Payment Processing · Security

The hardest part of leaving a payment processor is usually not the contract. It is the customers whose cards are saved with it: the subscribers billed every month, the clients on a payment plan, the regulars who never type in a card number. Lose those cards and every one of those customers has to be asked to enter them again, and some of them will not.
The good news is that the card numbers are usually portable. Seven of the eight providers we checked describe sending your stored cards to another processor or vault, and several say plainly that the data is yours. The bad news is in the details. The card numbers move; almost nothing attached to them does. We read the export and import pages of eight providers on 29 September 2026. This is what they say.
You will never be handed a spreadsheet of your customers' card numbers. Card data moves directly between two companies that are certified to hold it, in an encrypted file, and the receiving company has to prove its certification first.
The wording is almost identical everywhere. Stripe says that to meet its PCI obligations it "can only transfer your card data to another PCI DSS Level 1-compliant payment processor", and asks for that processor's Attestation of Compliance or its listing on Visa's Global Registry of Service Providers, plus a PGP encryption key of at least 4,096 bits hosted on the new processor's own domain. Square uses the same Level 1 wording. Helcim exports only to a Level 1 provider and asks you for its Attestation of Compliance. Braintree wants "an attestation of their PCI compliance from a qualified provider" before it will request the receiving side's key. Adyen wants the new provider's Attestation of Compliance, a PGP key that is referenced on the new provider's own website, and a data processing or data transfer agreement with you.
In practice this means the process starts with your new processor, not your old one. Before you give notice, ask the new provider whether it accepts card imports, whether it is PCI DSS Level 1, and who on its side handles migrations. If it cannot answer, the migration is not going to happen.
None of the pages from Stripe, Square, Authorize.net or Adyen mentions a fee for an export. Only Braintree and Helcim state in writing that there is none. If the price matters to you, ask for it in writing before you give notice.
Expect the card details to move and very little else. Plan for everything else to be rebuilt.
Stripe, Square and Braintree all say subscriptions are not part of the migration. Braintree tells departing merchants to download a report of their plans and subscriptions or pull them through the API. Square, on the receiving side, says it will not import gift cards, subscriptions or appointments, and that billing has to be set up again in your account or in an outside app. Your new processor gets a list of cards. It does not get the schedule of who is charged what and when, so that has to come from your own records.
Braintree says the tokens behind Apple Pay and Google Pay payments "are not transferrable between providers", so it leaves them out of exports. Stripe says on its import page that it cannot migrate cards stored by digital wallets such as Google Pay, because the wallet, not the old processor, tokenizes the stored card. Stripe can import Apple Pay device card numbers if your old processor can supply the device card number, expiry date and network transaction ID, and you arrange it with a Stripe representative. Customers who saved a wallet with you should expect to be asked to add it again.
Braintree says a customer who stores a bank account for ACH payments agrees to be charged by that processor only, so moving those accounts requires you to accept additional legal terms. Transaction history does not move anywhere: Stripe says it does not export payment history and points you to its Dashboard and API to retrieve it. Download it before you close the old account, because you will need it for refunds and chargebacks on sales made there.
Stripe warns that files from other processors "often contain expired cards". On import you can skip them, or import them and let its card account updater fetch replacement details from the issuing bank, which Stripe says "might incur fees for each updated card". Ask your new processor which it does by default. Our article on network tokenization fees explains how Visa now prices its card-updating services.
The export is a snapshot. Anything that changes after it is taken does not reach the new processor, and both sides warn about it. Authorize.net says card updates customers make through the old provider after the export is requested "will not be included in the initial data transfer and could be lost", and that nothing can be changed on its side until the import finishes. Square accepts "a single encrypted file" and says card imports are a one-time onboarding process it cannot run on an ongoing basis. Braintree's two-export limit exists for the same reason: one for the bulk of your customers, one for anyone added during the switch.
The timetables add up. Square quotes up to two weeks to export and up to 15 business days to import, and says it cannot guarantee a completion date. Helcim quotes five to ten business days and up to 30. So a realistic plan is:
If your contract has an early termination fee, the timing of that last step matters too. Our guide to leaving a processor after a fee increase covers the notice clauses.
Things are harder when the cards live with your store platform rather than a processor. Shopify's help centre describes in detail how to bring cards into Shopify, including a paid Professional Services migration for credit card numbers that requires the Plus or Enterprise plan. It says nothing about sending them out. In 2022 a Shopify staff member told merchants on its community forum there was "currently no possible way of exporting that data to a new gateway". Merchants were still asking on the same thread in 2024 and 2025, and we found no Shopify help page since that describes an export. If you run subscriptions on Shopify Payments, assume the stored cards stay with Shopify unless it tells you otherwise in writing.
The same question is worth asking of any all-in-one system that stores cards on your behalf, such as a booking platform, an invoicing tool or a point-of-sale system. Ask before you sign, when you still have leverage: can the stored cards be exported to another PCI Level 1 processor, how long does it take, and what does it cost?
Larger merchants sometimes avoid the problem by keeping cards with an independent vault and routing payments to whichever processor they like. Spreedly is the best-known example. Its developer documentation describes a self-service export to supported gateways, "for the purpose of migrating one of your merchants to a new provider or for leaving the Spreedly platform completely", and a manual encrypted-file export to other PCI-compliant destinations that it generally completes within two weeks. Our review puts the entry price for the vault alone at $750 a month, before anything else, so this only makes sense at a scale where a lost card file would cost far more than that.


