Payment Processing and PCI Compliance Reference

Why this reference exists

Field service businesses process millions of dollars in credit card payments. Many do so without understanding PCI compliance - the standards required by every credit card company (Visa, Mastercard, AmEx, Discover). A data breach can mean K-100K+ in fines + business closure. PCI compliance is straightforward when set up correctly + nearly impossible to fix after an incident.

What PCI compliance means

Payment Card Industry Data Security Standard (PCI DSS) = set of requirements for any business processing credit cards.

Three pillars:

  1. Card data not stored (in most cases - see exceptions below)
  2. Network security (firewalls, antivirus, encryption)
  3. Compliance documentation (annual self-assessment OR external audit)

Most small service businesses qualify for "merchant level 4" - simplest tier.

Merchant levels

Level Annual transactions Requirements
1 6M+ Quarterly external scan + annual on-site audit
2 1-6M Annual self-assessment + quarterly scan
3 20K-1M ecommerce Annual self-assessment + quarterly scan
4 < 20K ecommerce OR < 1M offline Annual self-assessment only

Most field service businesses: Level 4 (offline + low ecommerce). Annual self-assessment via processor portal; that's it.

Self-Assessment Questionnaire (SAQ)

For Level 4 merchants using a payment processor's POS:

  • SAQ A (web ecommerce): processor handles all card data; you collect nothing
  • SAQ A-EP (hosted payment with redirect): similar; you redirect to processor
  • SAQ B (terminal-only): chip card reader; no card data on your network
  • SAQ B-IP (terminal connected to network): chip card reader on your network
  • SAQ C (POS system): customer-facing POS with card data on network
  • SAQ D (other): comprehensive; service businesses storing cards (rare + risky)

Most field service businesses: SAQ B-IP or SAQ C depending on POS architecture.

Filling SAQ takes 30-90 minutes annually. Processor portal walks through it.

Card processing options

Mobile card reader (SAQ B-IP):

  • Bluetooth-paired reader (Square, Stripe Terminal, ServiceTitan Pay)
  • Chip + tap + magstripe
  • Customer-facing or tech-facing
  • 2.5-3.5% per transaction processing fee

Tablet + reader POS:

  • iPad / Android with reader attached
  • More flexibility (estimate, invoice, take signature)
  • ServiceTitan, Housecall Pro, Jobber all have integrated options
  • hardware + software subscription

Phone-based (NFC tap):

  • Square Reader, Stripe Tap to Pay
  • Customer phone taps tech phone
  • No separate hardware
  • Newer + growing

Web-based (estimate-to-pay link):

  • Email or text customer a payment link
  • Customer enters card on their own device
  • SAQ A scope (lowest compliance burden)
  • Growing popular for one-time service-call payments

For most modern service business: combine mobile reader (in-person) + web link (remote/late payment).

Common PCI violations

Storing card data:

  • Writing card number on paper invoice
  • Saving in customer database (NEVER)
  • Email with full card number (don't do this)
  • Verbal recording of card number

Storing CVV:

  • ANY storage of CVV is PCI violation (even encrypted)

Unsecured Wi-Fi:

  • Open Wi-Fi at customer site exposes data
  • VPN OR cellular data preferred for processing
  • Network firewall + antivirus required

Outdated terminals:

  • Pre-EMV terminals (post-2015 deadline)
  • Pre-PCI-PTS 3.0 (security standards)
  • Most modern POS compliant; older equipment not

Untrained crew:

  • Crew taking cards by phone (over voice) and writing down
  • Verbal CVV captured
  • No policy or training

Service trade specifics

In-home service:

  • Tech with mobile reader
  • Customer card processed at point-of-service
  • Compliance: SAQ B-IP typical
  • Customer's home Wi-Fi NOT secure for processing; use cellular + reader

Phone payments:

  • Customer calls in card information
  • Office writes down (PCI VIOLATION!) OR processes via portal at time of call
  • BEST: use processor's pay-by-phone OR email payment link

Recurring charges (maintenance contracts, financing):

  • Tokenize card with processor (not store)
  • Processor stores; you reference a token
  • PCI compliance maintained

Invoicing:

  • Email or text payment link
  • Customer enters card on processor-hosted page
  • You see "paid" status; never see card data
  • SAQ A scope

Payment processors

Square: simplest, mobile-first, no monthly fee (transaction fees apply). Best for very small + new businesses.

Stripe: developer-friendly, web payments, scaling. Mobile reader available. 2.7-2.9% + 30ยข per transaction.

PayPal / Venmo Business: smaller scale; not preferred for large service tickets.

ServiceTitan Payments (integrated with ServiceTitan POS): convenience trade-off for fee. Best for ServiceTitan users.

Housecall Pro Payments: similar integration.

TSYS, Worldpay, First Data: traditional commercial processors. Lower fees at higher volume but harder setup.

For most field service: Stripe + integrated POS (ServiceTitan, Housecall Pro, Jobber) OR Square for simpler operations.

Fees + costs

Transaction fees typical:

  • 2.5-2.9% +/dip
  • 3.0-3.5% for keyed (card-not-present) entries
  • 1.5-2.5% for ACH / bank transfer
  • 0% for cash

Monthly: typically no monthly fees at Square + similar simple processors. Traditional processors: + fees per transaction.

Annual: PCI compliance fees from some processors; built-in for others.

Hardware: for reader + tablet/POS combo.

Customer-side preferences

Customers want:

  • Tap (NFC) preferred for speed + security
  • Chip dip preferred over magstripe
  • ACH for large amounts (less fee, security)
  • Apple Pay / Google Pay / Samsung Pay all NFC
  • Pay-on-web link if not paying in person

Magstripe declining (most cards have chip + tap).

Best practices

For PCI compliance + customer experience:

  1. Use a processor with PCI compliance support: they walk you through annually
  2. Modern POS hardware: EMV chip + NFC tap reader
  3. Never write card numbers: not on paper, not in CRM notes
  4. Encrypt Wi-Fi: if processing at site
  5. Use cellular data + reader: even better than Wi-Fi
  6. Tokenize for recurring: never store card directly
  7. Train crew: brief PCI awareness annually
  8. Email payment links: for remote / late payments; lowest PCI scope
  9. Annual self-assessment: complete promptly

Common pitfalls

References

  • PCI Security Standards Council (pcisecuritystandards.org)
  • PCI DSS v4.0 documentation
  • Federal Trade Commission data security guidance
  • Card network security standards (Visa, Mastercard, AmEx, Discover)
  • Processor compliance support documentation
  • Manuall internal: Service Fleet Management Reference, Customer Financing Options Reference