Recognizable context
Use the business name the customer expects and a short description of the order, appointment, invoice, or other interaction. Avoid vague urgency or language that pressures the recipient to click immediately.
Virtual terminals, invoicing and payment links
Yes. Some payment-link products let a business copy a hosted checkout URL and send it to a customer by text message. The text delivers the link; the customer opens the provider-hosted payment page and enters payment details there. Sensitive payment information should never be requested or collected inside an ordinary text conversation.
The exact sharing controls, link settings, checkout fields, receipts, and reporting tools vary by provider. Confirm the workflow shown inside the business's authenticated account before using it with customers.
Current Stripe documentation lists text messages as one place a merchant can share a Payment Link. Current Square documentation says a payment link can be copied or shared by text from Square Point of Sale. These are current product examples, not a promise that every payment platform, account, device, or messaging setup offers the same option.
A texted payment link is best understood as a route to checkout. It is not a request for the customer to reply with a card number, security code, password, bank credential, or other payment detail. The hosted page should handle the checkout interaction.
Use the business name the customer expects and a short description of the order, appointment, invoice, or other interaction. Avoid vague urgency or language that pressures the recipient to click immediately.
Explain that the link opens a hosted payment page. If the message was unexpected, tell the customer how to contact the business through a known website or phone number before opening it.
Keep full card numbers, security codes, passwords, bank credentials, complete account numbers, and secret keys out of the message. Use a non-sensitive order reference only when it helps the customer recognize the request.
The FTC warns that phishing texts can impersonate familiar organizations and use links to seek sensitive information. A plain, expected, verifiable message helps the customer distinguish a legitimate business request from an unexplained link.
Review the link in the provider's authenticated dashboard before it leaves the business. Confirm that it opens the intended checkout, displays the correct business identity and description, and uses the expected amount behavior. Check whether the link is active, reusable, limited to a particular purpose, or associated with a specific customer or order.
Do not infer one provider's settings from another provider's documentation. A feature demonstrated by Stripe or Square may work differently elsewhere. For related planning, read whether a payment link can be reused and compare the documented controls for the product actually being evaluated.
Send the message only through a business-approved workflow and make sure staff know which account, phone number, or messaging tool they should use. A consistent sender identity and message format can make legitimate requests easier for customers to recognize. Keep an ordinary customer-service path available for someone who cannot open the link or wants to confirm it independently.
Test the flow with non-sensitive test information before relying on it. Review the message on a small screen, open the link using a supported mobile browser, and confirm that the checkout does not overflow or hide essential instructions. Then verify how the provider records the result and how staff connect that result to the correct order.
Email can be another delivery channel when it better fits the customer's workflow. The guide to sending payment links by email covers the same separation between message delivery and hosted checkout.
Never ask a customer to reply to a text with cardholder data, a security code, password, bank credential, full account number, or secret API key. The text should carry only the checkout link and limited business context. Payment entry belongs on the provider's designated hosted page.
Limit dashboard and messaging access to workers who need it, use individual staff accounts where the product supports them, and verify results inside the authenticated payment system. If a customer reports an unexpected message, staff should use a known contact method and the provider's account records to investigate rather than asking the customer to forward sensitive information.
This page addresses the operational payment-link workflow, not consent, telecommunications, or other legal requirements. Businesses should use their own approved customer-messaging policies and qualified guidance for obligations that apply to their messages.
No. An ordinary text conversation is not the payment-entry screen. The customer should enter payment details only on the verified hosted checkout page provided for that transaction.
No. Message delivery and payment confirmation are different events. Check the provider's authenticated dashboard or approved order system for the transaction result.
That depends on the link type and provider settings. Some links are reusable, while others are tied to a particular invoice, customer, amount, purchase limit, or status. Confirm the current settings before resending.
Give the customer a way to verify the request through a phone number or website they already trust. Do not pressure them to open an unexpected link.
Document who creates the link, which details staff verify, how the text identifies the business, where customers enter payment information, and how the team confirms the result. Then compare that workflow with current provider documentation.
Continue with the Virtual Terminals, Invoicing and Payment Links FAQ hub or review ways to reduce checkout abandonment. For general help, contact Payments Max without sending cardholder data, passwords, bank credentials, complete account numbers, or secret API keys.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US