Skip to content

Accounts  ·  Explainer

Tap to Pay, and Why It Beats a Card

Paying by phone is more secure than the plastic it replaces, for reasons that have nothing to do with the phone being newer.

Most people treat contactless phone payment as a convenience feature. It is, and it is also a meaningful security improvement over handing someone a card — because the phone never gives the merchant your card number.

What actually gets transmitted

When you add a card to a phone wallet, the card number is sent once to the card network, which returns a different number — a device account number, or token — that is stored on the phone.

The real card number is not stored on the phone. It is not stored in the wallet app, and it is not transmitted at the till.

Each transaction sends the token plus a one-time cryptogram generated by a secure chip on the device. The cryptogram is valid for that transaction only.

The merchant never sees your card number. They see a token that is useless anywhere else.

Why this matters

A merchant breach cannot expose your card. When a retailer's payment system is compromised, tokenised transactions yield nothing reusable. Card-swipe and card-number transactions do.

A skimmer cannot capture it. There is no magnetic stripe and no static number to copy.

A stolen phone is not a stolen card. Payment requires biometric or passcode authentication for each transaction. A thief with your unlocked phone is a problem; a thief with your locked phone is not.

You can kill it remotely. Suspending the device account number through your wallet account or the card issuer takes effect immediately, and the physical card keeps working.

Compare that with a lost physical card, which anyone can tap for small amounts without authentication until you cancel it.

The practical limitations

Battery. A phone with no power cannot pay. Both major platforms keep a reserve that allows payment for a period after the phone appears dead, but it is finite and not guaranteed.

Terminal support. Nearly universal in the US now, but not entirely. Some older equipment, some parking meters, some transit systems.

Limits. Some terminals impose a ceiling above which they require a card, though phone payments with biometric authentication are usually exempt because the authentication satisfies the requirement.

Not accepted where cards are handed over. Restaurants that take the card away are the awkward case, though tableside terminals have largely solved this.

When a payment fails

The failure is almost never mysterious. Work through it in this order.

Is the phone unlocked and authenticated? Most failures are this. The wallet needs authentication at the moment of payment.

Is it the right card? Wallets default to one card; the terminal will decline if that card is expired or has an issue.

Did the phone actually contact the terminal? Contactless range is a few centimetres and the antenna location varies by phone — usually near the top on iPhones, often centre-rear on Android. Holding the wrong part of the phone against the reader is a common cause.

Is the terminal contactless-capable? Look for the wave symbol. Not all readers with a chip slot accept contactless.

Did the card issuer decline? If the terminal says declined rather than failing to read, the transaction reached the bank. That is a card problem, not a phone problem — check the banking app.

Was it a large amount at an unusual location? Fraud systems decline transactions that break your pattern. Travel is the classic trigger.

Peer-to-peer payment apps are a different thing

Sending money to a person through an app is not the same transaction type as paying a merchant, and the protections differ substantially.

Card payments have chargeback rights. If goods never arrive, or the charge is fraudulent, you can dispute it with the issuer and the money is typically returned while it is investigated.

Person-to-person transfers generally do not. They are treated as cash. If you send money to a scammer, or to the wrong person, recovery depends on the recipient agreeing to return it.

This asymmetry is the basis of a large category of fraud. Anyone who insists on payment by a peer-to-peer app rather than a card, for a purchase from a stranger, is asking you to give up your protection. That request is itself the warning sign.

Use peer-to-peer apps for people you know. Use a card for purchases from anyone you do not.

Setting it up sensibly

Add more than one card, so a single card problem does not leave you unable to pay.

Know how to switch cards at the terminal before you need to.

Turn on transaction notifications from the issuer. Immediate visibility of a fraudulent charge is worth more than any preventive setting.

Keep the phone's lock screen secure. Everything above depends on the device being locked to anyone but you. A four-digit passcode used in public is the weak point in an otherwise strong system.

Check what your wallet shows on a locked screen. Some configurations expose recent transactions without unlocking.