Why We Won't Take Your Credit Card Number Over the Phone
Why PHYX takes cards by chip or tap in person, what changes when a card number is read aloud, and what to pay with instead.

You call to pay for your repair. You have the card in your hand. You start reading off the numbers, and we stop you.
That is on purpose. We take cards in person with a chip or a tap. We do not key in numbers read over the phone.
There is a real reason behind it. The two transactions are not the same thing underneath, and the difference matters to you more than it matters to us.
A chip transaction is a conversation, not a number
When you insert or tap a chip card, the chip does math.
It runs a small cryptographic routine and produces a one-time code for that exact purchase. The payments industry calls it a cryptogram. American Express describes the mechanism in its EMV chip card FAQ, where dynamic data authentication validates a unique cryptogram generated for each transaction by the card.
That code is good once. If somebody grabbed it off the wire, it is already spent. Replaying it gets a decline.
Tapping works the same way. Contactless runs the same EMV standard over a short-range radio link.
Apple Pay and Google Pay go one step further. Apple's Apple Pay security and privacy overview explains that your device stores a Device Account Number instead of your real card number, and that the full card number is never kept on the device or on Apple's servers.
So the terminal never needs your secrets. The chip proves itself instead.
A number read out loud stays valid forever
Your card number, expiration date, and the code on the back do not change.
They are the same today, next week, and in March. They stay valid until the bank reissues the card.
When those digits get spoken, written on a pad, typed into a screen, or captured on a recorded line, they keep working. Anyone holding them can spend your money from anywhere.
There is no cryptogram in that path. There is no proof the card was ever in the room. The processor is taking somebody's word for it.

The recorded-call problem is not hypothetical
Repair shops take a lot of phone calls. Plenty of businesses record them.
That creates a compliance trap most people never think about. The PCI Security Standards Council states plainly that storing card verification codes in audio recordings after authorization violates PCI DSS Requirement 3.3.1, even when the recording itself is encrypted.
Read us your security code on a recorded line and the recording becomes a liability for the shop. It is a problem for you too. Your live card data now sits in a file that somebody else has to protect.
The clean fix is the obvious one. Keep the number out of the audio stream.
Somebody eats the loss when a keyed charge turns out to be stolen
Card networks treat a keyed transaction as card-not-present, even when the customer is standing right there.
Card-not-present fraud has been climbing in the United States. Federal Reserve Bank of Kansas City research on card-present and card-not-present fraud rates found that the merchant card-not-present fraud loss rate on single-message debit networks more than doubled from 2021 to 2023, from 5.4 basis points to 12.8. That works out to roughly $12.80 lost for every $10,000 processed.
Those figures cover non-prepaid debit cards specifically. The direction of the trend is the part that matters here.
Liability follows the same logic. Square explains the EMV liability shift this way: when a counterfeit chip card gets used and the business does not run it through the chip, the business can be held liable for that charge. On a card-not-present charge, the business usually absorbs the chargeback too. Those are rules we did not write and cannot appeal.
Chip or tap versus numbers over the phone
| What is happening | Chip inserted or card tapped | Numbers read over the phone |
|---|---|---|
| What the bank receives | A one-time cryptogram, different every purchase | The same static digits every time |
| Value if intercepted | None, the code is already spent | Full value until the card is reissued |
| Evidence the real card was present | Yes, the chip proves it | None |
| Typical fraud liability | Issuer, when the chip is used correctly | The business |
| Where your data can end up | Terminal to processor, nowhere else | Notepads, screens, call audio |
| Processing cost to the business | Lower | Higher |
What to pay with instead
If you are at the shop, chip or tap handles it. If you are not, these keep your card data out of a phone call.
| Method | How it works | What you need |
|---|---|---|
| Cash App | Send to `$phyxrepair` from your app | Cash App account |
| Venmo | Send to `@PHYX-Repairs` from your app | Venmo account |
| PayPal | Send to `repairs@phyx.me` as the PayPal recipient | PayPal account |
| Apple Pay or Google Pay | Tap your phone or watch at the counter | Wallet set up on your device |
| Cash | Pay at the counter | Nothing |
Cash App, Venmo, and PayPal are safe here for the same underlying reason the chip is. You authorize the payment yourself, inside your own app, on your own device. You unlock it with your face, your fingerprint, or your PIN.
Nothing sensitive gets spoken aloud. Nothing gets written down. We never see or hold your card credentials, which means we cannot lose them.
One note on that PayPal line. `repairs@phyx.me` is our email address as well as our PayPal recipient. Send the money through PayPal, not through email. Do not put card numbers in an email either. Email sits in plain text on several servers along the way.

One thing to watch for
We will never call you out of the blue and ask for a card number. Nobody at a legitimate shop will.
If you get that call, hang up. Then look our real number up yourself on the PHYX contact page and call back. Scammers impersonating local businesses is an old trick, and it still works.
Same goes for app payments. Confirm the handle with us directly before you send anything. A wrong handle sends real money to a stranger, and those transfers are hard to claw back.
Why we hold this line
We have been repairing devices in Springfield since 2015. We were voted Best Phone & Computer Repair Shop in the 2026 Valley Advocate Readers' Poll. You do not stay open that long by being casual with people's money.
Handing us a card that we never key in is better for you. It is better for us too. That combination is rare enough in business that it is worth doing right.
FAQs
> Q: Can I pay over the phone before I come pick up my device?
>
> A: Not with a card number, no. Send it through Cash App, Venmo, or PayPal and we will mark the ticket paid before you arrive. You can also pay at the counter with a chip, a tap, or cash. Any of those work fine. Just call or text first so we know the device is ready to go.
> Q: Why does the chip matter if I am handing you the card anyway?
>
> A: Because a keyed charge is processed as card-not-present even when the card is sitting in front of us. The chip is what generates the one-time code proving the real card was used. Without that code, the transaction carries none of the protection the chip was built to provide.
> Q: Is tapping my phone as safe as inserting the chip?
>
> A: Yes. Apple Pay and Google Pay run the same EMV process and swap a device-specific number in place of your real card number. Your actual card number never reaches our terminal. If your phone is already set up, tapping is the fastest option we have at the Springfield counter.
Ready to pay and pick up?
Bring the device in and tap or insert your card at the counter. If you want payment sorted before you drive over, [Text PHYX at 413-234-4313](sms:+14132344313) or Call PHYX at 413-234-4313 and we will point you to the right app handle.

