How to Send Credit Card Details Securely
Usually the right answer is not to send them at all — use a payment link or a virtual card. When you really must hand over a card number: what never to do, and how to split it.
Most of the time, the secure way to send credit card details is: don’t. Almost every situation that seems to need it has a better route, and the better route is usually also less work.
So this guide is in two parts — how to avoid sending the card at all, and how to do it properly on the occasions when you must.
First: do you need to send it?
Paying a business. Ask for a payment link or an online invoice. Stripe, Square, PayPal and every serious invoicing tool produce one in seconds; you type the card into the processor’s page, and the business never handles the number. If a company insists on a card number by email, that tells you something about how they will store it.
Businesses have a reason to agree: the card industry’s security standard (PCI DSS) says full card numbers must never be sent over ordinary email, chat or SMS unprotected, and any system that stores them falls under audit. A payment link takes them out of that scope.
Paying over the phone. Reading the number aloud to a merchant you called is a normal, accepted channel — nothing is written down on your side. Call the number on their website, not one from a message.
Letting someone else spend on your behalf — a partner, an assistant, a contractor buying materials:
- an authorised user card in their own name, or
- a virtual card number from your bank or card provider, with its own limit and expiry, that you can cancel without touching the real card, or
- Apple Pay / Google Pay on a shared family set-up.
A leaked virtual number costs you a tap to cancel. A leaked real card costs you a new card and a week of failed subscriptions.
When you really must send it
A relative booking a flight for you tonight. An assistant paying a supplier who only takes cards by phone. A client’s card on file for a one-off purchase.
What never to do
- Email — it is permanent, searchable and in more places than you think.
- SMS — unencrypted, and often mirrored to laptops and tablets.
- A photo of the card — photo libraries sync to the cloud, and both phones now index the text in images. Malware that scans photo libraries for card numbers and wallet phrases is real.
- Everything in one message. Number, expiry, security code, name and billing postcode together are a complete payment credential.
What to do instead
- Split it across two channels. Send the card number one way and the expiry date another; give the security code by voice only. Either half alone is close to useless.
- Use something that expires. A one-time secret link, a password manager’s share link with a single view, or disappearing messages in Signal. We compare the options in One-Time Secret Alternatives and explain the pitfalls (link previews spending your one view) in How to Send a Password Securely.
- If it has to be a regular chat, turn on disappearing messages first and delete the message for everyone once it has been used. A chat history is a bad place for anything valuable — see Is It Safe to Send a Password over WhatsApp?.
- Tell them what to do with it afterwards: do not save it in a notes app, do not store it in the browser, delete the message.
- Watch the statement for a few weeks, and turn on transaction alerts. It costs nothing and catches most misuse within minutes.
For firms that handle other people’s details
Travel agents, executive assistants, family offices, accountants, law firms — some jobs mean routinely passing a client’s sensitive details to one specific colleague. The problem is never the single message; it is the hundreds of old ones sitting in chat histories and mailboxes across the firm.
That is the problem WaxSeal is designed around, for confidential information in general. The sender’s device encrypts the text for the devices of the named recipients; the organisation’s vault stores ciphertext it cannot read; and what travels through WhatsApp, WeChat or email is an ordinary photo carrying only an invisible reference. The sender sets it to open once, to expire, or to need a PIN given by phone — and can revoke it afterwards, at which point the photo is just a photo. Nothing readable is left in anyone’s chat history or backup.
Two things it is not: it is not a payment processor, and it is not a certified store for card data. If your business takes payments, use a processor’s payment links and keep card numbers out of your own systems entirely. WaxSeal is for the occasional, human hand-over of something confidential inside a team — where the alternative, today, is an email.
The short version
- Prefer a payment link, a virtual card or an authorised user over sending anything.
- Never email, never SMS, never photograph the card.
- If you must send it: split it, use a channel that expires, and give the security code by voice.
- Delete afterwards, and watch the statement.
Bank account details are a different problem with a different answer — there the risk isn’t someone reading them but someone changing them. See How to Send Bank Details Securely.
Frequently asked questions
Is it safe to send credit card details by email?
Is it safe to send a card number by text or WhatsApp?
Should I ever send the CVV?
What is the safest way to let someone else pay with my card?
StegoSafe hides AES-256-encrypted secrets inside ordinary photos — in a deniable format with no header or marker — and can split them across several photos with Shamir Secret Sharing. Runs fully offline on iPhone, iPad and Mac; one universal purchase. For organisations that must send a secret and control it afterwards, see WaxSeal
Get StegoSafe →