Cards on File and Recurring Billing
Where to find it: Dashboard > Manage Accounts > open the customer > Financial Information > Credit Card Account / Payment Methods & Billing Schedule
Keeping a customer's card on file means you can charge them without the card in the room — a phone order, a member's monthly locker fee, a regular who says "just put it on my card." TORO stores nothing sensitive itself: the card lives in your processor's secure vault, and TORO only ever sees the brand, the last four digits, and the expiration date.
This feature requires Paya (PayaConnect). Cards on file work on other processors in a limited way, but recurring billing schedules do not — on USAePay, TORO will tell you to contact Support about switching to Paya Connect.
Read This First: Do You Actually Need a "Card Not Present" Account?
Most shops do not, and setting one up when you don't need it costs you real money every year. Read this before you create a Card Not Present account.
There are two kinds of card-on-file account (explained in detail below): Card Present, for customers standing at your register, and Card Not Present, for charges where the card isn't physically there — phone orders, and especially online sales.
A Card Not Present account for a tobacco shop is a "high-risk" account, and the card networks charge an annual fee to register one:
| Network | Annual registration fee |
|---|---|
| Visa | $950 / year |
| Mastercard | $500 / year |
| Total | ~$1,450 / year |
None of this money goes to TORO, and none of it goes to your credit card processor. It is a compliance fee set by Visa and Mastercard for high-risk (tobacco) card-not-present sales, and it goes entirely to them. Neither we nor your processor make a cent on it. It renews every year, not just once. (The good news: Visa exempts card-not-present tobacco merchants from their extra per-transaction assessments.)
So here's the rule of thumb:
Selling cigars online? A registered Card Not Present account is mandatory. There's no way around it and no threshold — if cards are being charged over the web, you must be registered. Get the account.
Not selling online, and your phone / mail-in card charges are under about 5% of your monthly transactions? You almost certainly don't need a separate Card Not Present account. Just store those cards on your Card Present (Retail) account and charge them there. Skip the $1,450/year.
Somewhere in between? Weigh the volume against the $1,450/year. If a handful of phone charges a month is all you have, the Retail account covers it.
Fees change, and every processor quotes them a little differently. Confirm the current numbers before you decide:
➡️ Confirm the latest fees with Google
Card Present vs. Card Not Present
The first thing to understand, because it trips people up: a customer can have two separate processor accounts, and they don't share cards.
- Card Present — for customers standing in front of you. Cards saved here are the ones the Card on File [Retail] button charges at the register.
- Card Not Present — for phone and mail orders. Cards saved here are charged by the Card on File [Card Not Present] button.
They are set up separately, hold separate cards, and have separate billing schedules. A card saved under one is invisible to the other. A lounge billing monthly lockers uses Card Present; online sales require Card Not Present. As covered above, most shops only need Card Present — don't create a Card Not Present account unless you sell online or your phone-order volume justifies the yearly fee.
You can only create the ones your store's processor is connected for. If a Create button is greyed out, that processor account isn't connected — give us a call.
Opening the Credit Card Accounts Window
From the Dashboard, tap Manage Accounts and open the customer's account.
Save the account first if it's brand new. TORO will ask — "You must save the Account prior to creating Payment Methods & Billing Schedules." Tap Yes.
In the Financial Information box, tap Credit Card Account / Payment Methods & Billing Schedule.
The Credit Card Accounts window opens with two panels — Card Present Account and Card Not Present Account.
Wholesale accounts: open the account in the Wholesale Account editor and tap Credit Card Accounts in the Account Payment Settings box. The account needs a name, a default billing address, and a default billing contact first, or TORO will tell you which one is missing.
Step 1: Create the Processor Account
Each panel starts as one big button — Create RETAIL Processor Account or Create CARD NOT PRESENT Processor Account. Tap it.
That registers the customer with your processor and gives them a vault to hold cards in. The button is replaced by the real panel, showing their cards, their billing schedule count, and an Add button.
You only do this once per customer, per account type.
Step 2: Add a Card
TORO never touches the card number — the customer's card goes straight into the processor's secure vault. That's the whole point.
In the panel you want, tap Add.
The Add Payment to Vault window explains what's about to happen. Tap Add Credit Card.
Your browser opens a secure, PCI-compliant page hosted by the processor. Enter the card there.
Come back to TORO and tap Complete.
Tap Refresh. The card appears in the panel as a branded tile — brand logo,
•••• 1234, and the expiration.
That Refresh step matters. TORO doesn't watch the browser window, so the card won't show up on its own.
Managing Cards
Tap a card tile to open the Payment Methods manager. It lists every card on file with its Card Type, Card Number, and Expiration Date, and gives you:
- + — add another card (same secure browser flow as above).
- – — remove the selected card. TORO confirms first, showing you the card type and last four.
- View On Processor — open that card's record on the processor's website.
A card you know exists but can't see here? If it was added anywhere other than TORO — in PayaConnect, through a signup form, or by processor support — TORO doesn't know it belongs to this customer, so this panel stays empty. See Attaching a Card That TORO Can't See.
Before you remove a card, check the billing schedules. If a recurring charge is pointed at the card you're deleting, that charge will fail. Update the schedule to a different card first.
Step 3: Set Up a Billing Schedule
A billing schedule is a recurring charge — a monthly locker rental, a membership fee, a humidor subscription. It charges a card on file automatically, on a schedule, with no one at the register.
Recurring billing is set up on your processor's website, not inside TORO. TORO walks you over there and reads the result back. Here's the flow:
In the panel, tap View & Edit Billing Schedules. The Billing Schedules window opens showing anything already running.
Tap +.
(If the customer has no card saved yet, TORO stops you: "Must first add a payment method." Go back and add a card first — a recurring charge needs something to charge.)
TORO tells you it's about to open your Paya site, then launches it. Log in.
TORO then opens the add-a-recurring-item page for that exact customer. Fill in the amount, how often it should run, when it starts, and which card on file it charges — all on the processor's page.
Come back to TORO and tap Refresh.
The schedule now appears in the Billing Schedules table:
| Column | What it tells you |
|---|---|
| Status | Whether the schedule is live. Rows that are pending, inactive, or closed show in red. |
| Name | What the charge is called. |
| Amount | What gets charged each time. |
| Frequency | How often it runs. |
| Next Date | When it fires next. |
Changing or cancelling a schedule
Do it on the processor's website — log in, change or remove the recurring item there, then come back to TORO and Refresh. TORO picks the change up automatically. The – button in the Billing Schedules window will tell you the same thing.
Charging a Card on File at the Register
Once a card is on file, taking payment with it is quick:
Attach the customer to the sale. This is required — no customer attached, no cards to pull, and the Card on File buttons stay greyed out.
Tap Add Payment, then Card on File [Retail] (they're in the store) or Card on File [Card Not Present] (phone order).
TORO pulls their saved cards live from the processor, hides anything expired, and lets you pick which card to charge.
If they have no usable card, TORO says "No payment methods on file for customer. Please add one to proceed." and opens the Credit Card Accounts window right there so you can add one without losing the sale.
See Taking Payment for the rest of the payment types.
Staying Ahead of Expiring Cards
A card on file that quietly expires is a recurring charge that quietly fails. TORO watches for this.
Turn it on once: Dashboard > Set Up System > Set Up Credit Cards > check Check stored cards for expiration (recommended).
TORO then checks your customers' stored cards a few times a day and warns you about any that have already expired or expire within 30 days. To see them, go to the Dashboard and tap Expiring Cards on File. From there you can view any card on the processor or jump straight to the customer in TORO to update it.
Things to Know
TORO never stores the card number. It lives in the processor's vault. TORO holds the brand, the last four, and the expiration — that's all it ever sees.
Refresh is your friend. Anything you do on the processor's website — add a card, change a schedule — shows up in TORO after you tap Refresh. TORO doesn't poll while the window is open.
Expired cards are treated as no card. At the register, TORO filters them out entirely. A customer whose only card expired will look like they have none.
Card Present and Card Not Present don't share. A card saved under one won't be there for the other. If a card "vanished," check the other panel.
You need an internet connection. Cards are pulled live from the processor every time, so the Card on File buttons are unavailable when the store is offline.
Permissions apply. Charging a card on file — Retail or Card Not Present — is a permission you can grant or withhold per employee.