Tokenisation
Replacing a card number with a substitute value — a token — that stands in for it in a merchant's systems and is useless anywhere else. It is what allows a business to recognise a returning customer, or to charge a saved card, without the card number ever being stored on its side. It is the single largest lever a merchant has on PCI DSS scope.
Why it matters to a merchant
This is the mechanism behind "we never store card numbers", and it is worth asking your provider to confirm in those terms. If saved cards, subscriptions or one-click repeat purchases are part of your business, the question is not whether you can do them but whether you can do them without card data landing in a system you are then responsible for securing.
Read more: PCI DSS: what a Singapore merchant actually has to do
Where this comes up
Pages on this site that deal with this in context:
Related terms
In this section: How a payment moves