AI Help for Retail › Guides › Customer data & PCI

Customer data and payment cards for shops: PCI and privacy in plain English

In a sentence: when you take a card and keep customer info, you're holding something worth protecting, and the rules for doing it are simpler than they sound -- use a modern payment provider, never store raw card numbers yourself, and keep only the customer data you actually use. This page is plain-English context to help you ask good questions, not legal advice.
See Square for Retail →   Compare POS tools →
Start here

The short version

  • PCI stands for Payment Card Industry, and PCI DSS is the Data Security Standard -- the card networks' shared checklist for keeping card data safe. It applies to any business that takes cards, including yours.
  • The one big rule: don't store raw card numbers. If you never hold them, most of the risk (and the paperwork) disappears.
  • Your POS does the heavy lifting. Square, Shopify, Lightspeed, and other modern providers keep card data locked down on their side.
  • Your part is small: use those tools as intended, keep devices and passwords tidy, train your staff, and fill out a short yearly self-check.
  • Customer data beyond cards -- emails, phone numbers, purchase history -- deserves the same care: keep only what you need, get permission to market, and honor opt-outs.
Questions

Common questions

Am I too small for PCI to apply to me?

No. PCI DSS applies to any business that takes card payments, no matter how small. The good part is that a small shop usually has a simple setup, so the effort is small too -- especially if you never store card numbers and let a compliant payment provider do the heavy lifting.

Does using Square or Shopify mean I'm automatically compliant?

It handles most of it, but not all of it. A modern provider keeps card data locked down on their side, which removes the hardest parts. Your part is to use their tools as intended, not write card numbers down anywhere, keep your devices and passwords tidy, and complete your yearly self-assessment. They do the heavy lifting; you keep your side clean.

Can I keep a customer's card number on file for repeat orders?

Don't keep the raw number yourself. If you want card-on-file for regulars, use your payment provider's saved-card feature, which stores a secure token instead of the real number. You can charge a returning customer without ever holding the card data, which is exactly what you want.

Is it fine to use customer emails I collected at checkout for marketing?

Only if they agreed to it. Collecting an email for a receipt isn't the same as permission to send marketing. Ask for that opt-in in plain words, keep an easy way to unsubscribe, and only keep the data you actually use. That keeps you on the right side of both the rules and your customers' trust.

Sources: the PCI Security Standards Council's small-merchant guidance (pcisecuritystandards.org/merchants) and the Federal Trade Commission's "Protecting Personal Information: A Guide for Business" (ftc.gov) -- checked 2026-08-14. This is plain-language context, not legal advice; confirm your obligations with your payment provider, bank, and a qualified professional. Last reviewed: 2026-08-14.

What is PCI, really?

The card companies (Visa, Mastercard, and the rest) got together and wrote a shared set of security rules for anyone who handles card payments. That's PCI DSS, the Payment Card Industry Data Security Standard. Think of it as the safety checklist for taking cards.

It applies to every shop that accepts cards, from a one-till boutique to a chain. Size doesn't get you out of it. What size does change is how much work it takes: a small shop with a simple setup has far less to worry about than a big operation with servers full of customer data.

You don't need to memorize the standard. You need to know the few things that are on you, and let good tools handle the rest.

The single most important rule: don't store card numbers

Almost every serious card problem traces back to a business holding card numbers it shouldn't. So the simplest, strongest thing you can do is never store them at all.

The PCI Security Standards Council says it plainly for small shops: the best way to protect card data is not to store it. Let your payment provider capture and hold the card on their secure systems, and keep none of it yourself.

That means no writing card numbers on a notepad, no typing them into a spreadsheet, no keeping the full number in an email. If you want to charge a repeat customer, use your provider's saved-card feature, which keeps a secure stand-in (a token) instead of the real number.

What your POS or payment provider already handles

Here's the relief: if you use a modern POS or payment provider, they carry most of the load. The card data flows through their secure, PCI-compliant systems, and you never touch the sensitive part.

  • Secure card capture -- the chip reader or tap terminal encrypts the card at the moment of sale.
  • Compliant storage on their side -- if a card gets saved for a repeat customer, they store the token, not the raw number.
  • Their own PCI compliance -- providers like Square, Shopify, and Lightspeed maintain their side of the standard so you don't have to build it.

This is why "which POS you pick" is partly a security decision. A reputable, compliant provider takes the scariest part off your plate.

The handful of things that are still on you

Even with a great provider, a few basics stay your job. None of them are hard.

  • Use compliant payment tools -- take cards through your provider's terminal and software, not some workaround.
  • Never write down or store card numbers -- the rule from above, applied to your whole team.
  • Keep software and devices updated -- run updates on your POS, tablet, and computer so known holes get patched.
  • Use strong, separate passwords -- and lock down your shop Wi-Fi; don't run the register on the same open network you hand to customers.
  • Train your staff -- a quick "here's how we handle cards and customer info" talk prevents most slip-ups.
  • Do the yearly self-check -- most small shops complete a short Self-Assessment Questionnaire (SAQ), a plain checklist your payment provider or bank points you to once a year.
Compliance

Customer data beyond cards: the privacy basics

Cards aren't the only thing you hold. Emails, phone numbers, and purchase history are personal data too, and customers trust you with them. The Federal Trade Commission's small-business guidance boils good handling down to a few plain ideas.

  • Keep only what you need. If you don't have a real use for a piece of personal info, don't collect it, and don't hang onto it.
  • Protect what you keep. Lock up paperwork, secure your devices, and limit who can see the data.
  • Get rid of what you're done with. Old customer lists you'll never use are risk, not value.
  • Have a simple plan if something goes wrong. Know who you'd call and what you'd do if data got lost or stolen.

On marketing: collecting an email for a receipt isn't the same as permission to market to someone. Ask for that opt-in in plain words, make unsubscribing easy, and never sell your customer list. That's covered more in our email and text marketing guide.

Where AI tools fit in

When you add AI marketing, loyalty, or analytics tools, they touch your customer data too. Same principles apply: pick reputable vendors, check what they store and where, and only feed them data you have permission to use.

A good AI marketing tool works off the list you already built with permission. It shouldn't need you to hand over card numbers or anything you wouldn't be comfortable explaining to a customer. If a tool asks for more than it needs, that's your cue to slow down.

Want help setting up secure payments and data?

Find a local AI consultant who sets up a compliant POS, saved-card handling, and clean customer-data practices for shops like yours -- by zip code.

Find a local AI pro →
Find a local pro

Get these tools set up for you

Enter your zip and we'll show local AI consultants who set up POS and inventory tools, email and text marketing, reviews, and shipping for shops like yours. Free to use, and we don't take a cut of what you pay them.