Transitions and provider reviews

Arrange a saved-card transfer through the providers

Ask the outgoing provider to arrange its documented processor-to-processor transfer, with the intended receiving processor identified and the scope confirmed. When Stripe is the outgoing provider, its export documentation limits card-data transfers to another PCI DSS Level 1 processor; it excludes Link credentials, payment history, and other objects. Do not download or email a card-data file as an ordinary migration task. Keep your role to authorizing the request through the provider's process and tracking what the providers actually confirm.

For: A research-only merchant evaluating a provider change after the proposed new provider asks for saved payment credentials.

Updated 2026-10-01

Identify who will receive the credentials

A request from a new agency or payment supplier does not identify the processor that would receive the data. Record the outgoing provider, the proposed recipient's legal or service identity, and the person authorized to discuss the merchant account. Ask the outgoing provider to confirm that the named destination can use its transfer process before treating the request as ready.

Stripe's documented restriction is specific: its card-data export goes to another PCI DSS Level 1 processor. A statement that the new store has a secure checkout does not establish that the named recipient meets that condition. If Stripe is not the outgoing provider, obtain that provider's own documented migration route; do not substitute Stripe's process or infer a matching recipient requirement.

Authorize the process without taking custody of the file

Use the outgoing provider's established account-support route to identify the migration procedure and the authorization it requires. Have the receiving processor coordinate the technical destination through that procedure. Keep a case reference and the written scope in your migration notes. These are records of a request, not the payment credentials themselves.

The PCI Security Standards Council's FAQ says unprotected primary account numbers must not be sent through email, instant messaging, SMS, or chat. This is a restriction concerning card numbers, not a ban on ordinary messages about the project. A message can name the providers, the request reference, and the unresolved scope without containing card data.

Do not give a new contractor your login, API secrets, or a customer export as a substitute for the documented transfer. If the request still says to send a card-data file to a person, pause that handoff and ask the outgoing provider to reconcile it with its migration instructions. Changing the file name or delivery label does not establish an approved route.

Separate transferable credentials from the rest of the move

For a Stripe export, record Link credentials as excluded. Record payment history and other objects as excluded as well. Those exclusions matter before the store promises returning buyers that all saved payment options will be available after the change. The transfer request cannot establish continuity for data it does not include.

Maintain a separate list of ordinary operational records the business still needs, with their actual export or retrieval arrangements. A report used to reconcile old orders answers a different question from a credential transfer. Neither a report nor an order export is evidence that the receiving processor can use a saved card.

Ask both providers to state what their completion messages will establish: which agreed scope was sent, which was received, and which exceptions remain. Ask the store implementer separately how the received data will connect to the intended customer workflow. Until those answers exist, leave availability of saved cards at the new checkout unconfirmed.

Make the next decision from the unresolved dependency

If the recipient or transfer route is unconfirmed, the next action is to resolve that requirement with the outgoing provider. If the route is confirmed but scope excludes credentials buyers currently use, the next action is to document the affected checkout journey with the receiving provider and implementer. If the transfer is reported complete, compare that report with the agreed scope before describing the migration as complete.

Prism's processing consultation can help organize the business description and the processing question. Bring the website, research-only products, the two providers' names, and a non-sensitive summary of the migration dependency. Confirm any migration assistance, responsibilities, fees, and terms before work. The inquiry follows up by email and does not submit a processing application; credential transfer also does not establish the receiving provider's approval of the business.

Credential migration authority and scope map

Complete this with references to provider instructions and actual replies, never with payment credentials. An unidentified recipient or undocumented transfer route leaves the handoff unresolved. Exclusions need their own continuity decision even after a transfer is confirmed.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Credential migration authority and scope map. The last column is for temporary notes.
Migration itemEvidence to locateDecision supportedYour record
Outgoing providerThe account relationship and its official credential-migration instructions.Use the procedure of the provider holding the credentials; a store export menu is not that procedure.
Proposed receiving processorThe processor's identity and outgoing provider's confirmation of the destination.For a Stripe export, the destination must be another PCI DSS Level 1 processor.
Documented transfer routeThe provider procedure and migration case reference, without secrets or transfer tokens.Proceed through that route; resolve any request for a merchant-forwarded file before handing data over.
Excluded data typesThe scope and exclusions stated for the actual transfer.Stripe excludes Link credentials, payment history, and other objects; do not promise they will arrive.
Authorized account contactThe merchant role responsible for the request and the provider's authorization instructions.Assign someone able to authorize the request without sharing their account credentials.
Completion and remaining dependenciesSending and receiving confirmations tied to the agreed scope; implementer's outstanding questions.A requested transfer is not a received transfer or proof that the new checkout can use the data.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Stripe's recipient rule and export exclusions apply to Stripe exports, not automatically to another provider.
  • This worksheet records authority and scope; it is not a place to enter card numbers, authentication codes, passwords, API secrets, or customer records.
  • A completed transfer does not establish processing eligibility, legal clearance, or uninterrupted saved-card availability.

Sources

  • Stripe payment data export — checked 2026-09-21. Stripe transfers card data only to another PCI DSS Level 1 processor through its process. Link credentials, payment history, and other objects are excluded.
  • PCI SSC FAQ 1085 — checked 2026-09-21. Unprotected primary account numbers must not be sent through email, instant messaging, SMS, or chat. This concerns card numbers rather than all migration correspondence.
  • Prism solutions — checked 2026-09-21. Prism offers storefront review, card-processing preparation, and help with a provider's website questions. Scope, fees, and terms are discussed before work; the provider decides eligibility and account terms.
  • Prism contact — checked 2026-09-21. The form asks for the website, products, and question, excludes payment card details, passwords, and customer records, and leads to email follow-up. A request does not book an appointment, purchase a service, or submit a processing application.

Discuss my processing options

Want to talk through your own processing situation?