Glossary

Virtual Terminal

A virtual terminal is a web-based application that lets merchants process card-not-present payments without physical hardware.

Key Takeaways

  • A virtual terminal is a web-based interface that lets merchants manually key in card details to process card-not-present payments over the phone, by mail, or from invoices: no physical hardware required.
  • Virtual terminal transactions carry higher interchange fees (typically 2.9%–3.5%) and greater fraud risk than card-present payments because the merchant cannot verify the cardholder through chip, PIN, or tap.
  • Modern alternatives like API-based payment gateways and stablecoin payment rails are reshaping how merchants accept remote payments, offering lower fees, faster settlement, and programmable automation.

What Is a Virtual Terminal?

A virtual terminal is a software application, typically accessed through a web browser, that allows merchants to accept credit and debit card payments without a physical point-of-sale terminal. The merchant logs into a secure portal provided by their payment processor, manually enters the customer's card number, expiration date, CVV, billing address, and transaction amount, then submits the payment for authorization.

The name reflects the core concept: it "virtualizes" the function of a countertop card terminal into software. Where a physical terminal reads card data from a chip or contactless tap, a virtual terminal relies entirely on the merchant keying in information received over the phone, through mail, or from an invoice. This makes virtual terminals the standard tool for MOTO (Mail Order/Telephone Order) businesses.

Virtual terminals sit alongside physical POS systems, e-commerce payment gateways, and mobile card readers as one of four primary ways merchants accept card payments. They require no developer expertise, no hardware investment, and no website: just a browser and a merchant account.

How It Works

Processing a payment through a virtual terminal follows the same authorization flow as any card transaction, but with the merchant acting as the data entry point instead of the cardholder:

  1. The merchant logs into the virtual terminal portal provided by their payment processor (Square, Stripe, Authorize.net, or similar)
  2. The merchant enters the customer's card details: card number, expiration date, CVV/CVC, billing address, and the transaction amount
  3. The system runs AVS checks and CVV verification in real time, and some processors apply machine-learning fraud scoring before forwarding the request
  4. The data is encrypted and transmitted to the payment gateway, which routes it through the card network (Visa, Mastercard, Amex) to the issuing bank for authorization
  5. The merchant receives an approval or decline response, typically within one to three seconds
  6. Approved transactions are batched and settled through the acquirer, with funds deposited to the merchant's bank account in one to two business days

Virtual Terminal vs. Payment Gateway

The distinction between a virtual terminal and a payment gateway is a common source of confusion. A payment gateway is the underlying infrastructure that securely transmits card data from the point of capture to the processor. A virtual terminal is a specific user interface built on top of a gateway, designed for merchant-initiated manual entry.

When a customer enters their own card details on a checkout page, they interact with a payment gateway directly. When a merchant keys in those details on behalf of the customer, they use a virtual terminal. Both rely on the same backend authorization infrastructure.

MethodCard PresenceWho Enters DataTypical Use Case
Physical POS terminalCard-present (chip/tap)CustomerRetail, restaurants
E-commerce gatewayCard-not-presentCustomerOnline stores, SaaS
Mobile card readerCard-present (chip/tap)CustomerMarkets, field service
Virtual terminalCard-not-presentMerchantPhone, mail, invoices

PCI DSS Compliance

Merchants using virtual terminals fall under PCI DSS SAQ C-VT (Self-Assessment Questionnaire C-VT), one of the simplest compliance categories. This applies when the virtual terminal is the merchant's only card processing method and is hosted by a PCI DSS-validated third-party provider.

Under SAQ C-VT, the merchant's own systems never store, process, or transmit cardholder data: the provider's infrastructure handles the heavy lifting. The merchant's obligations center on securing the workstation used for data entry and training employees on security practices.

With PCI DSS v4.0 (mandatory since March 2025), SAQ C-VT merchants must meet updated requirements including 12-character minimum passwords, anti-phishing controls, phishing-focused employee security training, and documented security policies. Despite these additions, SAQ C-VT remains significantly lighter than the SAQ D required for merchants handling card data directly through custom API integrations.

Use Cases

Virtual terminals serve merchants who need to accept card payments in situations where the cardholder is not physically present and no online checkout flow exists:

  • Phone orders: call centers and service businesses take card details over the phone and key them into the virtual terminal in real time
  • Mail orders: merchants processing paper order forms manually enter card details from the submitted forms
  • Invoice payments: B2B vendors allow clients to call and pay outstanding invoices by reading their card details to an accounts receivable team
  • Service professionals: consultants, contractors, and healthcare providers bill clients remotely without maintaining a website
  • Supplementary channel: retailers with physical POS systems use a virtual terminal as a fallback for phone orders or manual adjustments

Fee Structure

Virtual terminal transactions are classified as card-not-present, which carries higher interchange rates than card-present transactions. The gap exists because CNP transactions have a higher risk of fraud and chargebacks, since the merchant cannot verify the cardholder through chip, PIN, or biometric methods.

At the interchange level (rates set by Visa and Mastercard), keyed-entry transactions run roughly 30 to 40 basis points higher than card-present transactions. Processor markups widen the gap further:

Transaction TypeTypical Total RateExample (Square)
Card-present (chip/tap)1.7%–2.1% + $0.102.6% + $0.10
Virtual terminal (keyed)2.9%–3.5% + $0.15–$0.303.5% + $0.15

On a $100 transaction, that translates to roughly $2.70 via in-person tap versus $3.65 via virtual terminal: a 35% increase in processing cost. For high-volume merchants, this difference is a significant line item. For a deeper analysis, see the research on merchant payment acceptance costs.

Virtual Terminals vs. API-Based Processing

Modern API-based payment processing (Stripe API, Square API, Adyen) represents the developer-driven evolution of remote payment acceptance. Where virtual terminals are manual and human-operated, APIs enable fully automated, programmable payment flows:

DimensionVirtual TerminalAPI-Based Processing
Integration effortNone: browser loginDeveloper integration required
ScalabilityLimited by manual entry speedThousands of transactions per second
AutomationEach transaction is manualRecurring billing, webhooks, retries
Fraud toolsBasic AVS + CVV3D Secure, ML risk scoring, device fingerprinting
PCI burdenSAQ C-VT (lightest)SAQ A (hosted) to SAQ D (direct handling)
Best forLow-volume phone/mail ordersE-commerce, SaaS, marketplaces

The two approaches are complementary rather than competing. Many businesses use API integration for their primary online channel while keeping a virtual terminal for phone orders and manual adjustments. Providers like Stripe and Square offer both under a single merchant account.

The Stablecoin Alternative

Crypto payment acceptance, particularly through stablecoins, is emerging as an alternative to traditional virtual terminal workflows. Stablecoin payments bypass card networks entirely, eliminating interchange fees and offering faster settlement:

  • Fees as low as 1.5% per transaction versus 2.9%–3.5% for card-based virtual terminals
  • Settlement in seconds to minutes versus one to two business days through traditional batch settlement
  • No chargebacks: blockchain transactions are final, though this shifts dispute resolution responsibilities
  • Global reach without cross-border card fees or currency conversion costs

However, the payment model is fundamentally different. Virtual terminals use a pull-based model: the merchant enters a card number and pulls funds. Stablecoin payments are push-based: the customer initiates the transfer from their wallet. This means the "virtual terminal" concept does not translate directly to crypto. Instead, merchants generate payment links, display QR codes, or send invoices that the customer pays from their wallet.

For merchants exploring this transition, Spark's Bitcoin Layer 2 enables stablecoin acceptance with near-instant settlement and minimal fees. See the stablecoin merchant adoption guide for implementation details, or explore how POS terminals are integrating crypto alongside traditional card acceptance.

Risks and Considerations

Higher Fraud Exposure

Because virtual terminal transactions are card-not-present, they carry elevated fraud risk. The merchant has no way to verify the physical card or the cardholder's identity beyond AVS and CVV checks. Stolen card numbers work just as well when keyed into a virtual terminal as they do on a compromised e-commerce site. Merchants should implement additional verification steps (callback confirmation, customer authentication) for high-value transactions.

Chargeback Liability

In CNP transactions, the chargeback liability typically falls on the merchant. Unlike card-present transactions where chip verification provides strong proof of cardholder authorization, virtual terminal transactions offer limited evidence in disputes. Merchants should maintain detailed records of phone conversations, order confirmations, and delivery tracking to defend against chargebacks. For a broader view of fraud prevention strategies, see the research on fraud prevention in digital payments.

Manual Bottleneck

Every virtual terminal transaction requires a human to key in card details. This creates a natural throughput ceiling: a single employee can process only so many phone payments per hour. For businesses experiencing growth in remote payment volume, migrating to an API-integrated payment gateway or payment link system removes the human bottleneck and reduces data entry errors.

Data Entry Errors

Manual keying is inherently error-prone. Transposed digits, misheard card numbers over the phone, and incorrect billing addresses all lead to declined transactions, customer friction, and lost sales. Some virtual terminal providers offer features like card-on-file tokenization for repeat customers, which eliminates re-entry for subsequent transactions.

This glossary entry is for informational purposes only and does not constitute financial or investment advice. Always do your own research before using any protocol or technology.