Processing choices

Describe the phone order and the keyed payment separately

Disclose the ordering channel and the payment-entry channel as separate facts. Say whether staff take an order by phone, whether staff actually key card details, which provider tool receives the payment, and whether the channel is live or proposed. A manually created WooCommerce order does not establish a manually keyed card payment. Trace the order to its payment record and buyer confirmation, describe the shipment promise that accompanied it, and identify any unanswered provider question. Keep card numbers and verification codes out of the worksheet and inquiry.

For: An owner or authorized representative of a research-only merchant whose orders may be taken by phone or paid through a staff-operated card tool.

Updated 2026-10-01

Follow the order beyond its method of entry

Start with the real path from the buyer’s request to the payment record. Record the staff role that accepts the order, the system that creates the order, and who enters payment details into which tool. Use roles and tool names, not employee credentials or customer data. An order taken by phone can still be paid by the buyer through a separate payment page; it should not be described as staff-keyed unless staff actually enter the card details.

WooCommerce documents both customer-created checkout orders and orders added manually in WP Admin. That explains how an order record can exist, but it does not identify how the payment was made. Inspect the corresponding provider record or obtain confirmation from the person responsible for the tool. If only the store order is available, mark payment entry unconfirmed instead of classifying it from the word manual.

Identify the records this channel actually produces

For an existing channel, locate its order record, provider payment record, and buyer-facing receipt or confirmation. Keep private references in the business’s own systems and put only the record type and location in the worksheet. Check whether the payment reference can be matched to the order and whether the buyer receives the same seller name, amount and order description that staff recorded.

An order acknowledgment and a payment receipt answer different questions. The first can confirm what was ordered; the second must be read for the payment state it actually reports. If the channel produces no store order or no retrievable buyer confirmation, disclose that gap. For a proposed channel, describe the intended records as planned rather than claiming they already exist.

Describe code handling without collecting codes in the inquiry

The PCI SSC FAQ permits requesting a card verification code for a card-not-present authorization and states that PCI DSS Requirement 3.3.1.2 prohibits storing that code after authorization, even when encrypted. Retaining it for later orders is therefore not part of a repeat-order record.

Document the responsible system and the person who can confirm its handling. Do not prove the process by copying a code or card number into an order note, screenshot, worksheet or consultation message. The prohibition here concerns post-authorization verification-code storage; it does not establish that a primary account number can never be stored under any compliant arrangement. A tool’s existence also does not establish that this channel is permitted on your merchant account.

Keep the telephone shipment promise in the channel description

A telephone order can carry a shipment promise even when it never passes through the website’s checkout. Record what ship time staff actually stated, where that promise is documented, and which inventory or fulfillment records supported it. Distinguish handing merchandise to the carrier from its arrival with the buyer.

Where the US FTC Mail, Internet, or Telephone Order Merchandise Rule applies, the seller needs a reasonable basis for the stated ship time. The usual unstated-time provision is 30 days after a properly completed order, with a 50-day provision when the buyer applies to the seller for credit. If the applicable time cannot be met, the rule requires a delay-consent or cancellation-and-prompt-refund choice. Its definitions treat shipment as placement with the carrier. Applicability must be assessed separately; this is not a conclusion that every business-to-business research-only order falls under the rule.

Write the disclosure from the completed record

Build the inquiry sentence from the channel’s status, ordering method, staff role, payment-entry tool and account holder. Follow it with the record and receipt locations, the shipment-promise basis, and the specific question the provider must answer. Say explicitly when staff only create the order and the buyer enters payment details elsewhere. Do not let a description of online checkout stand in for the additional channel.

The result is ready for a processing discussion when the description distinguishes observed facts from proposed steps and names unresolved items without guessing. Prism can help organize that description within a scoped processing consultation. Scope, responsibilities, fees and terms are discussed before work; the provider determines eligibility and account terms. Prism’s public inquiry is not a processing application. Send the website, product types and channel question, without payment data or customer records.

Keyed-order channel record

Complete one copy for each actual or proposed phone/keyed workflow. Write live, planned or unconfirmed beside the facts you record. If the order and payment cannot be connected, disclose the missing link; do not fill it with an assumed checkout path.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Keyed-order channel record. The last column is for temporary notes.
Channel factRecord to inspectInterpretation for the inquiryYour record
Ordering and payment-entry rolesThe actual order path and the staff-operated tool, if any.Separate who records the order from who enters payment details; name the tool without copying card data.
Provider payment recordThe record type and location associated with this channel’s orders.A manually added store order alone does not identify a keyed payment.
Buyer receipt or confirmationThe confirmation actually sent and the matching provider record.Identify whether it acknowledges an order, reports a payment state, or does both.
Telephone shipment promiseThe stated ship time and inventory or fulfillment evidence behind it.Record the promise made on the call, not an assumption that online policy text was communicated.
Verification-code handlingThe responsible system and confirmation of its handling after authorization.No post-authorization code storage, even encrypted; put no code or card number in this sheet.
Channel status and disclosure sentenceThe verified facts above and any written provider response.Write a factual sentence naming live or planned status, order entry, payment entry and the exact permission question.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • This worksheet describes a channel; it is not a card-collection procedure or proof that a provider permits keyed transactions.
  • FTC rule applicability depends on the transaction and jurisdiction. The shipment summary is not a legal determination for a particular sale.
  • Keep card numbers, verification codes, customer records and credentials out of the worksheet and public inquiry.

Sources

  • WooCommerce managing orders — checked 2026-09-21. WooCommerce orders can originate at checkout or be added manually in WP Admin; manual order creation does not identify the payment-entry channel.
  • PCI SSC card-verification FAQ — checked 2026-09-21. PCI DSS prohibits storing card verification codes after authorization, even encrypted; a code may be requested for a card-not-present authorization.
  • FTC Mail, Internet, or Telephone Order rule, definitions — checked 2026-09-21. The rule addresses mail, internet or telephone ordering regardless of payment method and defines shipment as placing merchandise with the carrier. Applicability is not determined here.
  • FTC Mail, Internet, or Telephone Order rule, seller duties — checked 2026-09-21. Where applicable, the rule requires a reasonable shipment basis and a delay-consent or cancellation/refund choice; it includes the 30-day default and seller-credit exception.
  • Prism solutions — checked 2026-09-21. Prism offers processing preparation within agreed scope; the provider determines eligibility and account terms.
  • Prism contact — checked 2026-09-21. The consultation form takes a website, products and question, excludes sensitive records and does not submit a processing application.

Discuss my processing options

Want to talk through your own processing situation?