{"id":6753,"date":"2021-10-12T15:45:23","date_gmt":"2021-10-12T10:15:23","guid":{"rendered":"https:\/\/razorpay.com\/blog\/?p=6753"},"modified":"2025-03-21T15:09:30","modified_gmt":"2025-03-21T09:39:30","slug":"card-on-file-tokenisation-all-you-need-to-know","status":"publish","type":"post","link":"https:\/\/razorpay.com\/blog\/card-on-file-tokenisation-all-you-need-to-know\/","title":{"rendered":"Decoding Card-on-File Tokenisation: All You Need to Know"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">In the wake of businesses moving online and adapting to the digital payments ecosystem, the <strong>Reserve Bank of India (RBI)<\/strong> has issued a circular (dated September 7, 2021) that prohibits <\/span><b>businesses<\/b><span style=\"font-weight: 400;\">, <\/span><b>payment aggregators<\/b><span style=\"font-weight: 400;\">, <\/span><a href=\"https:\/\/razorpay.com\/payment-gateway\/\"><b>payment gateways<\/b><\/a><span style=\"font-weight: 400;\"> and <\/span><b>acquiring banks<\/b><span style=\"font-weight: 400;\"> from saving customer card details on their servers from July 1, 2022.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The circular states that the only entities allowed to store card information will be <\/span><b>issuing banks <\/b><span style=\"font-weight: 400;\">(the bank which issues the card) and <\/span><a href=\"https:\/\/razorpay.com\/learn\/what-is-a-card-network\/\"><b>card networks<\/b><\/a><span style=\"font-weight: 400;\"> (Visa, Mastercard, Rupay, etc.).<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The main aim of this move is to prevent online fraud by helping keep the critical financial information of customers secure from card data breaches, which allow malicious actors to steal funds from unsuspecting individuals and organisations.\u00a0<\/span><\/p>\n<blockquote><p><strong>While it is true that the RBI now prohibits you from saving your customers\u2019 card details when accepting digital payments, the apex body also provides a workaround &#8211; \u2018Card-on-File Tokenisation\u2019.\u00a0<\/strong><\/p><\/blockquote>\n<h2><b>Understanding Card-on-File Tokenisation\u00a0<\/b><\/h2>\n<h3>What is tokenisation?<\/h3>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/razorpay.com\/blog\/tokenisation-and-its-impact-on-online-payments\/\">Tokenisation<\/a> is the process by which the original card number or Primary Account Number is replaced with a surrogate value called a \u2018token\u2019.\u00a0<\/span><\/p>\n<h3>Card-on-File Tokenisation<\/h3>\n<p><span style=\"font-weight: 400;\">In this process, tokens are created for customer cards to secure them from online frauds. These tokens are managed between the token requestor and the network, thereby allowing customers to store their card details in a secure and compliant fashion. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The relationship between token and card-related data is saved in a vault owned by the card networks. As a result, customer card details will be safer than ever before.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The apex body has recommended that businesses, <a href=\"https:\/\/razorpay.com\/blog\/what-is-a-payment-aggregator\/\">payment aggregators<\/a>, payment gateways and acquiring banks in the payment ecosystem &#8211; particularly payment service providers &#8211; use and store \u2018tokens\u2019 instead of card information through tokenisation.\u00a0<\/span><\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/www.rbi.org.in\/Scripts\/BS_CircularIndexDisplay.aspx?Id=12159\" rel=\"nofollow noopener\" target=\"_blank\"><strong>Check out the RBI circular here<\/strong><\/a><\/p>\n<h2>What does tokenisation mean for digital payments?<\/h2>\n<p><span style=\"font-weight: 400;\">Most businesses adopted the online-first model post the outbreak of the COVID-19 pandemic, making <a href=\"https:\/\/razorpay.com\/learn\/digital-payments-india-definition-methods-importance\/\">digital payments<\/a> a necessity.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6758 aligncenter\" src=\"https:\/\/razorpay.com\/blog-content\/uploads\/2021\/10\/digital-payments-using-debit-and-credit-cards-1024x560.png\" alt=\"digital-payments-using-debit-and-credit-cards\" width=\"660\" height=\"361\" srcset=\"https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/digital-payments-using-debit-and-credit-cards-1024x560.png 1024w, https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/digital-payments-using-debit-and-credit-cards-300x164.png 300w, https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/digital-payments-using-debit-and-credit-cards-768x420.png 768w, https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/digital-payments-using-debit-and-credit-cards-1536x840.png 1536w\" sizes=\"auto, (max-width: 660px) 100vw, 660px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The new regulation by the RBI implies your customers will have to bear the inconvenience of entering their credit or debit card details every time they make an online payment. Besides customer experience, this change can also impact your business in other ways. <\/span><b>\u00a0<\/b><\/p>\n<ul>\n<li aria-level=\"1\"><b>Increased cart abandonment<span style=\"font-weight: 400;\"> &#8211; This will result in an increase in drop-offs at the checkout page and will lead to a decline in revenue<\/span><\/b><\/li>\n<li aria-level=\"1\"><strong>Loss of market share<\/strong> <span style=\"font-weight: 400;\">&#8211; Customers will migrate to competing businesses that offer tokenisation since it will provide a superior experience to customers<\/span><\/li>\n<li aria-level=\"1\"><b style=\"font-size: 19px;\">Loss of personalisation <\/b><span style=\"font-weight: 400;\">&#8211; This will also prevent businesses from offering bespoke offers and promotions to customers based on saved and prior purchase history<\/span><\/li>\n<\/ul>\n<p style=\"text-align: center;\"><a href=\"https:\/\/razorpay.com\/blog\/tokenization-and-its-impact-on-online-payments\/\"><b>Also read: Tokenisation and its impact on Online Payments<\/b><\/a><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><em>If you are worried about how to face these challenges, here is a reliable industry-first tokenisation solution by Razorpay.<\/em><\/p>\n<h2><strong>Razorpay TokenHQ: Enabling seamless card tokenisation<\/strong><\/h2>\n<p><a href=\"https:\/\/razorpay.com\/card-tokenisation\/\">Razorpay TokenHQ, India\u2019s first RBI compliant card tokenisation solution, <\/a>allows businesses to continue offering their customers a saved card experience with the help of a unified platform that connects with various networks such as VISA, Mastercard, Rupay, etc., as well as the issuing banks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6755 aligncenter\" src=\"https:\/\/razorpay.com\/blog-content\/uploads\/2021\/10\/card-on-file-tokenisation-how-it-works-1-1024x604.png\" alt=\"card-on-file-tokenisation-how-it-works\" width=\"703\" height=\"414\" srcset=\"https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/card-on-file-tokenisation-how-it-works-1-1024x604.png 1024w, https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/card-on-file-tokenisation-how-it-works-1-300x177.png 300w, https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/card-on-file-tokenisation-how-it-works-1-768x453.png 768w, https:\/\/blog.razorpay.in\/wp-content\/uploads\/2021\/10\/card-on-file-tokenisation-how-it-works-1.png 1376w\" sizes=\"auto, (max-width: 703px) 100vw, 703px\" \/><\/p>\n<p>Businesses can leverage Razorpay\u2019s local vault as well as a global vault to offer their customers a seamless checkout experience. If you\u2019re a business using Razorpay\u2019s standard checkout\/custom checkout capability, <a href=\"https:\/\/razorpay.com\/blog\/card-tokenisation-all-you-need-to-know\/\">card tokenisation<\/a> will be auto-enabled.<\/p>\n<p>If you have an S2S (server to server) integration with Razorpay, you can use developer-friendly APIs to easily integrate.<\/p>\n<div style=\"text-align: center;\"><a style=\"border-radius: 3px; background: #528ff0; padding: 15px; font-weight: 600; cursor: pointer; text-decoration: none; color: white;\" href=\"https:\/\/razorpay.com\/card-tokenisation\/\" target=\"_blank\" rel=\"noopener noreferrer\">Get started with Razorpay TokenHQ<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In the wake of businesses moving online and adapting to the digital payments ecosystem, the Reserve Bank of India (RBI) has issued a circular (dated September 7, 2021) that prohibits businesses, payment aggregators, payment gateways and acquiring banks from saving customer card details on their servers from July 1, 2022.\u00a0 The circular states that the<\/p>\n","protected":false},"author":68,"featured_media":16745,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[26],"tags":[237,239,238],"class_list":{"0":"post-6753","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-payments","8":"tag-card-on-file-tokenisation","9":"tag-rbi-guidelines","10":"tag-tokenisation"},"_links":{"self":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts\/6753","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/comments?post=6753"}],"version-history":[{"count":2,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts\/6753\/revisions"}],"predecessor-version":[{"id":21562,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/posts\/6753\/revisions\/21562"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/media\/16745"}],"wp:attachment":[{"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/media?parent=6753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/categories?post=6753"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/razorpay.com\/blog\/wp-json\/wp\/v2\/tags?post=6753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}