Card tokenization replaces a guest's real card number with a unique token that is useless if stolen. Hotel systems store and pass the token instead of the card, which reduces fraud risk and PCI DSS compliance scope.
The gateway or a tokenization vault keeps the real card data in a secured environment. The PMS, booking engine and channel manager only ever see the token, which they can use to charge, refund or pre-authorize through the same provider.
Tokenization matters most in hotels because card data travels between many systems, from OTA to channel manager to PMS. Any system that still emails, faxes or displays full card numbers is a liability, and auditors typically flag it immediately.
← sesion.org · All categories · Advisors · Blog · Glossary