📞 +91 9092778767  ·  +91 9080441242   |   ✉ [email protected]
Guhan Capitals
🏠 Home ✍️ Blog 🛡️ Insurance 💳 Credit Cards 📋 Track Application ❓ FAQ 📞 Contact Apply for a loan → 💬 WhatsApp us
← Back to blog Credit Cards

RBI Card Tokenisation Explained: Why Your Card Number Disappeared From Websites

If online checkout suddenly stopped showing your saved card number in full, replaced instead by a masked number or a generic "saved card" label, this isn't a glitch or a downgrade in convenience, it's a deliberate, RBI-mandated security change worth understanding clearly.

What Changed and Why

Since October 2022, merchants and their payment service providers are no longer permitted to store your actual card number, CVV, or expiry date for processing future transactions. Instead, the system uses tokenisation, your card details are replaced with a unique token, a substitute number tied specifically to your card, the specific merchant, and the specific device or app, that has no independent value if it were ever leaked or stolen.

How Tokenisation Actually Works From Your Side

When you choose to save a card for future purchases on a specific website or app, instead of the merchant storing your actual card number, a token is generated and stored in its place, when you later use this saved card, the merchant sends the token, which is then converted back to your actual card details only by the card network or your issuing bank, never by the merchant itself.

Why This Genuinely Improves Your Security

Since merchants no longer hold your actual card details at all, a data breach at a specific merchant's systems, a genuinely common source of large-scale card fraud historically, can no longer expose your real card number, since it was never stored there in the first place. This is a meaningfully stronger security position than the previous system, where your actual card details sat on potentially thousands of different merchant servers with varying security standards.

A Brief Exception for Settlement Purposes

Merchants and payment processors are permitted to retain your card data for a very limited period, up to four days, or until the transaction settles, whichever comes first, specifically to complete legitimate settlement and post-transaction processes, this narrow exception doesn't undermine the broader rule against ongoing storage.

What This Means Practically When You Shop Online

You'll typically be asked to opt in to tokenisation the first time you save a card on a new website or app, once tokenised, your saved card shows only a masked number (commonly the last four digits) at checkout, future purchases through that same saved token don't require re-entering your full card details each time, preserving the original convenience while removing the underlying security risk.

Do You Need to Re-Tokenise Your Card for Every Website Separately?

Yes, tokenisation is specific to each individual merchant and device combination, a card saved and tokenised on one shopping app doesn't automatically extend to a different website, you'll need to go through the tokenisation process (typically a simple opt-in during checkout) separately for each merchant where you want to save your card for future use.

What Happens If a Merchant's Systems Are Breached Now?

Since the merchant only ever held a token, not your actual card details, a breach at that merchant exposes only tokens tied specifically to that merchant, which have no usable value anywhere else, this significantly limits the damage a single merchant breach can cause compared to the pre-tokenisation era, when actual card numbers stored across many merchants represented a much larger combined exposure risk.

2026 Compliance Deadlines Worth Being Aware Of

RBI's more recent directions have set an April 1, 2026 compliance deadline focused on strengthening authentication requirements across the digital payment ecosystem, continuing to build on the original tokenisation framework, this reflects an ongoing regulatory push toward stronger digital payment security more broadly, not a one-time change that's now complete and unchanging.

Frequently Asked Questions

Do I have to use tokenisation, or can I still enter my card details manually every time?

Tokenisation for saved cards is optional, you can always choose to enter your card details manually for each transaction instead of saving a tokenised card, though this removes the convenience of a saved payment method for future purchases on that specific site.

Does tokenisation apply to cards saved before the rule came into effect?

Merchants were required to delete previously stored card data and transition to the tokenisation system, if you're prompted to re-add or re-tokenise a card you'd previously saved, this is the expected result of that required transition.

Is my card less convenient to use now because of tokenisation?

The practical checkout experience for a tokenised saved card remains largely similar to before, a masked number and a quick confirmation, the main visible difference is not seeing your full card number displayed, the underlying convenience of not re-entering full details each time is preserved.

Does tokenisation protect against all types of card fraud?

No, tokenisation specifically protects against merchant-side data breaches exposing your actual card details, it doesn't protect against other fraud types like phishing or OTP-sharing scams, the broader precautions discussed in our fraud protection guide remain equally important.

Chat with us