Payment Processing and PCI Compliance Reference
Why this reference exists
Field service businesses process millions of dollars in credit card payments. Many do so without understanding PCI compliance - the standards required by every credit card company (Visa, Mastercard, AmEx, Discover). A data breach can mean K-100K+ in fines + business closure. PCI compliance is straightforward when set up correctly + nearly impossible to fix after an incident.
What PCI compliance means
Payment Card Industry Data Security Standard (PCI DSS) = set of requirements for any business processing credit cards.
Three pillars:
- Card data not stored (in most cases - see exceptions below)
- Network security (firewalls, antivirus, encryption)
- Compliance documentation (annual self-assessment OR external audit)
Most small service businesses qualify for "merchant level 4" - simplest tier.
Merchant levels
| Level | Annual transactions | Requirements |
|---|---|---|
| 1 | 6M+ | Quarterly external scan + annual on-site audit |
| 2 | 1-6M | Annual self-assessment + quarterly scan |
| 3 | 20K-1M ecommerce | Annual self-assessment + quarterly scan |
| 4 | < 20K ecommerce OR < 1M offline | Annual self-assessment only |
Most field service businesses: Level 4 (offline + low ecommerce). Annual self-assessment via processor portal; that's it.
Self-Assessment Questionnaire (SAQ)
For Level 4 merchants using a payment processor's POS:
- SAQ A (web ecommerce): processor handles all card data; you collect nothing
- SAQ A-EP (hosted payment with redirect): similar; you redirect to processor
- SAQ B (terminal-only): chip card reader; no card data on your network
- SAQ B-IP (terminal connected to network): chip card reader on your network
- SAQ C (POS system): customer-facing POS with card data on network
- SAQ D (other): comprehensive; service businesses storing cards (rare + risky)
Most field service businesses: SAQ B-IP or SAQ C depending on POS architecture.
Filling SAQ takes 30-90 minutes annually. Processor portal walks through it.
Card processing options
Mobile card reader (SAQ B-IP):
- Bluetooth-paired reader (Square, Stripe Terminal, ServiceTitan Pay)
- Chip + tap + magstripe
- Customer-facing or tech-facing
- 2.5-3.5% per transaction processing fee
Tablet + reader POS:
- iPad / Android with reader attached
- More flexibility (estimate, invoice, take signature)
- ServiceTitan, Housecall Pro, Jobber all have integrated options
- hardware + software subscription
Phone-based (NFC tap):
- Square Reader, Stripe Tap to Pay
- Customer phone taps tech phone
- No separate hardware
- Newer + growing
Web-based (estimate-to-pay link):
- Email or text customer a payment link
- Customer enters card on their own device
- SAQ A scope (lowest compliance burden)
- Growing popular for one-time service-call payments
For most modern service business: combine mobile reader (in-person) + web link (remote/late payment).
Common PCI violations
Storing card data:
- Writing card number on paper invoice
- Saving in customer database (NEVER)
- Email with full card number (don't do this)
- Verbal recording of card number
Storing CVV:
- ANY storage of CVV is PCI violation (even encrypted)
Unsecured Wi-Fi:
- Open Wi-Fi at customer site exposes data
- VPN OR cellular data preferred for processing
- Network firewall + antivirus required
Outdated terminals:
- Pre-EMV terminals (post-2015 deadline)
- Pre-PCI-PTS 3.0 (security standards)
- Most modern POS compliant; older equipment not
Untrained crew:
- Crew taking cards by phone (over voice) and writing down
- Verbal CVV captured
- No policy or training
Service trade specifics
In-home service:
- Tech with mobile reader
- Customer card processed at point-of-service
- Compliance: SAQ B-IP typical
- Customer's home Wi-Fi NOT secure for processing; use cellular + reader
Phone payments:
- Customer calls in card information
- Office writes down (PCI VIOLATION!) OR processes via portal at time of call
- BEST: use processor's pay-by-phone OR email payment link
Recurring charges (maintenance contracts, financing):
- Tokenize card with processor (not store)
- Processor stores; you reference a token
- PCI compliance maintained
Invoicing:
- Email or text payment link
- Customer enters card on processor-hosted page
- You see "paid" status; never see card data
- SAQ A scope
Payment processors
Square: simplest, mobile-first, no monthly fee (transaction fees apply). Best for very small + new businesses.
Stripe: developer-friendly, web payments, scaling. Mobile reader available. 2.7-2.9% + 30ยข per transaction.
PayPal / Venmo Business: smaller scale; not preferred for large service tickets.
ServiceTitan Payments (integrated with ServiceTitan POS): convenience trade-off for fee. Best for ServiceTitan users.
Housecall Pro Payments: similar integration.
TSYS, Worldpay, First Data: traditional commercial processors. Lower fees at higher volume but harder setup.
For most field service: Stripe + integrated POS (ServiceTitan, Housecall Pro, Jobber) OR Square for simpler operations.
Fees + costs
Transaction fees typical:
- 2.5-2.9% +/dip
- 3.0-3.5% for keyed (card-not-present) entries
- 1.5-2.5% for ACH / bank transfer
- 0% for cash
Monthly: typically no monthly fees at Square + similar simple processors. Traditional processors: + fees per transaction.
Annual: PCI compliance fees from some processors; built-in for others.
Hardware: for reader + tablet/POS combo.
Customer-side preferences
Customers want:
- Tap (NFC) preferred for speed + security
- Chip dip preferred over magstripe
- ACH for large amounts (less fee, security)
- Apple Pay / Google Pay / Samsung Pay all NFC
- Pay-on-web link if not paying in person
Magstripe declining (most cards have chip + tap).
Best practices
For PCI compliance + customer experience:
- Use a processor with PCI compliance support: they walk you through annually
- Modern POS hardware: EMV chip + NFC tap reader
- Never write card numbers: not on paper, not in CRM notes
- Encrypt Wi-Fi: if processing at site
- Use cellular data + reader: even better than Wi-Fi
- Tokenize for recurring: never store card directly
- Train crew: brief PCI awareness annually
- Email payment links: for remote / late payments; lowest PCI scope
- Annual self-assessment: complete promptly
Common pitfalls
References
- PCI Security Standards Council (pcisecuritystandards.org)
- PCI DSS v4.0 documentation
- Federal Trade Commission data security guidance
- Card network security standards (Visa, Mastercard, AmEx, Discover)
- Processor compliance support documentation
- Manuall internal: Service Fleet Management Reference, Customer Financing Options Reference