This is a managed integration. Contact your PolyAI account manager to enable PCI Pal for your project.
How it works
1
Payment trigger
When a caller needs to pay, the PolyAI agent initiates a PCI Pal session.
2
Secure transfer
The call is transferred to PCI Pal’s secure environment where card details are captured.
3
DTMF masking
Card numbers entered by keypad are masked and never exposed to the call recording.
4
Payment processing
PCI Pal processes the payment through your configured payment gateway.
5
Return to agent
After completion, the caller is transferred back to the PolyAI agent for confirmation.
Capabilities
Secure card capture
PCI DSS Level 1 compliant payment collection.
DTMF payment
Callers enter card details on the phone keypad.
Real-time authorization
Immediate payment confirmation.
Payment status
Success or failure is passed back to the agent so it can continue the conversation.
Getting started
Prerequisites
- A PCI Pal account with API access
- Your payment gateway credentials configured in PCI Pal
- PolyAI project access
Set up
1
Obtain PCI Pal credentials
Contact PCI Pal to obtain the following values:
2
Configure your payment flow
Work with PCI Pal to configure:
- Payment amounts and currencies
- Card types accepted
- Retry logic for failed payments
- Confirmation messaging
3
Share credentials with PolyAI
Securely share the PCI Pal credentials with your PolyAI representative. PolyAI stores them as encrypted secrets.
4
Test in sandbox
- PolyAI configures the integration in your sandbox environment.
- Run test payments using PCI Pal’s test card numbers.
- Verify successful processing and the return-to-agent flow.
- Deploy to production once testing passes.
Caller experience
A typical payment sounds like:1
Agent hands off
“I’ll now transfer you to our secure payment line.”
2
PCI Pal prompts for card
“Please enter your 16-digit card number using your keypad.”
3
Caller enters card via DTMF
Digits are masked in the recording and never seen by the agent.
4
PCI Pal confirms and returns
“Payment successful. Transferring you back.”
5
Agent confirms
“Thank you, your payment of $50 has been processed.”
Security
- PCI DSS compliance — PCI Pal is certified Level 1 PCI DSS compliant.
- No card data storage — PolyAI never stores or has access to card details.
- Encrypted transmission — All payment data is encrypted in transit.
- Recording pause — Card entry is automatically excluded from call recordings.
Limitations
- Voice entry — Card numbers must be entered by keypad, not spoken.
- Transfer required — Caller experiences a brief transfer to the payment system.
- Single payment — Each session handles one payment transaction.
Support
- Contact your PolyAI account manager for integration assistance.
- Contact PCI Pal support for payment gateway issues.
Related pages
Stripe
Alternative payment processing integration.
Managed services
Other managed integrations requiring account manager setup.

