Key takeaways

  • Since 1 October 2022, merchants and payment gateways can't store your full card number, expiry or CVV.
  • When you "save" a card, the app stores a token that only works for that merchant.
  • If a merchant is hacked, the token is useless elsewhere, which is far safer than stored card numbers.
  • You can view and delete tokens in your bank app or on the merchant's site.

When you tick "save this card" on Amazon, Swiggy or any app today, the app doesn't actually keep your card number. It keeps a token. That's because of RBI's card-on-file tokenisation rules. Here's how it works and how safe it is.

What is tokenisation?

Tokenisation replaces your actual card details with a unique code, a token, that can be used to make payments but reveals nothing about your card. Each token is tied to a specific merchant (and device, for in-app or tap-to-pay tokens), so a token saved on one shopping site can't be used anywhere else.

What RBI changed in 2022

Under RBI's card-on-file (CoF) rules, effective 1 October 2022, no entity in the payment chain other than the card issuer and card network may store your actual card data. Merchants, payment gateways and aggregators had to delete stored card numbers. They can keep only limited information for reconciliation, such as the last four digits and the issuer's name, shown as "XXXX-XXXX-XXXX-1234".

Is it safe to save your card?

Much safer than before. If a merchant's database is breached, attackers get tokens that don't work on other sites, not your card number. Tokenised payments still need authentication (usually an OTP) for most online transactions in India, as they did before. Tokenisation removes one of the biggest sources of mass card-data leaks.

How to save a card as a token

  1. At checkout, enter your card details and tick the option to save or secure the card, per RBI guidelines.
  2. Give consent. Tokenisation is optional and requires your explicit consent, usually confirmed with an OTP.
  3. Next time, pay with the saved card using just the CVV (where required) and an OTP.

How to see and delete your tokens

  • On the merchant's site or app: go to saved payment methods and remove the card.
  • In your bank app: many banks show a list of tokens created for your card, and let you disable them individually.
  • If you lose or replace your card: tokens linked to the old card generally stop working, and you'll need to save the new card again.

Tokenisation vs other card protections

ProtectionWhat it does
TokenisationHides your card number from merchants
OTP / additional factor of authenticationConfirms it's really you making the payment
Card controls in your bank appTurn online, international or contactless use on or off and set limits
Transaction alertsWarn you instantly of any payment
RBI zero-liability rulesProtect you if you report fraud within 3 working days

Where tokenisation doesn't protect you

  • Phishing and fake websites. If you type your card details and OTP into a fraudulent site, the fraudster can use them. Tokenisation doesn't help.
  • OTP sharing. No system protects you if you share an OTP with a caller.
  • Physical card theft. Block a lost card immediately.

See our guides to common card scams and what to do if you're hit by fraud.

Tap-to-pay on your phone

When you add a card to a phone wallet for contactless payments, that's device tokenisation. The phone stores a device-specific token rather than your card number, and payments usually need your phone to be unlocked. It's generally considered more secure than tapping a physical card.

Three common questions from readers

"Why do I still need to enter my CVV for a saved card?"

Some merchants and card networks still ask for the CVV on tokenised cards as an extra check. It isn't stored. You enter it fresh each time.

"My saved cards disappeared in 2022. Why?"

Merchants had to delete stored card numbers when the CoF rules took effect on 1 October 2022. Cards you save now are stored as tokens instead.

"Is it safer not to save my card at all?"

Not saving is always the most private option, but a tokenised card is a reasonable choice for merchants you use often. It means you type your card number less often, which also reduces the chance of entering it on a fake site by mistake.

FAQs

What is card tokenisation?

Replacing your real card details with a unique token that works only for a specific merchant or device, so your card number isn't stored by merchants.

Is tokenisation mandatory?

Saving a card now requires tokenisation, but it's optional for you. You can choose not to save your card and enter details each time.

Is there a charge for tokenising my card?

No. Customers aren't charged for tokenisation.

Can merchants still see my card number?

No. Since 1 October 2022, merchants can only store limited details like the last four digits and the issuer name.

Can I use one token on multiple websites?

No. A card-on-file token is specific to the merchant that created it, so you save your card separately on each site. That's what makes a stolen token useless elsewhere.

Does tokenisation work for international websites?

RBI's rules apply to card-on-file storage in India. International merchants may use their own network tokenisation, so check your bank's token list and card controls if you shop abroad.

Sources

About the author

Deepak

Founder & Editor, CardPicker

Deepak founded CardPicker and writes and fact-checks its credit card guides, comparisons and news.

✓ Fact-checked 26 September 2026Prices, dates and card terms in this article were checked against issuer websites, official pages and news reports listed under Sources. Card figures come from our database, which is re-verified regularly. Offers change often, so confirm on the issuer's site before you buy or apply. Spotted an error? Tell us.