FAQs: Integrated Payments Card on File
For complete instructions on this feature, please visit taking a payment with Card on File or watch the video.
Don’t have integrated payments? Visit our IDEXX Payments page to learn more about the benefits integrated payments provides, including eliminating manual errors, faster transaction time, online payments, and more.
Ready to get started with Card on File? Fill out this request form and IDEXX will send the files to your server in 1-2 business days.
Setup, requirements, and general questions
How does Card on File work?
When processing an integrated card payment, a credit card can be added, or an existing saved card can be used to process the transaction.
Can any Cornerstone customer use Card on File, and how do I get it?
To use Card on File, your Cornerstone system must be integrated with an eligible payment provider and have Cornerstone 9.6 or above installed.
- Don’t have integrated payments? Visit our IDEXX Payments page to learn more about integrated payments’ benefits, including eliminating manual errors, faster transaction time, online payments, and more.
- For eligible practices also on Cornerstone 9.6, fill out this request form and IDEXX will send the files to your server in 1-2 business days. The files that enable the Card on File feature will be included in future versions.
How do I turn Card on File on?
- For Cornerstone 9.6 and above, when you get the files, the functionality will automatically be turned on and ready to use right after the files are applied. To turn it off, contact support.
- For future versions, you will be able to call support to turn Card on File on, as needed.
How does Card on File protect customer data?
- IDEXX Payments uses PCI-Validated Point-to-Point Encryption (P2PE). Card data is encrypted at the payment terminal and tokenized during its full lifecycle.
- The card number is not stored by IDEXX or Cornerstone.
- IDEXX Payments partners with our payment vendor(s) to process card on file transactions. Our card on file service uses CardSecure P2PE-validated encryption and tokenization solution. A token is a hashed alphanumeric representation of sensitive data, such as a credit card account number. These tokens can only be used by IDEXX Payments to process a transaction and cannot be used with any other payment vendor. IDEXX Payments takes additional security steps be also encrypting all tokens stored in our secure cloud environment.
Can I choose what features of Card on File I want my staff to access?
Security for Card on File falls under any security related to integrated payments. If the staff have access to take an integrated payment, they will have access to all features within the integrated payment window.
Does using a saved Card on File cost the practice more in processing fees?
There is no cost to enable the Card on File feature in Cornerstone, but credit card rates and fees vary per merchant and can be impacted by Card on File.
I’d like my client to sign an authorization form to use Card on File. What should that look like?
Create a Client Only Correspondence document with the language you’d like to use, client information, a question bookmark for the cardholder’s name, and a client signature bookmark. For example:

Using Card on File
Does Card on File allow for scheduled payments?
No. Card on File is intended to be used with existing functionality when processing a payment within Cornerstone. It does not add additional functionality for other payment processing workflows.
Can I use Card on File for refunds?
When using the Void feature, the refund is automatically sent without needing to select a card.
If entering a negative amount to return funds, the card on file option is not available and normal processing will be required.
Can a card be added to the customer profile at any time?
A successful transaction has to be completed to save a Card on File. This means that a card can only be saved during a payment transaction. The user needs to select Add a new card on file before they process the transaction.

Can a manually entered card be saved to the profile? Example: A customer provides their card number over the phone.
No. The card must be physically present to be saved to the customer’s profile and must be swiped, tapped, or inserted to be added to the profile.
Where can the client’s profile for saved cards be accessed?
Currently, the profile can be managed from the payment processing window when taking a payment.
Note: If you need to manage the Card on File but do not need to process a payment, click Cancel on the Integrated Card Payment and Payment windows.

Is it possible to tell when a saved card was used to process a transaction?
Yes. On the Payment window, instead of the XXXX and the last four digits of the card in the Prompt field, it will have COF and the last four digits. This indicates that a saved card on file was used to process that transaction.

What happens when a saved card on file expires?
Currently, there is no automated function to remove that card or update the expiration date. Manually delete expired cards when processing a transaction and re-add the new updated card.
How do I track that consent was received from the client to save or process a card on file?
- To either add or use a saved card, the staff member has to check the Obtain Consent checkbox. This places the responsibility on the practice to ensure your staff understands the importance of talking to the client and only checking this box once they have confirmed consent.
- Cornerstone stores the consent flag on the saved card.
- Every time a card on file is used to complete a payment, the staff must check the Obtain Consent checkbox, confirming that they have talked with the client to obtain consent.
Changing or deleting client information
What happens if I change the Client’s email address on their Client Account?
Updating a client email on their client record in Cornerstone will not update their card on file email address. The email address does not need to be updated for the Card on File email profile, as the address is only used to create the profile and not to send emails. If changing the email on the file is requested, do the following:
- Delete the entire profile.
- Re-add the cards.
- When re-adding the cards, the newly updated email address from the client record will default in the Card on File Profile field, or you can manually type it in.
What should I do before merging Clients who have Cards on File?
Before doing the merge:
- Start a payment on the client whose ID will no longer be present. This client ID will be entered in the From field when merging.
- Delete the profile for the client. This will ensure that this client’s profile is deleted from the system.
Before deleting or purging a Client with Cards on File, what should I do?
Before deleting or purging a client:
- Start a payment on the client who will be deleted or purged.
- Delete the profile for the client. This will ensure that this client’s profile is deleted from the system.