Most of the time, the secure way to send credit card details is: don’t. Almost every situation that seems to need it has a better route, and the better route is usually also less work.

So this guide is in two parts — how to avoid sending the card at all, and how to do it properly on the occasions when you must.

First: do you need to send it?

Paying a business. Ask for a payment link or an online invoice. Stripe, Square, PayPal and every serious invoicing tool produce one in seconds; you type the card into the processor’s page, and the business never handles the number. If a company insists on a card number by email, that tells you something about how they will store it.

Businesses have a reason to agree: the card industry’s security standard (PCI DSS) says full card numbers must never be sent over ordinary email, chat or SMS unprotected, and any system that stores them falls under audit. A payment link takes them out of that scope.

Paying over the phone. Reading the number aloud to a merchant you called is a normal, accepted channel — nothing is written down on your side. Call the number on their website, not one from a message.

Letting someone else spend on your behalf — a partner, an assistant, a contractor buying materials:

  • an authorised user card in their own name, or
  • a virtual card number from your bank or card provider, with its own limit and expiry, that you can cancel without touching the real card, or
  • Apple Pay / Google Pay on a shared family set-up.

A leaked virtual number costs you a tap to cancel. A leaked real card costs you a new card and a week of failed subscriptions.

When you really must send it

A relative booking a flight for you tonight. An assistant paying a supplier who only takes cards by phone. A client’s card on file for a one-off purchase.

What never to do

  • Email — it is permanent, searchable and in more places than you think.
  • SMS — unencrypted, and often mirrored to laptops and tablets.
  • A photo of the card — photo libraries sync to the cloud, and both phones now index the text in images. Malware that scans photo libraries for card numbers and wallet phrases is real.
  • Everything in one message. Number, expiry, security code, name and billing postcode together are a complete payment credential.

What to do instead

  1. Split it across two channels. Send the card number one way and the expiry date another; give the security code by voice only. Either half alone is close to useless.
  2. Use something that expires. A one-time secret link, a password manager’s share link with a single view, or disappearing messages in Signal. We compare the options in One-Time Secret Alternatives and explain the pitfalls (link previews spending your one view) in How to Send a Password Securely.
  3. If it has to be a regular chat, turn on disappearing messages first and delete the message for everyone once it has been used. A chat history is a bad place for anything valuable — see Is It Safe to Send a Password over WhatsApp?.
  4. Tell them what to do with it afterwards: do not save it in a notes app, do not store it in the browser, delete the message.
  5. Watch the statement for a few weeks, and turn on transaction alerts. It costs nothing and catches most misuse within minutes.

For firms that handle other people’s details

Travel agents, executive assistants, family offices, accountants, law firms — some jobs mean routinely passing a client’s sensitive details to one specific colleague. The problem is never the single message; it is the hundreds of old ones sitting in chat histories and mailboxes across the firm.

That is the problem WaxSeal is designed around, for confidential information in general. The sender’s device encrypts the text for the devices of the named recipients; the organisation’s vault stores ciphertext it cannot read; and what travels through WhatsApp, WeChat or email is an ordinary photo carrying only an invisible reference. The sender sets it to open once, to expire, or to need a PIN given by phone — and can revoke it afterwards, at which point the photo is just a photo. Nothing readable is left in anyone’s chat history or backup.

Two things it is not: it is not a payment processor, and it is not a certified store for card data. If your business takes payments, use a processor’s payment links and keep card numbers out of your own systems entirely. WaxSeal is for the occasional, human hand-over of something confidential inside a team — where the alternative, today, is an email.

The short version

  1. Prefer a payment link, a virtual card or an authorised user over sending anything.
  2. Never email, never SMS, never photograph the card.
  3. If you must send it: split it, use a channel that expires, and give the security code by voice.
  4. Delete afterwards, and watch the statement.

Bank account details are a different problem with a different answer — there the risk isn’t someone reading them but someone changing them. See How to Send Bank Details Securely.

Frequently asked questions

Is it safe to send credit card details by email?
No. Email is stored in plain form in both mailboxes, their backups and every signed-in device, often for years, and is a routine target of account takeovers. Card-industry rules (PCI DSS) tell businesses never to send full card numbers by unencrypted email or chat. If a company asks you to email your card number, ask for a payment link instead.
Is it safe to send a card number by text or WhatsApp?
SMS is not encrypted and should not be used. WhatsApp and Signal protect the message in transit, but the number then sits in the chat history, in backups and on linked devices. If you use them, split the details across two channels and delete the message afterwards — and prefer a method that expires by itself.
Should I ever send the CVV?
Avoid it. The three- or four-digit security code is what lets someone use the card online. If the other person genuinely needs it, give it by voice, separately from the number, and never in writing alongside the number and expiry date.
What is the safest way to let someone else pay with my card?
Do not give them the card at all: add them as an authorised user, pay the invoice yourself through the merchant’s payment link, or create a virtual card number with a spending limit and an expiry. A leaked virtual number can be cancelled without touching your real card.

StegoSafe hides AES-256-encrypted secrets inside ordinary photos — in a deniable format with no header or marker — and can split them across several photos with Shamir Secret Sharing. Runs fully offline on iPhone, iPad and Mac; one universal purchase. For organisations that must send a secret and control it afterwards, see WaxSeal

Get StegoSafe →