Virtual POS
What is Virtual POS?
Virtual POS (virtual point of sale) is browser-based software that lets a merchant accept card payments by typing card details into a form instead of reading the card on physical hardware. It performs the same request a countertop terminal sends, using a web interface in place of a card reader.
Virtual POS is also called a virtual terminal. The merchant's staff member enters the card number, expiry, , and into a secure page inside the payment provider's back office, then submits the transaction for authorization. No reader, no PIN pad, and no dedicated card line are involved, so any device with a browser and a login becomes an acceptance point.
Because the card is never read by a device, every virtual POS payment settles as a . That classification follows the payment for its whole life: it shapes the the merchant pays, the fraud checks the issuer applies, and who carries the loss if the cardholder later disputes the charge.
Key facts
- Also known as: virtual terminal, virtual point of sale, browser-based terminal
- Transaction type: card-not-present transaction, even when the cardholder is standing in front of the operator
- Hardware required: none beyond an internet-connected device and a browser
- Who keys in the data: the merchant's staff, not the cardholder
- Common use cases: phone and mail orders (), invoice and deposit collection, event and field sales, back-office corrections
- Access control: user-level logins inside the payment provider or back office, usually with per-operator permissions
- Compliance scope: staff handle raw card data, so the merchant sits inside scope for the way that data is received, spoken, and stored
How it works
- The merchant collects the card details. A staff member takes the card number, expiry date, security code, and billing address over the phone, from an order form, or in person.
- The operator keys the details into the terminal. The virtual POS form sits inside the merchant's account with the or gateway, behind a login.
- The gateway builds the authorization request. Card data is encrypted and passed to the with the transaction amount, currency, and the merchant's identifiers.
- The issuer approves or declines. The runs its own risk checks on a transaction it can see was card-not-present, then returns an approval or a .
- The result is shown and captured. The operator sees the outcome immediately, and the approved amount is captured either at once or later, depending on how the is configured.
- Funds settle through the normal cycle. The transaction joins the merchant's regular batch alongside payments taken through other channels.
Why it matters
Virtual POS covers the orders that never pass through a checkout page. A customer who calls to place a repeat order, a client paying an emailed invoice by card, and a field rep closing a deal at a trade stand all sit outside a hosted , and each of them still needs an authorization.
It also removes a fixed cost from low-volume acceptance. A merchant taking a handful of card payments a week doesn't need to rent, install, and maintain a terminal for that volume when a login covers the same job.
The tradeoff sits in the risk profile. Keyed transactions carry no chip or contactless proof that the card was present, so issuers decline them more readily, and a cardholder who claims they never authorized the payment leaves the merchant defending a charge with no device-level evidence behind it. and the card security code are the main signals available to support the authorization.
Common issues
- Higher decline rates. Issuers treat keyed entry as riskier than a chip read, and an authorization with a mismatched billing address is a frequent decline trigger.
- Manual entry errors. A mistyped digit produces a failed authorization, and a mistyped amount produces a payment the merchant has to void or .
- Internal fraud and misuse. Staff logins that can charge any card need permission limits and an audit trail, since the operator holds the full card number during entry.
- Card data handled by people. Card numbers read aloud on a call or written on an order sheet sit outside the protection that gives stored credentials, which is what keeps virtual POS inside the merchant's PCI compliance scope.
- Weaker dispute position. Without a card read or a authentication, liability for a fraud claim usually stays with the merchant.


