Outsourcing & team, Virtual Assistant

Do you give your VA your credit card details?

Annabel Kaye
Client considering whether to share credit card details with a Virtual Assistant

Giving your VA your personal credit card details can seem like a good idea.

Perhaps you hired them to make travel arrangements, pay for software, organise an event or help with an online application. You do not want to stop what you are doing whenever they reach a payment screen.

It is usually the busy client who says, “Just use my card.” But your VA may not be insured to hold or use your credit card details, and you should not put them in that position simply because it is convenient for you.

This article was first published in 2017. The basic message has not changed, but there are now better ways to arrange payments without sharing the details of your main credit card.

What happens if you share your credit card details?

Your credit card agreement will include rules about keeping your card and its security details safe.

Sharing your credit card details does not automatically remove every protection you have against fraud. However, it may breach the terms of your account and it can make a later fraud claim much more complicated.

If you have authorised your VA to use the card, payments they make within that authority will not normally be treated as unauthorised transactions.

If somebody else later obtains the details and uses them fraudulently, the card provider will look at the circumstances. This may include how the details were shared and protected, what you authorised your VA to do and whether you complied with the terms of your card account.

You also put your VA in a difficult position. If something does go wrong, they may be one of the first people questioned once you tell the card provider that they had your credit card details.

Isn’t it all about trust?

You trust your VA. If you did not, you would not have appointed them.

But this is not about how trustworthy your VA is. It is about having a secure payment system that protects both of you.

There are plenty of ways the details could be compromised without either you or your VA behaving dishonestly:

  • Your card could be skimmed or its details obtained through a scam.

  • Your computer or phone could be compromised.

  • Your VA’s computer or phone could be compromised.

  • A supplier’s website could be insecure or suffer a data breach.

  • Credit card details sent by email or message could remain stored long after the payment has been made.

  • Somebody else with access to an inbox, device or shared folder could find them.

Once more than one person has the complete credit card details, it can be much harder to establish how a fraudulent payment happened.

Trust your VA, but give them a safe system to work with.

Never share your PIN, passwords or security codes

Never give your VA your card PIN, online banking password or a one-time security code sent to your phone.

A card provider may use an app notification, one-time code or other security check to confirm that it is really you approving a payment. Passing that code to somebody else defeats the purpose of the security check and may breach the terms of your account.

Your VA should not ask you to disclose it.  And you should not disclose it just because it’s quicker!

Don’t put your VA in this position

Your VA may not be insured to store or use client credit card details.

Before you ask them to make payments for you, both of you need to understand what their professional indemnity and cyber insurance covers. Your VA should explain the proposed workflow to their broker or underwriter and obtain confirmation in writing that it is covered.

If the insurer will not cover the arrangement, find another way to make the payment. Do not expect your VA to accept an uninsured risk because you are ‘too busy’ to stop and pay.

Let the client pay the supplier directly

For occasional purchases, the simplest solution is often for your VA to do the research and prepare everything up to the payment stage.

The supplier may provide a payment link which your VA can send to you. You enter your own credit card details and complete any security checks. Your VA never sees or stores the details.

If there is no separate payment link, you may be able to log in and make the payment yourself after your VA has prepared the order. You could also enter your credit card details during a screen-sharing session without reading them aloud or sending them to your VA.

A few minutes of your time is a small price to pay for keeping control of your card.

What about paying for visa applications?

The same principle applies when your VA is helping you with a visa application.

Your VA can prepare the application up to the payment stage. The applicant should then review and approve the information before logging into the official portal and making the payment.

If the visa system generates a payment link, your VA can send that link to the applicant. Not every visa portal provides one, so the applicant may need to log in or join the VA briefly by screen share to enter their own credit card details and authorise the payment.

Your VA should not routinely pay substantial visa fees using their own card and wait to be reimbursed. That creates a credit risk for the VA and may fall outside their insurance.

Our guide to helping clients with visa applications explains how to agree the wider workflow, including reviewing and approving the application before it is submitted.

Can your VA have a separate card?

If your VA needs to make regular payments for your business, consider a facility specifically designed to give a contractor separate and controlled access.

Capital on Tap currently states that its additional business cards can be issued to contract workers as well as employees.

You can issue your VA with a separate physical or virtual card in their own name. You can set a limit for each transaction or billing period, block cash withdrawals, monitor spending and freeze the card.

Your VA receives separate card details, so you do not disclose the details of your main business credit card. A virtual card can be used for online purchases and cancelled without replacing your main card.

Your VA will need to complete the provider’s verification and onboarding process. You remain legally and financially responsible for spending on the account.

Product terms and eligibility change. Tell the  card provider that the proposed cardholder is a self-employed external VA and obtain confirmation that the arrangement is permitted before ordering the card.

Do not assume that a product described as an “employee card” can be given to a contractor.

Agree the rules before the card is used

Giving your VA a separate card does not mean giving them unlimited authority to spend your money.

Agree in writing:

  • what your VA is authorised to buy;

  • whether you must approve each purchase;

  • the maximum amount they can spend;

  • which card or payment method they must use;

  • how receipts must be stored;

  • who handles cancellations, refunds and chargebacks;

  • what happens if the card or its details are compromised; and

  • when the card and access must be cancelled.

Your VA should not use their personal or business credit card to fund your expenses and then add the amount to their invoice.

Take particular care with travel bookings

Paying for travel and recharging it to a client can create much larger problems than an ordinary business purchase.

The Society of Virtual Assistants describes booking travel on the VA’s own card and rebilling the client as a “no-no”. Its advice is to use a specialist travel agent or have the VA research the options and send the client the links so that the client makes the booking. You can read its guidance on booking travel as a Virtual Assistant.

A VA who buys and resells flights or combines travel services may stray into the rules governing travel organisers, packages and ATOL protection. Business travel is not automatically outside those rules.

Before offering travel booking or payment as a service, the VA should check the proposed workflow with their insurer and obtain written confirmation that it is covered. If the VA will collect the client’s money, recharge travel costs or combine flights, accommodation or other travel services, they should also take specialist advice on whether travel-industry rules apply.

Payment security is only one part of supporting a client with travel. If your VA is also handling itineraries, identity documents or information about the people travelling, read our top tips to protect your client’s data when travelling.

Don’t share your main credit card details

There are now practical alternatives to sending your main credit card details by email, WhatsApp or text.

Make the payment yourself, use a genuine supplier payment link or arrange a separate controlled card which the provider confirms can be issued to your self-employed VA.

Do not share your PIN, passwords or one-time security codes.

Convenience is not a good reason to expose your money, weaken your security or expect your VA to accept work they are not insured to perform.

KoffeeKlatch agreements can help

We take the security of your money and data seriously.  Our VA AI Ready Hiring Agreement helps you and your VA agree who is doing what and who is sharing what and how.

Putting the arrangement in writing protects both of you and is far safer than sending your credit card details in a message.