Payment Processing and PCI Compliance Reference

Why this reference exists

Field service businesses process millions of dollars in credit card payments. Many do so without understanding PCI compliance - the standards required by every credit card company (Visa, Mastercard, AmEx, Discover). A data breach can mean fines large enough to close the business outright. PCI compliance is straightforward when set up correctly + nearly impossible to fix after an incident.

What PCI compliance means

Payment Card Industry Data Security Standard (PCI DSS) = set of requirements for any business processing credit cards.

Three pillars:

  1. Card data not stored (in most cases - see exceptions below)
  2. Network security (firewalls, antivirus, encryption)
  3. Compliance documentation (annual self-assessment OR external audit)

Most small service businesses qualify for "merchant level 4" - simplest tier.

Merchant levels

Level Annual transactions Requirements
1 6M+ Quarterly external scan + annual on-site audit
2 1-6M Annual self-assessment + quarterly scan
3 20K-1M ecommerce Annual self-assessment + quarterly scan
4 < 20K ecommerce OR < 1M offline Annual self-assessment only

Most field service businesses: Level 4 (offline + low ecommerce). Annual self-assessment via processor portal; that's it.

Self-Assessment Questionnaire (SAQ)

For Level 4 merchants using a payment processor's POS:

  • SAQ A (web ecommerce): processor handles all card data; you collect nothing
  • SAQ A-EP (hosted payment with redirect): similar; you redirect to processor
  • SAQ B (terminal-only): chip card reader; no card data on your network
  • SAQ B-IP (terminal connected to network): chip card reader on your network
  • SAQ C (POS system): customer-facing POS with card data on network
  • SAQ D (other): comprehensive; service businesses storing cards (rare + risky)

Most field service businesses: SAQ B-IP or SAQ C depending on POS architecture.

Filling SAQ takes 30-90 minutes annually. Processor portal walks through it.

Card processing options

Mobile card reader (SAQ B-IP):

  • Bluetooth-paired reader (Square, Stripe Terminal, ServiceTitan Pay)
  • Chip + tap + magstripe
  • Customer-facing or tech-facing
  • 2.5-3.5% per transaction processing fee

Tablet + reader POS:

  • iPad / Android with reader attached
  • More flexibility (estimate, invoice, take signature)
  • ServiceTitan, Housecall Pro, Jobber all have integrated options
  • hardware + software subscription

Phone-based (NFC tap):

  • Square Reader, Stripe Tap to Pay
  • Customer phone taps tech phone
  • No separate hardware
  • Newer + growing

Web-based (estimate-to-pay link):

  • Email or text customer a payment link
  • Customer enters card on their own device
  • SAQ A scope (lowest compliance burden)
  • Growing popular for one-time service-call payments

For most modern service business: combine mobile reader (in-person) + web link (remote/late payment).

Common PCI violations

Storing card data:

  • Writing card number on paper invoice
  • Saving in customer database (NEVER)
  • Email with full card number (don't do this)
  • Verbal recording of card number

Storing CVV:

  • ANY storage of CVV is PCI violation (even encrypted)

Unsecured Wi-Fi:

  • Open Wi-Fi at customer site exposes data
  • VPN OR cellular data preferred for processing
  • Network firewall + antivirus required

Outdated terminals:

  • Pre-EMV terminals (post-2015 deadline)
  • Pre-PCI-PTS 3.0 (security standards)
  • Most modern POS compliant; older equipment not

Untrained crew:

  • Crew taking cards by phone (over voice) and writing down
  • Verbal CVV captured
  • No policy or training

Service trade specifics

In-home service:

  • Tech with mobile reader
  • Customer card processed at point-of-service
  • Compliance: SAQ B-IP typical
  • Customer's home Wi-Fi NOT secure for processing; use cellular + reader

Phone payments:

  • Customer calls in card information
  • Office writes down (PCI VIOLATION!) OR processes via portal at time of call
  • BEST: use processor's pay-by-phone OR email payment link

Recurring charges (maintenance contracts, financing):

  • Tokenize card with processor (not store)
  • Processor stores; you reference a token
  • PCI compliance maintained

Invoicing:

  • Email or text payment link
  • Customer enters card on processor-hosted page
  • You see "paid" status; never see card data
  • SAQ A scope

Payment processors

Square: simplest, mobile-first, no monthly fee (transaction fees apply). Best for very small + new businesses.

Stripe: developer-friendly, web payments, scaling. Mobile reader available. 2.7-2.9% + 30ยข per transaction.

PayPal / Venmo Business: smaller scale; not preferred for large service tickets.

ServiceTitan Payments (integrated with ServiceTitan POS): convenience trade-off for fee. Best for ServiceTitan users.

Housecall Pro Payments: similar integration.

TSYS, Worldpay, First Data: traditional commercial processors. Lower fees at higher volume but harder setup.

For most field service: Stripe + integrated POS (ServiceTitan, Housecall Pro, Jobber) OR Square for simpler operations.

Fees + costs

Transaction fees typical:

  • 2.5-2.9% +/dip
  • 3.0-3.5% for keyed (card-not-present) entries
  • 1.5-2.5% for ACH / bank transfer
  • 0% for cash

Monthly: typically no monthly fees at Square + similar simple processors. Traditional processors: + fees per transaction.

Annual: PCI compliance fees from some processors; built-in for others.

Hardware: for reader + tablet/POS combo.

Customer-side preferences

Customers want:

  • Tap (NFC) preferred for speed + security
  • Chip dip preferred over magstripe
  • ACH for large amounts (less fee, security)
  • Apple Pay / Google Pay / Samsung Pay all NFC
  • Pay-on-web link if not paying in person

Magstripe declining (most cards have chip + tap).

Best practices

For PCI compliance + customer experience:

  1. Use a processor with PCI compliance support: they walk you through annually
  2. Modern POS hardware: EMV chip + NFC tap reader
  3. Never write card numbers: not on paper, not in CRM notes
  4. Encrypt Wi-Fi: if processing at site
  5. Use cellular data + reader: even better than Wi-Fi
  6. Tokenize for recurring: never store card directly
  7. Train crew: brief PCI awareness annually
  8. Email payment links: for remote / late payments; lowest PCI scope
  9. Annual self-assessment: complete promptly

Common pitfalls

Assuming the processor makes you compliant. The processor is compliant for the parts it handles. Your people, your phones, your office network, and your paperwork are still your scope. Nobody will tell you otherwise until there is an incident.

Never finishing the annual SAQ. Many processors charge a monthly non-compliance fee until the questionnaire is filed, and most merchants never notice it on the statement. It is the cheapest money you will ever recover: log into the portal, complete it, and calendar it for the same month every year.

Card numbers living in the CRM. Not in the "notes" field, not in a job comment, not in a task reminder to charge them Friday. Once a number is typed into a system that gets backed up, exported, and read by every user, you have created storage you cannot audit. Use the processor's tokenized card-on-file instead, which stores a reference you can charge but nobody can read.

Card photos in the job photo gallery. Techs photograph a card to key it in later. That image syncs to a phone gallery, a cloud account, and the job record. Same violation as writing it down, with wider distribution.

Taking the number over the phone and writing it on a sticky note. Even if it goes in the shredder five minutes later, it existed unprotected, and CVV must never be recorded at all. Send a payment link or key it directly into the processor portal while the customer is on the line.

Processing on the customer's Wi-Fi. Free network, unknown configuration, unknown other devices. Use cellular data with the reader, and turn Wi-Fi off on the work tablet so it does not join an open network on its own.

Shared logins to the processor portal. One password everyone knows means no audit trail and no way to cut off a departed employee. Individual accounts, and removal on the day someone leaves.

Personal payment apps for company work. A tech collecting on a personal peer-to-peer app is outside the merchant account entirely: no chargeback protection, no records, a tax problem, and a theft risk for the business.

No documentation when a chargeback lands. Signature, work order, before-and-after photos, and time stamps are what wins a dispute. Businesses that keep them win most chargebacks; businesses that do not lose almost all of them.

Surcharging without checking the rules. Adding a card fee is regulated by state law and by card network rules, including disclosure and cap requirements. Check before adding a line item, not after a complaint.

Old terminals left in service. A reader in a retired truck or a back-office drawer is still enrolled and still a liability. Decommission and deregister hardware when it comes out of rotation.

References

  • PCI Security Standards Council (pcisecuritystandards.org)
  • PCI DSS v4.0 documentation
  • Federal Trade Commission data security guidance
  • Card network security standards (Visa, Mastercard, AmEx, Discover)
  • Processor compliance support documentation
  • Manuall internal: Service Fleet Management Reference, Customer Financing Options Reference