Use a virtual terminal only when staff must complete the gift
Choose when nonprofit staff should use a virtual terminal, send a self-service link, or use a card-present path—and record the assisted gift safely.
CharityStack
·4 min read
Use a nonprofit virtual terminal when a donor has asked a trained staff member to enter the gift for them. If the donor can complete a secure donation form, send the link instead. When the donor and card are physically present, use your approved card-present path when one is available.
That boundary keeps an assisted gift from becoming an informal payment process. It also tells your team which record should prove who entered the gift, what the donor authorized, and whether the payment finished.
Start with the assisted-gift boundary
The PCI Security Standards Council defines a virtual terminal as an internet-connected interface where a merchant manually enters transactions one at a time. In fundraising, that commonly means a staff member keys a donor-authorized phone, mail, or event gift into an internal payment screen.
Use two intake lanes:
- Donor self-service: Send the official donation link when the donor has a safe device and can complete the form. The donor enters their own payment details and reviews the amount, frequency, and designation.
- Staff-assisted entry: Use the approved virtual terminal when the donor has asked your team to complete the gift and self-service would not solve the situation. Common examples include a phone donation or written payment instruction handled under your organization's policy.
Do not open the public donation form and pretend to be the donor. Do not copy payment details into email, chat, a spreadsheet, or the donor record before entering them. The virtual terminal is the controlled entry point, not a shortcut around your payment process.
Confirm five facts before entering the payment
Treat the terminal as the final step of an intake decision. Before typing payment details, confirm:
- Donor: You have the right contact or organization record.
- Authorization: The donor asked you to enter this gift, and you can repeat the amount, frequency, and designation back accurately.
- Operator: The person entering it has an individual approved account and is using an approved device and network.
- Source: You know whether the gift came by phone, mail, an event station, or another documented route.
- Receipt: You know where the confirmation should go and can correct the address before submission.
Current platforms expose different controls. Fundraise Up documents a limited Virtual Terminal Specialist role and records Virtual Terminal as a donation source. Virtuous describes permissions-based access, campaign or designation fields, receipts, and reconciliation. Those examples show useful controls to look for; they do not prove that every terminal uses the same roles or fields.
If a fact is missing, stop the entry. A callback through a known number or a fresh self-service link is better than guessing which donor, fund, or recurring schedule the request meant.
Keep payment details inside the approved screen
A virtual terminal reduces handoffs only when staff enter sensitive details directly into the approved interface. Anedot's current documentation describes its terminal as an internal entry surface that does not save donor payment information to the browser. Your platform's behavior and your obligations may differ.
Follow the payment processor's current instructions for devices, user access, phone or mail handling, recordings, and required payment-security checks. Fundraise Up notes that enabling its virtual terminal brings organization networks and computer systems into its PCI requirements. This article does not determine which requirements apply to your organization.
One practical rule still holds: the gift record may keep the donor's instruction, but it should not become a second home for card or bank details. Record “Donor authorized a one-time $75 general gift by phone at 10:14 a.m.” rather than copying the information used to pay.
Close the assisted gift with five fields
After submission, keep a small assisted-entry record beside the gift:
- Operator: the individual user who entered the transaction;
- Authorization note: channel, date, time, amount, frequency, and designation, without payment details;
- Source: phone, mail, event station, or another stable internal value;
- Result: transaction or gift ID plus the current payment state;
- Receipt outcome: sent, suppressed by request, or held for a corrected address.
Copy the terminal's reported payment state into the closeout record without translating it into a more favorable label. Keep later settlement or recovery work in the payment workflow instead of rewriting the assisted-entry note.
This closeout also exposes duplicates. If two operators entered the same mailed instruction, matching authorization notes and source values give your team a reason to investigate before sending a second acknowledgment or changing totals.
Use a card-present path when the donor is present
A virtual terminal is a keyed-entry tool. It is not automatically the right event checkout just because staff are nearby. When the donor and their card or wallet are physically present, an approved card reader or tap-to-pay flow can keep the donor in control of the payment action.
Choose the virtual terminal at an event only when the actual workflow requires staff-assisted entry and your processor supports that use. Test the device, account, connection, receipt, source value, and failure handoff before doors open. If any part fails, fall back to the official self-service link rather than collecting payment details for later entry.
CharityStack's current plan comparison lists a virtual terminal on Starter, Base, and Plus. Its Manage product keeps payments, contacts, subscriptions, and receipts in the same fundraising workspace.