Credit card machines do not store your information in any usable, lasting way. The terminal reads your card number, name, and expiration date long enough to request authorization from your bank, encrypts that data the moment it’s captured, and then flushes it from memory once the transaction clears. Industry rules flatly prohibit terminals and merchants from keeping the most sensitive pieces (your PIN, your security code, or the full contents of the magnetic stripe or chip) after a sale is authorized.
That’s the short answer. The longer answer matters because the protections work differently depending on how you pay, what the merchant does afterward, and whether someone has tampered with the reader itself.
What the Terminal Reads and How Long It Holds It
When you swipe, dip, or tap, the reader captures your primary account number (the 15 or 16 digits on the front), your name, the expiration date, and service codes that tell your bank how to handle the request. That’s the working set. It’s enough for the merchant’s system to format an authorization request and send it through the payment network.
That data lives in the terminal’s volatile memory (RAM) only while the transaction is actively processing. Once authorization comes back, the data is flushed. If the terminal loses power in the middle of a sale, volatile memory clears itself. Terminals do have permanent flash storage inside them, but that space holds the operating system and the payment software, not a database of customers.
The card technology matters here. A magnetic stripe transmits the same static data every time you swipe, which is why swiped transactions have historically been the easiest to clone. An EMV chip generates a unique cryptogram for each purchase, so even a perfectly intercepted transaction can’t be replayed. That’s why terminals now prompt you to insert instead of swipe.
What Merchants Are Forbidden From Storing
The Payment Card Industry Data Security Standard (PCI DSS) sets the rules for what can and cannot be kept after a transaction is authorized. It isn’t a federal law. It’s an industry framework written by Visa, Mastercard, American Express, Discover, and JCB, enforced through the contracts merchants sign with their banks and processors. In practice it functions like regulation, because the penalties are severe.
Three categories of data must never be stored after authorization, even in encrypted form:
- The full magnetic stripe or chip track data
- Card verification codes (the CVV2, CVC2, or CID printed on the card)
- PINs and PIN blocks
Encrypting these does not create a loophole. The standard is explicit that sensitive authentication data must not exist on merchant systems in any form once the sale is approved.1PCI Security Standards Council. PCI Data Storage Dos and Donts
Merchants who slip out of compliance face fines from the card networks that can reach $500,000 per incident, monthly penalties from their acquiring banks, and ultimately the loss of their ability to accept card payments at all. That last consequence is why compliance is treated seriously by any business that survives on card revenue.
Encryption and Tokenization Keep the Merchant Blind
Two layers keep your actual card number from ever sitting in plain form on a merchant’s system. The first is point-to-point encryption. Your card data is scrambled at the read head, the instant the terminal captures it. It travels through the merchant’s network in a form that’s meaningless without the decryption key, which only the payment processor holds. The store’s own systems never see your real number.
The second layer is tokenization. After authorization, the real account number is replaced with a random alphanumeric string. Merchants can keep that token for returns, recurring charges, and recordkeeping. A thief who steals the token gets nothing usable, because it only works within the specific merchant-processor relationship that generated it and can’t be reverse-engineered back to your card.
Tap-to-Pay and Mobile Wallets Leave the Smallest Trace
Contactless payments through NFC send the terminal a token plus a one-time dynamic authentication code instead of your card number. Every tap generates a fresh code. Intercepting one gives an attacker nothing to reuse.
Mobile wallets like Apple Pay and Google Pay go further. Your real card number is never stored on your phone and never transmitted to the terminal. During setup, the wallet swaps your card for a device-specific token, and that token is all the reader ever sees. If you’re weighing which payment method exposes you least, the wallet on your phone is the answer.
What the Receipt Is Allowed to Show
Federal law limits what a printed or digital receipt can display. Under the Fair and Accurate Credit Transactions Act, an electronically printed receipt can show no more than the last five digits of your card number, and it cannot show the expiration date at all.2Office of the Law Revision Counsel. 15 U.S. Code 1681c – Requirements Relating to Information Contained in Consumer Reports Most merchants print only the last four. Transaction IDs, timestamps, and dollar amounts stay on the receipt for accounting and dispute purposes, but none of that is enough to charge your account.
Where the Real Risk Lives: Skimmers and Shimmers
The terminal itself may be designed to purge your data, but criminals attach their own hardware to grab it before the terminal’s protections engage. Skimmers are external devices placed over or inside a card reader slot. They record stripe data as you swipe, and modern versions transmit it over Bluetooth so the thief never has to come back.
Shimmers are the chip-era version. Paper-thin circuit boards slip inside the chip slot, sit between your card and the reader, and intercept chip data during insertion. Because they hide inside the device, they’re much harder to spot than an overlay skimmer.
Legitimate terminals fight back through hardware protections defined by the federal FIPS 140-3 standard. At Security Level 3, a terminal must include tamper-response circuitry that destroys all encryption keys and sensitive data the instant someone opens the device or accesses a maintenance port.3NIST CSRC. FIPS 140-3 Section 5 – Physical Security Cracking one open to install a shimmer triggers a self-wipe.
You can protect yourself with a few habits. Wiggle the card reader before inserting your card; legitimate readers are firmly mounted, and anything loose, misaligned, or protruding is a warning sign. When contactless or a mobile wallet is available, use it. Your card never enters the slot, so the slot can’t attack it.
What You Owe if Your Data Is Stolen Anyway
Breaches happen despite the layers above. Federal law caps your losses, but the caps are very different for credit and debit.
For credit cards, the Truth in Lending Act limits your liability for unauthorized charges to $50, and the burden falls on the issuer to prove even that $50 applies.4GovInfo. 15 U.S. Code 1643 – Liability of Holder of Credit Card Most major issuers go further with zero-liability policies that waive the $50 entirely, so credit card fraud usually costs you nothing.
Debit cards are riskier because the protections under Regulation E depend on how fast you report:
- Report within 2 business days: liability capped at $50.
- Report after 2 business days but within 60 days: liability rises to $500.
- Report after 60 days: unlimited liability for unauthorized transfers that happen after the 60-day window.
The clock starts when your bank sends the statement showing the unauthorized transfer, not when you personally spot it.5Consumer Financial Protection Bureau. Regulation E 1005.6 – Liability of Consumer for Unauthorized Transfers People who don’t read their bank statements can blow past 60 days without knowing it and lose far more than they ever would on a credit card.
If You Suspect Your Card Was Compromised
There is no single federal law that requires a merchant to notify you after a point-of-sale breach. All 50 states and the District of Columbia have their own notification statutes. Roughly 40 percent set specific deadlines between 30 and 60 days after discovery; the rest require notice without unreasonable delay.
Don’t wait for a letter. If you think your card was exposed at a particular retailer, check your statements now, dispute any charge you don’t recognize, and ask your issuer to send a new card with a new number. Cutting off the old number ends whatever exposure is still in motion.