Description: Learn how you request a Token Migration to migrate full credit card data.
Jump to a section by selecting a link below:
- Token Migration Summary
- What’s Included in the Export
- How to Get Started
- Token Migration Process
- Frequently Asked Questions
Token Migration Summary
Shift4 offers a paid detokenization procedure to perform token export service for accounts that need to migrate full credit card data, including optional customer and transaction details, to a PCI-validated third-party provider via SFTP (Secure File Transfer Protocol).
Overview
This curated service allows you to export:
- Full credit card data
- Optional customer address information (depending on your POS/PMS setup)
- A secure transaction token containing the above data
This service is ideal for accounts transitioning from Shift4 to other vendors or switching to the
POS/PMS and needing a secure handoff of customer payment data.
What’s Included in the Export
The exported file will be delivered as a PGP-encrypted .txt file and may include the following data (depending on your POS/PMS integration):
- Secure Transaction Token
- Primary Account Number (PAN)
- Card Expiration Date
- Cardholder First Name
- Cardholder Last Name
- Street Address
- Postal Code
How to Get Started
Verify that your new processor or POS/PMS provider can accept the token export file and handle it accordingly with PCI data security standards (PCI DSS).
Enterprise Merchants
Enterprise-level merchants should contact their Enterprise Account Manager to initiate the process and receive detailed guidance.
Other Merchants
The Owner on File should visit shift4.com/support to initiate the Request via phone or Chat. After the request is placed, the verified owner can assign a person from the location to be responsible for handling all the inquiries and communication regarding the token export.
Token Migration Process
- The account owner initiates the process by contacting Shift4 Support with a request to export tokens.
- The account owner, or a designated Point of Contact (POC) from the business location, provides the details of the account from which tokens will be exported.
- An Enterprise Support agent contacts the owner or POC to answer any of your questions that might come up regarding the token export and share the cost associated with the token export.
- If you agree to the pricing, you must provide:
- Contact information for a PCI-validated third party receiving the token file.
- A preferred export date for Shift4 to prepare the Statement of Work (SOW).
- The Statement of Work is sent out to the owner or the POC, and once it is signed, the provided fee amount is deducted from the merchant's bank account using Automated Clearing House (ACH).
- Shift4’s Security Team will contact the PCI-validated third party and provide login credentials to access Shift4’s Secure File Transfer Protocol (SFTP) site.
- Token extraction & delivery, on the agreed export date:
- Shift4 extracts the token and credit card data from the account database.
- The data is encrypted and securely uploaded to the SFTP site for the PCI-validated third party to download the provided files.
- You confirm the receipt of the token file and advise if any further assistance is needed.
Frequently Asked Questions
How long does it take to receive the token file?
We aim to deliver the exported tokens within 5 weeks of receiving your initial request.
Is there a fee for this process?
Yes. The estimated cost is over $10,000, with a formal quote provided within 3 business days of the request.
Where is the token file delivered?
The token file must be sent to a PCI-validated third-party entity, such as your new POS provider or payment processor, or uploaded to the Shift4 SFTP site for the third-party to download it from the site.
What is the Shift4 SFTP site?
Before performing the token export, our security team will reach out to the provided point of contact from a third-party PCI-validated vendor to provide the login credentials to Shift4’s Secure File Transfer Portal (SFTP).
Trouble logging into the SFTP site?
- Use the "Forgot your password" link on the login page.
- Ensure your credentials are no older than 7 days.
- If issues persist, contact the sender of the email for support.
What are the Security Operations Center (SOC) hours?
Our SOC team is available Monday–Friday, 8 AM to 5 PM EST.
Can I process payments during the export process?
The token export will not disrupt processing, but to avoid missing any recent tokens, we advise pausing processing for one hour during the token export process that happens around 3:30 PM PST on an agreed date.
Can I choose specific tokens to export?
No. The export will include all transactions processed under your Shift4 account number that you provide.
Can you confirm if specific tokens are in your system?
For security reasons, we cannot review or verify specific token files.
How recent will the exported data be?
The file will include transactions up to the date of the token export.
What is the SFTP requirement in the Statement of Work (SOW)?
Your receiving 3rd must have an SFTP site that complies with PCI standards to receive the encrypted file, or you can utilize Shift4’s SFTP.
How is payment handled?
Payment will be processed via ACH debit for the amount specified in your Statement of Work (SOW).
Is the export by Merchant ID or Serial Number (SN)?
We export and count tokens based on the Shift4 account number (SN).
Can I preview the exported file format?
Yes. After the request is submitted, we can provide you with a default sample file.
What is a transaction token?
A transaction token is a unique string of letters and numbers used to securely represent a customer’s credit card and address information for a specific transaction. It allows sensitive data to be encrypted and stored safely without exposing the actual payment details.
Comments
0 comments
Please sign in to leave a comment.