Pay by Link: why secure payment links matter more than ever

When customers read their card details aloud, who’s listening?

For decades, taking a card payment over the phone has followed a familiar routine. The customer gets their card out, reads the numbers aloud and an agent processes the payment.

But think about what happens in those few seconds. A customer is voluntarily sharing sensitive financial information with another person. What happens to those details once they’ve been spoken?

To this day, bad actors in contact centres record card holder data for fraudulent purposes. While instances like these are rare, it exposes an important issue with handing over card information. 

For any organisation still taking card details verbally, it’s an uncomfortable reminder of why payment security can’t stop at the technology.

When card details enter the conversation, the risk steps up

Businesses have invested heavily in PCI DSS compliance, encryption, tokenisation, secure payment gateways and fraud prevention. Contact centres can also use technologies such as DTMF masking (Dual-Tone Multi-Frequency) and tone suppression to prevent sensitive card information reaching agents or appearing in call recordings.

Contact centres can introduce policies and training around the handling of payment information, but these measures only go so far. If agents can hear, see or record customers’ card details during a transaction, sensitive information is still being exposed.

Do agents need access to card details at all? Not necessarily. And that’s where PaybyLink provides an alternative.

What is PaybyLink?

PaybyLink, also commonly described as a payment link, allows a business to send a customer a secure route to an online payment page.

The customer receives a link, typically by SMS or email, opens it on their own device and completes the transaction without needing to read their card details aloud.

It sounds like a small change, but it fundamentally changes the flow of sensitive information.

Instead of the customer passing card details to an agent who then processes the transaction, the customer enters their payment information directly into a secure payment environment.

The agent can continue helping the customer without needing access to their card details.

A better fit for modern contact centres

Consider a customer calling about an outstanding utility bill.

They have a question about the amount, so they speak to an agent. The issue is resolved and the customer says, “Can I pay it now?”

Traditionally, the customer might be asked for their card details, transferred to an automated payment service or told to visit the company’s website.

A secure payment link creates another option. The agent can send a payment request while the customer is still on the call. The customer opens it and completes the transaction on their own device.

There’s no need to search for the right webpage or start the journey again. More importantly, the agent doesn’t need to see or hear the customer’s card information. And the sensitive part of the transaction moves into a more appropriate and secure environment.

Payment links reflect a wider change in customer behaviour

Customers now move between phone calls, websites, apps, SMS and email as part of the same relationship with a business. They don’t think in terms of “payment channels”. They simply want a convenient way to pay when they’re ready.

A business could use a payment link to collect an outstanding balance, request a deposit, take payment following a customer service conversation or give someone another route to pay when their original journey hasn’t worked.

This is where PaybyLink for businesses becomes part of a wider omnichannel payment strategy.

Are payment links secure?

Not all payment links or payment journeys are created equal.

Businesses should consider what happens after a customer taps the link. Where is payment information entered? Can an agent access it? Does card data touch the organisation’s systems? Is the payment page protected by appropriate security measures? Can a link be reused?

PCI DSS compliance also matters. Reducing the number of people, systems and processes exposed to cardholder data can help businesses reduce their PCI DSS scope and the risks associated with handling sensitive payment information.

Customer trust is just as important. With phishing and payment scams commonplace, businesses need clear, recognisable payment communications rather than training customers to click unexpected links without thinking.

A payment journey should be easy, but it also needs to feel safe.

From payment link to payment choice

Once a customer moves into a secure digital checkout, there’s another opportunity: choice.

Encoded’s PayByLink can work alongside its Payment Gateway to support traditional debit and credit cards as well as digital payment methods including Apple Pay, Google Pay, Samsung Pay and Visa Click to Pay.

That means a payment link doesn’t have to be a digital copy of a telephone card transaction. It can become an entry point into a broader checkout experience where customers choose how they want to pay.

For businesses handling payments across contact centres and digital channels, that’s an important distinction.

Does card information need to enter the conversation at all?

Payment innovation often focuses on big shifts such as digital wallets, biometrics, tokenisation and the move towards a future where customers may no longer need to enter long card numbers.

Pay by Link solves a much more immediate problem.

A customer wants to pay. They’re already talking to the business. They need a secure and convenient way to complete the transaction.

They shouldn’t necessarily have to read 16 card digits, an expiry date and a security code aloud to do it.

Sometimes the simplest way to protect card information is to make sure it never enters the conversation in the first place.

Find out more about Encoded PayByLink and secure payment links for your customer journeys.

 

Your checkout could be costing you more than you think

Your checkout could be costing you more than you think

Most businesses know exactly how much it costs to get someone onto their website. They track their website metrics, cost per click, cost per acquisition and return on ad spend with precision. Every campaign is carefully optimised to attract more of the right customers. Then the customer reaches the checkout.

read more
Your checkout could be costing you more than you think

Your checkout could be costing you more than you think

Most businesses know exactly how much it costs to get someone onto their website. They track their website metrics, cost per click, cost per acquisition and return on ad spend with precision. Every campaign is carefully optimised to attract more of the right customers. Then the customer reaches the checkout.

read more