Retail
PAYMENT DATA AS HIDDEN DEBT
Retailers are carrying a growing burden of technical debt in their payment systems, as fragmented data, legacy integrations and rising customer expectations collide. Jacob Spencer, Chief Revenue Officer at BR-DGE, explains how outdated payment infrastructure is quietly eroding performance, resilience and revenue.
R
etailers increasingly rely on several providers, acquirers, payment methods and channels, and there are sound reasons for doing so. The mix can
improve acceptance, give customers more choice and provide merchants with greater resilience and flexibility. This broad payments estate also generates significant
volumes of data. Insights around approval rates, failed transactions, refund patterns, retry results and provider performance all help teams make better decisions. Retailers need that information to understand where revenue is being lost and how different routes behave across markets and customer journeys. But retailers need to be selective about what type of data is kept for
analysis and insights, separating the useful, operational data from the sensitive data that carries compliance exposure. Without this deliberate separation, raw card details and stored credentials can end up spread across ecommerce platforms, apps, loyalty systems, fraud tools, customer service and reporting, even though most of those systems only need a token, transaction reference or payment status. As the payment setup expands, retailers have to keep track of where
the sensitive data sits, how far it travels, who can access it and what changes each time a provider, payment method or customer journey is added. This affects how quickly the business can change providers, introduce new services and respond when a payment route fails.
Providers end up serving different parts of the business Payment performance changes across markets, channels and
6 | Jully/August 2026
transaction types. A retailer expanding overseas may add a local acquirer because it approves more transactions there, while keeping its existing PSP for domestic ecommerce. Another provider might be best placed to support a particular wallet or app. Over time, each connection takes on a different job within the payment setup. Working with several providers also gives retailers
more to learn from. They can see which routes approve more payments, where retries recover revenue and
whether a local acquirer performs better in a particular market. Each connection can bring its own approach to credentials, tokens
and stored cards. One provider holds the card details in its vault and issues tokens that only work on its platform. Another channel uses a different provider, while refunds, subscriptions and customer accounts depend on information held elsewhere. The retailer may have several useful payment relationships, yet the
stored credential needed to route a transaction remains tied to one of them. The restriction often comes to light during a change of provider. The new connection is ready, and the routing logic is in place, but existing saved cards still point back to the original vault. Adding that new provider then turns into token migration, re-tokenisation or a customer re-entry process.
PCI DSS is part of a wider operational task The Payment Card Industry Data Security Standard, or PCI DSS, provides a framework for protecting cardholder data. Systems that store, process or transmit payment account data can fall within
www.pcr-online.biz
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36 |
Page 37 |
Page 38 |
Page 39 |
Page 40 |
Page 41 |
Page 42 |
Page 43 |
Page 44 |
Page 45 |
Page 46 |
Page 47 |
Page 48 |
Page 49 |
Page 50 |
Page 51 |
Page 52