💳 Compliance & Data Privacy

Can a Daycare Keep Credit Cards on File? PCI Rules for Childcare Tuition

Autopay is what parents ask for and what steadies your cash flow. Here's how to offer it without your center ever holding a card number — and how to clean things up if it already does.

By Eshan de Silva · · 8 min read

A parent hands you their card at pickup and says, "just keep it on file and run it on the first." It's a kind offer and it solves a real problem — chasing late tuition is nobody's favorite Monday. But the moment that card number lands on an enrollment form, in a spreadsheet, or in the front-desk binder, your center has taken on an obligation most directors never signed up for. The good news is that you can give parents exactly the autopay they want while your center never touches a card number at all.

This guide covers what the payment card rules actually require, the one piece of data you can never keep no matter who gives you permission, where card numbers quietly hide in a childcare center, and a practical cleanup plan if yours is already holding some.

Quick note: This article is general guidance, not legal advice. Your obligations depend on your merchant agreement, your processor, and how you accept payments. Confirm specifics with your payment processor and, where money and liability are involved, your attorney.

The short answer

Yes, you can offer card-on-file billing. No, your center should not be the thing storing the card. Every modern payment processor and childcare billing platform can hold the card in its own secure vault and hand you back a token — a meaningless reference code that charges the right card on the first of the month without ever revealing the number. Your staff see the last four digits and a card brand. That's it.

That single design choice is the difference between a compliance question you can answer in one sentence and a filing cabinet full of liability. It costs nothing extra — tokenized card-on-file is standard in every reputable processor and childcare billing tool on the market.

What PCI DSS is, and why it applies to a preschool

The Payment Card Industry Data Security Standard (PCI DSS) is the rulebook every business that accepts cards agrees to follow. It isn't a federal statute — it reaches you through the merchant agreement you signed with your bank or processor, which is precisely why it's easy to miss. Nobody from the state inspects you for it. Your processor simply has the contractual right to pass down card brand fines, raise your rates, or stop processing your payments if card data leaks on your watch.

The current version is PCI DSS v4.0.1, which took full effect on March 31, 2025. The practical shape of it for a small merchant: the less card data you touch, the less of the standard applies to you. A center that has fully outsourced card handling to a compliant third party and keeps no electronic account data validates with a short self-assessment questionnaire (SAQ A) — a handful of questions, not a security audit. A center typing card numbers into its own spreadsheet is in an entirely different category, with dozens of technical requirements it almost certainly can't meet.

The rule that surprises people: the three- or four-digit security code on the card (the CVV or CVC) may never be stored after a transaction is authorized — not for autopay, not for recurring billing, not for convenience. The PCI Security Standards Council addresses this directly, and adds that a customer's permission "has no validity for PCI DSS and does not constitute an allowance to store the data." A signed parent authorization form does not make it okay.

Where card numbers actually hide in a childcare center

Almost no center sets out to build a card database. It happens one helpful moment at a time. When we look at a center's setup, these are the five places we nearly always find card data:

  • The enrollment packet. A "payment authorization" page with blanks for the card number, expiration, and security code — then filed in the child's folder for years.
  • Email and text. A parent photographs their card and texts it to the center phone, or emails the number when a payment bounces. It then lives in that inbox forever, and in the sent folder of whoever forwarded it.
  • The front-desk spreadsheet. Usually created by a well-meaning office manager so nobody has to ask families twice.
  • Voicemail and call notes. Parents read card numbers into voicemail, and modern phone systems transcribe voicemail into email — quietly turning a phone message into a stored document.
  • Shared logins to the payment portal. One password everyone at the desk knows, no multi-factor authentication, still working for a teacher who left in March.

The last one is worth sitting with. Even with a perfectly compliant processor doing all the storage, a shared, unprotected login to the billing portal hands an attacker refunds, payout redirection, and every family's payment history. Turning on multi-factor authentication for the payment portal is the highest-value ten minutes in this entire article.

What a clean setup looks like

  • Parents enter their own card, on the processor's page. Whether that's a link in your billing platform, a parent portal, or a hosted checkout page, the card should travel from the parent's fingers to the processor without passing through your staff or your network.
  • Your system stores a token, never a number. Confirm with your vendor in writing that card data is vaulted on their side and that you hold only tokens and the last four digits.
  • Offer ACH bank transfer for recurring tuition. Processing fees on ACH are typically a flat amount rather than a percentage, which on a monthly tuition figure is a meaningful saving. Bank details still deserve the same tokenized treatment.
  • Nobody accepts a card by email, text, or voicemail — ever. Have a one-line reply saved: "For your security we can't take card details by text — here's your payment link."
  • Portal access is named, role-limited, and MFA-protected. Individual logins, refunds restricted to the director, access removed the day someone leaves.
  • Your card-present terminal is checked. If you take cards at the desk, look at the reader monthly for tampering or an unfamiliar attachment, and keep it on a network segment away from the family Wi-Fi.

Setting this up once and keeping it that way is exactly the kind of quiet background work EDCON's managed IT services handle for childcare centers across Los Angeles, Oxnard, Ventura, and Azusa — portal access, MFA, device security, and the vendor questions nobody enjoys asking.

A cleanup plan if you're already holding card numbers

Don't panic, and don't try to do it in one evening. Work through it in order:

  • 1. Stop the inflow first. Remove the card fields from the enrollment packet today and replace them with a payment link or QR code. Tell the front desk the new rule out loud, not in a memo.
  • 2. Move active families to tokens. Send every current family a secure link to re-enter their card themselves. Frame it as a security upgrade, because it is — parents respond well to it.
  • 3. Destroy the paper. Cross-cut shred the old authorization pages once families are re-enrolled. Do not scan them first; that converts a filing cabinet problem into a searchable cloud problem. If a form has other information you need to keep, redact the card fields before scanning — the free PDF tools at SenCreator.app handle that without another subscription, and our paperless records guide covers the scanning workflow around it.
  • 4. Sweep the digital corners. Search your email for card-number patterns, delete the messages and empty the deleted items, clear voicemail transcripts, and delete that spreadsheet from every place it was ever copied to.
  • 5. Lock the portal. Individual logins, MFA on, old accounts removed, refund permissions limited.
  • 6. Write it down. One page: how we take payments, what we never accept, who has access. New staff read it on day one.

What's at stake if card data leaks

Three separate consequences stack up. First, the contractual one: card brand fines and investigation costs are passed to you through your processor, and your merchant account can be terminated. Second, the state one: California requires a business to notify affected residents when unencrypted personal information is acquired by an unauthorized person, and if a single breach requires notifying more than 500 California residents, a sample copy of that notice must also be submitted to the California Attorney General. For broader consumer-privacy obligations, see our CCPA guide for California small businesses.

Third, and hardest to price: childcare runs on referrals. A letter telling forty families that their card numbers were taken from your office does damage that no fine schedule captures. The FTC's Protecting Personal Information guide for business puts the principle plainly, and it's the right one here: if you don't need it, don't collect it — and if you must collect it, don't keep it.

Questions worth asking your billing vendor

Before you sign with a childcare billing or payment platform, send these five by email so the answers are in writing: Are you a PCI DSS validated service provider, and can you send your current attestation? Is card data tokenized so we never store a number? Which self-assessment questionnaire does our center qualify for using your product? Do you support multi-factor authentication and per-user roles for our staff? And if we leave, what happens to our families' stored payment methods? A vendor that answers these quickly and specifically is telling you something useful; one that deflects is telling you something more useful still. Our childcare app vendor vetting guide has the longer version of this checklist.

Common questions about cards on file

Can a daycare keep parents' credit card numbers on file?

You can offer card-on-file autopay, but your center shouldn't be the one holding the number. Let your processor or billing platform vault the card and give you a token that charges it without revealing it, so staff only ever see the last four digits. Card numbers on enrollment forms, in spreadsheets, or in a front-desk binder put the full PCI DSS burden on your center — and create a breach you would have to report.

Can we keep the CVV if the parent gives written permission?

No. The PCI Security Standards Council states that card verification codes must not be stored after authorization, including for card-on-file and recurring billing, and that a customer's permission carries no validity under PCI DSS. A signed authorization form doesn't change it — the code has to come out of your systems, paperwork, and email.

Is PCI compliance a law for California childcare centers?

PCI DSS is an industry standard rather than a statute, and it reaches you through the merchant agreement you signed with your processor or bank. That contract still bites: fines passed down from the card brands, higher rates, or losing the ability to accept cards. California's breach notification law applies separately when unencrypted personal information is acquired by an unauthorized person.

What do we do with old forms that have card numbers on them?

Re-enroll those families through your processor's own payment page, then cross-cut shred the old authorization pages. Don't scan them as-is — that turns a paper problem into a searchable digital one. Redact the card fields on anything you need to keep, remove the card field from the enrollment packet so the pile stops growing, and check old emails, texts, and voicemail transcripts for numbers still sitting there.

Not sure where your center's card data actually lives?

EDCON helps California childcare centers get tuition billing onto a tokenized, MFA-protected setup — then finds and clears the card numbers hiding in old forms, inboxes, and spreadsheets. Book a free 30-minute consultation and we'll walk your setup with you, no pressure.

Book a Free Consultation