Someoneâs on the phone wanting to pay. To take card payments over the phone in the UK, you need something called MOTO (mail order / telephone order), and it usually runs through a virtual terminal in your browser. Itâs the opposite of tapping a card on your handset, and mixing the two up costs people money. Hereâs how it works, what it really costs, and why a payment link is often the better answer.
TL;DR
- MOTO lets you key a customerâs card details into a virtual terminal when theyâre not stood in front of you. Itâs a permission on your merchant account, not a bit of kit.
- Card-not-present rates are typically higher, and if the payment turns out to be fraud, the money comes back off you. Thereâs no liability shift.
- Never write a card number or CVV down. Not on a pad, not in a spreadsheet, not in a text message.
- Pay by link does the same job with less risk and often a lower rate. Keep MOTO for the customers who wonât use a link.
- Not every provider enables MOTO on every account, so ask before you sign anything.
Tap to Pay is the opposite of this
Get this straight first. Itâs where most of the confusion lives. Tap to Pay on a phone, sometimes called SoftPOS, is a card-present payment: the customer is stood in front of you and taps their card or their watch on your handset. The chip does its job, the network sees a proper authentication, and if the card later turns out to be stolen, the loss usually sits with the issuer rather than with you.
Phone payments are the mirror image. The card is somewhere else, in someone elseâs hand, and youâre typing numbers theyâve read out to you. No chip, no PIN, nobody to look in the eye. The industry calls this card-not-present, and every difference in price and risk comes out of those three words.
So if what you want is a tap on your own phone with the customer stood there, thatâs a different setup and usually a cheaper one. Tap to Pay on your phone vs a card machine covers it. The rest of this page is about the other kind of payment.
What MOTO and a virtual terminal actually are
MOTO stands for mail order / telephone order. Itâs a permission your card provider adds to your merchant account, saying youâre allowed to charge a card the customer hasnât presented. Without it, keyed payments either get declined or get your account flagged for a look. You donât buy MOTO. Itâs a box that gets ticked during underwriting.
The virtual terminal is the thing you actually use. Itâs a web page inside your providerâs dashboard, so it works on a laptop in the office or in a browser on your phone in the van. You log in, type the long number, the expiry, the CVV and the billing address, then press charge. The card is debited while the customerâs still on the line, and the money settles into your bank on your usual timetable.
Plenty of card machines can be put into a keyed mode too, so you can do it on the terminal instead. Same transaction, same rate, same risk. Either way the account has to be set up for it first.
Why phone payments cost you more
Card-not-present transactions are typically priced higher than card-present ones. Thatâs not your provider being awkward. Interchange, the wholesale fee the card schemes set, is genuinely higher on keyed payments because more of them go wrong, and your provider passes that through.
How it shows up varies. Some providers quote one blended rate, then quietly apply a different, higher one to anything keyed. Others list card-not-present as its own line on the statement. A few charge a monthly fee for the virtual terminal on top of the transaction rate, which stings if you only use it twice a month.
Ask for the keyed rate in writing before you sign anything, and ask whether the virtual terminal carries a charge of its own. If a salesperson can only tell you the card-present rate, you havenât got a quote. Youâve got half of one. The hidden costs of card machines in the UK runs through the charges that tend to appear in month two rather than month one.
The fraud risk sits with you, not the bank
This is the part that catches people out. On a card-present payment the chip and the PIN do the authenticating, and thereâs a liability shift built into the rules: if the card was stolen, the issuer generally carries the loss. On a keyed payment there is no shift. The customerâs bank can pull the money back out of your account weeks later, and youâll usually pay a chargeback fee on top.
You canât win that dispute with a phone call you remember clearly. No PIN, no signature, nothing with the cardholderâs name on it. MOTO also sits outside the Strong Customer Authentication checks that apply to online card payments, which is part of why phone payments still work at all, and part of why the risk lands on your side.
So build a couple of habits. Take the billing postcode and house number every time so the address check runs, and always take the CVV. If something feels off (a brand new customer, an unusually big order, a delivery address that doesnât match the card) then slow down and ring them back on a number you found yourself. Most attempts fall apart right there.
Never write the card number down. Not once.
This is the one hard rule in the whole article. Card details go from the customerâs mouth into the virtual terminal while theyâre on the line, and nowhere else. Not on a pad. Not in a spreadsheet youâll tidy up later, not in a note on your phone, not in an email, never photographed, and not in a message to whoever does the books on Friday.
The CVV is the strictest bit. Under the card scheme rules youâre never allowed to store it after the payment, in any form, encrypted or otherwise. If you record your calls, you have to pause the recording while the details are read out, or the recording itself becomes a stored card number sat on someoneâs server.
PCI DSS is the standard covering all this. Itâs a contractual requirement from your card provider rather than UK law, which a lot of people hear as âoptionalâ. It isnât. Breaching it can mean fines passed down the chain to you, and in bad cases the merchant account gets closed. PCI DSS compliance for small businesses explains what you actually have to do, without the jargon.
Worked example: A B&B takes a card over the phone for a deposit and writes the number on the booking sheet to charge the balance nearer the date. Two weeks on, itâs in a folder behind reception. That business is storing a full card number and a CVV it was never allowed to keep. The fix costs nothing: take the deposit on a payment link, then send a second link for the balance when itâs due.
Pay by link is usually the better answer
For most of the businesses we set up, a payment link does the same job with less risk and often a lower rate. You generate the link in the same dashboard, text or email it over, and the customer types their own details into your providerâs hosted page. You never see the number. Nothing to write down, nothing to store.
The bigger win is 3-D Secure. Because the customer authenticates with their own bank on that page, the payment is treated much more like an online one, and in most cases the fraud liability shifts back to the card issuer. Thatâs the exact protection a keyed payment doesnât give you.
It isnât always practical, mind. Some customers havenât got a smartphone, and plenty wonât tap a link thatâs arrived by text, which is fair enough given how many scams work that way. Some are on a landline and want it done before they hang up. Sometimes youâre in a signal blackspot on site. And a trade customer who rings the same order in every Thursday wonât thank you for a fresh link each time.
The sensible setup for most people is both. Link first, MOTO for the ones who wonât use it.
Who genuinely needs MOTO
Deposits are the big one. A joiner wants money down before ordering the units, and he isnât driving back across town for it. Same for a holiday let taking the balance six weeks out, or a garage thatâs finished a job while the customerâs at work twenty miles away. The alternative is waiting on a bank transfer that may not land before you need to start.
Repeat account customers are the other real case. If the same handful of trade customers ring an order in every week, some providers can hold the card securely as a token on their side, so youâre authorising a payment rather than keying a number. Thatâs the safe version. What you must never do is keep the number yourself and call it a card on file.
Then thereâs the customer who simply will not use a link, and there are more of them than youâd think. Older customers especially, plus anyone whose bank has warned them off clicking things in texts. A payment they can hear you take is the one they trust. Donât argue with it.
Last one is the backup. If your terminal dies on a Saturday or the broadband drops, having MOTO already switched on means you can still take money from a browser on your phone. Some businesses keep it enabled purely for that and use it four times a year.
How to get it switched on, and what to check first
Ask your current provider before you assume youâve already got it. Not every provider offers MOTO on every account, and several of the app-based ones leave it off by default. It normally needs a short underwriting look: what you sell, roughly what share of your takings will be keyed, and your typical transaction size. Some trades get turned down flat.
If the answer is no, or the keyed rate is miles off, thatâs a switching conversation rather than an argument. Before you sign with anyone, get these in writing:
- The card-not-present rate as its own figure, separate from the card-present rate they led with.
- Whether the virtual terminal has a monthly fee, and whether pay by link is included or charged on top.
- The chargeback fee, and who does the dispute paperwork when one lands.
- Any cap on keyed payments, often written as a share of your monthly turnover.
- The term. Plenty of providers will do this on no long contract, so a three or five-year tie-in for what is essentially a web page isnât something you have to accept.
That last point matters more than a fraction of a percent on the rate, because itâs the thing that stops you moving when something better turns up. Card machines with no long contract covers who still sells them and what the catch tends to be.
FAQs
Is it legal to take card payments over the phone in the UK?
Yes. Telephone order payments have been around far longer than card machines have. Your provider has to enable MOTO on your account first, and the card scheme rules govern how you handle the details, which is a contract with your provider rather than UK law.
Can I just key the number into my existing card machine?
Sometimes. A lot of terminals have a keyed entry mode, but it has to be enabled on the merchant account behind it, and itâll be charged at the card-not-present rate. Other providers block it. Ring and ask rather than finding out on a declined payment.
Is it safe to take card details over the phone?
Safe enough if you key them straight in while the customerâs on the line and write nothing down. The risk you canât design away is fraud. The payment can be reversed weeks later and you carry it, which is why a link is the better default where the customer will use one.
Do I need a card machine at all?
No. A virtual terminal is a web page, so if nearly all your work is quoted and paid remotely you may never need hardware. Most businesses end up wanting both.
How long does it take to get MOTO added?
Depends on the provider and your trade. Some switch it on a day or two after the underwriting check, others want more detail about what you sell. Sort it before your busy season, not during.
