Skip to main content

PCI Compliance and Credit Card Collection

Training BLVD avatar
Written by Training BLVD
Updated over a week ago

Why are we doing this?

Collecting credit card information through non-compliant forms poses security risks, including fraud and data breaches. Additionally, it violates PCI compliance and our terms of service. To protect our customers and their clients, we are implementing necessary changes to ensure compliance with industry standards.

What’s Changing?

On February 11th, 2025, any credit card data collected in non-compliant forms will be permanently deleted. Forms that continue to collect this information will be disabled. Any net new forms that are built with credit card collection fields will see a warning informing customers that any credit card information will not be stored. To avoid disruptions, businesses should transition to PCI-compliant methods for handling payment information.

Alternative Ways to Collect and Store Credit Card Information

Collect Credit Card Information Over the Phone:

  • Staff can collect credit card details directly from customers over the phone and immediately input them into the "Cards on File" section of their client profile to ensure secure storage. To do this:

    • Go to the Client tab from the Boulevard dashboard

    • Find the client and open their profile

    • Select Payment Methods from the top navigation

    • Scroll down to the Cards on file section and click Add a credit card

    • Enter the credit card details and click Add to securely save the card on file

Use the Self-Booking Overlay for Booking and Payment:

  • If a client calls in to book an appointment but is hesitant to provide their credit card information over the phone, you can send them a direct link to book online securely. To find the direct link:

    • Go to the Manage tab from your Boulevard dashboard

    • Click Services from the left menu

    • Select the service you want to send a link for

    • Under Direct links for online booking change the Sharing Options to Link to this Service via external site and click Copy Link

    • Send the link to your client, allowing them to book the service securely online

    • Click here to learn more

Adding Secure Link to Self-Booking Overlay

  • If you need to securely collect credit card information from clients who are hesitant to provide it over the phone, you can send them a direct booking link. This secure link allows clients to enter their payment details online with confidence, ensuring their information is protected and processed safely.

    • Go to the Manage Business tab from your Boulevard dashboard

    • Click Services from the left menu

    • Create a new service category titled "🔓 Secure Credit Card Portal"

    • Create a new service titled “Credit Card/Debit Card on File” with a description outlining the purpose

    • Set the service price to $0 and modify the duration to 5 minutes

    • Create a new staff role and staff member titled Front Desk as the professional and ensure the staff is enabled to perform services for client

    • Go to the Manage tab from your Boulevard dashboard

    • Click Services from the left menu

    • Select the “🔓Secure Credit Card Portal” service

    • Enable the Front Desk staff role created to perform the service

    • Click Schedule from the menu

    • Create a schedule for the front desk staff assigned to the service

    • Once the service is created and staff has been assigned, clients can securely leave a credit or debit card on file using the self-booking overlay

NOTE: Owners and managers will need to provide the front desk with this link, as the front desk does not have access to the Manage tab. We recommend saving the link somewhere easily accessible on their desktop for quick copying.

FAQs

Q: Why can’t I collect credit card information through my forms anymore?

A: Collecting credit card information in forms that are not PCI-compliant exposes sensitive client data to security risks, including fraud and data breaches. Additionally, it violates PCI compliance and our terms of service.

Q: What happens if I don’t remove the credit card fields from my forms?

A: Any credit card data collected in non-compliant forms will be permanently deleted on February 11th, 2025. Additionally, any forms that collect this information will be disabled. Any information collected through new forms will not be stored.

Q: Can I still store client credit card details for future use?

A: Yes! The best way to store credit card information securely is by using the Cards on file section in your client’s profile.

Q: What are the consequences of not being PCI-compliant?

A: Non-compliance can lead to security breaches, financial penalties, and loss of payment processing capabilities.

Did this answer your question?