of regulars' cards, no photos of a card "just for this order." If a tool didn't come from your processor, card numbers don't belong in it.

This is general guidance, not a compliance program. For your store's specific obligations, consult your processor and the PCI standards, and if you want a second pair of eyes on your setup, the NRS Pay team answers seven days a week.

Frequently asked questions

Can I keep a regular customer's card number on file?

Not on paper and not in a spreadsheet. If regulars want to pay without presenting the card each time, ask your processor about stored-credential tools designed for that, which keep the number tokenized in secured systems your store never has to protect on its own.

What should I do if I find a skimmer?

Take that reader out of service immediately and stop running cards on it. Contact your processor, then report it to local police. Try not to handle the device more than necessary. Your processor can advise on next steps and get replacement equipment moving.

Are old paper receipts a card data risk?

Less than they used to be, since modern receipts truncate the card number to the last few digits. Merchant copies still pile up, though. Keep them somewhere customers can't reach, and shred them once your record-keeping window has passed. Ask your processor how long to retain them.

Not sure whether your current reader encrypts at the swipe? Ask the NRS Pay team to check with you.