Skip to main content

Is Method Pay PCI compliant?

How card and bank details are protected, what Method stores, and what it means for your own PCI obligations.

Method Pay uses PCI Level 1 certified payment infrastructure to collect, transmit, tokenize, and store sensitive payment information. Because that data is handled by the payment infrastructure rather than stored in Method's CRM database, your PCI scope is reduced, although not eliminated.


Where sensitive payment data actually lives

When credit card or bank details are entered, whether it be in the customer portal, or on an invoice payment page, that information is collected by a secure embedded payment component.

Those details go directly to PCI Level 1 certified payment infrastructure. They are not written into Method's CRM database. What comes back to Method is a tokenized payment reference: a secure ID that stands in for the payment method.


What Method stores, and what it doesn't

Method Pay stores

Method Pay does not store

Tokenized payment method reference

Full card number (PAN)

Card brand, last four digits, expiration date

CVC / security code

Transaction metadata (payment ID, authorization ID, processor reference)

Raw card data

Payment status (paid, failed, refunded, disputed)

Full bank account credentials

Invoice and payment relationship

Deposit and reconciliation data

Audit trail — who initiated the payment, when, and the result

CVC is required on every card transaction, but it is not retained after authorization.


How saved payment methods work without stored card numbers

This is the question that usually follows: if Method doesn't have the card number, how can it charge a saved card next month?

Think of it like a coat check. Method Pay holds the ticket, not the coat. The secure payment environment holds the sensitive details; Method Pay presents the token when an authorized payment needs to be processed.

The token is useless on its own. It isn't the card number and can't be used outside your Method Pay account.


What this means for your PCI obligations

Businesses using Method Pay through the embedded payment experience generally have a lighter PCI validation requirement, because they aren't directly storing or handling raw cardholder data.

That said, your exact requirement depends on your own circumstances, including:

  • Your transaction volume

  • The payment methods you accept

  • Whether any other system in your business collects, transmits, or stores cardholder data

If your team still writes card numbers on paper order forms, keys them into a separate terminal, or stores them in another application, those practices remain in scope regardless of how Method Pay works.

📌 Note: Method Pay reduces PCI scope; it does not remove your responsibility to handle payment data safely elsewhere in your business. If you need formal guidance for an audit or a customer security review, contact your Platform Success Manager.


Who can see card details

No one in your business, and no one in Method, can view a full card number or CVC through Method Pay.

Users see only what's needed to do their job: card brand, last four digits, expiration date, and payment status, alongside the transaction ID, invoice number, amount, and reconciliation status.


Common questions

Does Method Pay store my customer's credit card number? No. Full card numbers and CVC values are not stored in Method's CRM database. Method Pay stores a tokenized reference plus limited display details such as brand, last four digits, and expiration date.

Is saved payment information secure? Yes. Saved payment methods are represented by tokenized references. The sensitive credentials stay in the secure payment environment.

Can Method employees retrieve a card number for me? No. Full card numbers and CVC values are not exposed to Method employees. If a card needs to be re-entered, the customer or your team enters it again through the secure payment component.

We're migrating from another processor. Can our existing card data be imported? Card details can be migrated, but CVC must be re-collected — there is no CVC bypass in Method. Speak with your Platform Success Manager about the best path for your account.

Did this answer your question?