Blog
/Compliance

Credit Card Authorization Forms for Travel Agencies: How to Collect Them Without Creating a PCI Problem

Duncan AbdelnourDuncan Abdelnour/11 min read
Credit Card Authorization Forms for Travel Agencies: How to Collect Them Without Creating a PCI Problem

A hotel will not release a room booked on a third party's card without an authorization form. A tour operator will not confirm a deposit without one. So every travel agency ends up running the same loop: send the client a PDF, wait for them to print it, sign it, photograph it with their phone, and email it back with their full card number and security code sitting in the image.

That loop is the most common PCI exposure in the travel industry, and it is also completely fixable. This guide covers what an authorization form needs to contain, the three collection methods agencies use, and how to keep the documentation that actually wins chargeback disputes.

What a credit card authorization form is actually for

The form serves two distinct purposes, and agencies often optimize for the wrong one.

The first purpose is operational: it gives the supplier permission to charge a card belonging to someone who is not standing at their front desk. The property needs this before they will release inventory.

The second purpose is evidentiary: if the cardholder later disputes the charge, the authorization is your proof that the charge was consented to. This is the purpose that determines what you should retain, and for how long.

The mistake is treating the form as a card-transport mechanism. It is not. Getting the card number to the supplier and getting a durable record of consent are two different problems, and the best processes solve them separately.

What belongs on the form

Authorization form contents
0 / 12
Verdict:Tap an item to begin.

Two fields deserve special attention because they are where disputes are won and lost.

The amount. An open-ended authorization is close to worthless in a dispute and is the fastest route to an angry client. State a number or a hard cap. "Room, tax, and resort fee for three nights, not to exceed $1,842.00" survives a chargeback. "Charges incurred during stay" does not.

Incidentals. Decide explicitly and say so on the form. Most agency chargebacks are not about the room rate, which the client expected. They are about a $340 minibar and spa charge the client never authorized and does not recognize. If incidentals are excluded, the property needs a separate card at check-in, and the client needs to know that before they travel.

The three ways agencies collect these today

Method 1: Emailed PDF, returned by email or photo

This is the default and the worst option available. The completed form contains the full card number, the expiration, and usually the CVV, and it now exists in the client's phone camera roll, their sent mail, your inbox, both mail providers' servers, and every backup either of you runs.

Beyond the exposure itself, it drags your entire email environment into PCI scope. The mailbox holding those attachments is now part of your cardholder data environment, along with every device that syncs it. Almost no agency has the controls in place to defend that boundary, and most do not realize the boundary moved.

If you do nothing else after reading this guide, stop accepting completed forms by email.

Many properties and operators now send a secure link where the traveler or advisor enters card details directly into the supplier's compliant environment. Canary Technologies is the most common of these on the hotel side, and it is genuinely the best outcome available when the property offers it: the card data goes straight into the supplier's scope and never touches yours.

Two limitations keep this from being a complete answer. Coverage is inconsistent, since you do not control which suppliers have adopted it, and the resulting record lives in the supplier's system rather than yours, so your own dispute file depends on their retention policy and their willingness to produce it later.

Use these links whenever they are offered. Just do not assume they cover your book of business.

Method 3: Your own tokenized capture, with a generated authorization

The pattern that scales: the client enters their card once through a secure form of your own, the number is tokenized so your staff never handles it in the clear, and the authorization document is generated from the stored profile whenever a supplier asks for one. The form you send the supplier carries the details they need for that specific booking, and your retained copy carries the consent record without the sensitive data.

This is what purpose-built travel vaults do, including Cleo Pay's Travel Vault. The tradeoff is a subscription and a migration. The benefit is that re-authorization stops being an event that reintroduces risk every time it happens.

Criterion
Emailed PDF
The default
Supplier secure link
When offered
Tokenized capture
Your own
Card data stays out of your email
Works across all your suppliers
You keep your own consent record
Re-authorize weeks later without re-asking the client
Per-access audit trail
Cost to start
FreeFreeSubscription
No single method covers every booking. Most agencies end up combining supplier links where available with their own capture for everything else.

What you keep, and what you must not

This is the part that trips up agencies with otherwise good intentions. The rules are narrower than most people assume, and they are specific.

Never retain after authorization: the CVV, CVC, or CID security code. PCI DSS Requirement 3.3.1 prohibits storing sensitive authentication data once a transaction is authorized, and this holds regardless of encryption. If your archived authorization PDFs contain security codes, those files are a compliance problem sitting in your storage today, not a hypothetical one.

Keep, with protection: the cardholder name, the last four digits, the authorized amount, the booking details, the signature, and the date. This set is what actually wins a dispute. Notice that none of it requires the full card number.

Handle carefully: the full card number, if you retain it at all. Tokenizing it is the standard answer, because a token lets you re-authorize without your team ever handling the number in the clear.

Building a process that survives a chargeback

When a dispute lands, you generally have a short window to respond and the quality of your file decides the outcome. A strong response packet contains the signed authorization with a clear amount, the booking confirmation showing dates and property, evidence the client received and accepted the cancellation policy, and any correspondence confirming the booking details.

Three habits make that packet easy to assemble.

Capture consent at booking, not at charge time. If you are chasing a signature after the supplier has already charged the card, you are building the file backwards and the timestamps will show it.

Log every access to the card. Being able to show who used the card, when, and for which booking converts a he-said-she-said into a documented sequence. This is why per-user logins matter more than they appear to.

Keep the consent record longer than the card data. The signature and the authorized amount are what you need in month eleven. The card number is not. Separating the retention period for each is the cleanest way to hold onto your evidence while shrinking your exposure.

Frequently asked

Where to start

If your agency is running the emailed-PDF loop today, the sequence that gets the most risk reduction fastest is: stop accepting completed forms by email, use supplier secure links wherever they exist, purge the old authorization archive of full card numbers and security codes, and then decide whether your remaining volume justifies a tokenized capture tool.

That last decision is mostly about re-authorization. If suppliers regularly come back to you weeks after booking asking for a card again, you will keep drifting toward storing data you should not store, and a tokenized vault is what breaks the cycle. Our buyer's guide to client card storage walks through how to evaluate those tools.

Want to see the authorization workflow end to end with one of your real bookings? Book a walkthrough.

Ready to simplify your AP workflow?

Get early access to Cleo Pay and see how we help hospitality teams save hours every week.