Square How-Tos

Is Square PCI Compliant? Card Security for Cafés Explained

By The Tany Team 8 min read

If you take card payments, “PCI compliance” is one of those phrases that sounds expensive and legally scary but rarely gets explained in plain language. For an independent café owner on Square, the honest answer is reassuring: Square carries the heaviest part of that burden for you, at no extra cost. But there is a real line where responsibility shifts back to you, and it is worth understanding exactly where it sits — especially as you add online ordering, a branded app, or third-party tools.

This guide explains what PCI compliance is, what Square actually covers, what you still own, and the single decision that determines whether card data ever touches your systems.

What is PCI compliance, in one paragraph?

PCI DSS — the Payment Card Industry Data Security Standard — is a set of security requirements created by the major card networks (Visa, Mastercard, Amex, Discover, JCB) to protect cardholder data. Any business that stores, processes, or transmits card numbers has to meet it. The standard sorts businesses into four merchant levels based on annual card transaction volume, with Level 1 (roughly 6 million+ transactions a year) facing the most rigorous validation and Level 4 (small merchants) the least. The core idea is simple: raw card numbers are dangerous to hold, so the standard pushes everyone to hold as little of it as possible, as securely as possible.

The practical question for a café owner is not “what level am I?” It is “does a raw card number ever land in something I control?” If the answer is no, your compliance obligations shrink to almost nothing.

Is Square PCI compliant?

Yes. Square is certified PCI DSS Level 1 compliant — the highest and most demanding level of validation, the same tier required of the largest payment processors in the world. That certification covers Square’s role as the service provider that stores, processes, and transmits card data on your behalf.

What that means for you: when a customer taps, dips, or swipes a card into a Square reader, or enters it into a Square-hosted online checkout, the card data flows into Square’s certified-compliant environment — not yours. Square’s hardware encrypts card data end to end, at no extra cost and with no configuration required on your part.

Crucially, Square also states that if you use Square for all storage, processing, and transmission of your customers’ card data, you do not need to take any steps to become PCI compliant, and you do not need to pay any PCI-compliance fees. You are not required to complete the Self-Assessment Questionnaire (SAQ) or run vulnerability scans for those Square-handled transactions.

What Square covers vs. what you still own

It is tempting to read “Square handles PCI” as “I never have to think about security.” That is not quite right. Here is the honest split.

ResponsibilityWho owns it on Square
Certifying the payment environment (PCI Level 1)Square
Encrypting card data on the reader / in transitSquare
Storing card numbers securely (tokenization)Square
Completing an SAQ for Square-processed paymentsNobody — not required
Paying a monthly PCI compliance feeNobody — Square doesn’t charge one
Strong, unique dashboard passwords + 2FAYou
Not writing card numbers on paper or in notesYou
Controlling who can log into your Square accountYou
Vetting any third-party tool that touches card dataYou

The pattern is clear: Square owns the technical, certification-heavy layer, and you own the human-and-access-hygiene layer. Nobody has to file the paperwork, because Square’s architecture keeps raw card numbers out of your hands entirely.

The one thing that shifts PCI scope back to you

Here is the line that matters. Square’s coverage holds as long as card data never touches a system you control. The moment you route payments through a third-party integration, a custom checkout, or any tool that handles raw card numbers, part of the compliance burden comes back to you — because now that data is passing through something Square hasn’t certified.

In practice, for a small café this almost never happens, because the safe options are also the easy ones:

  • In-person: cards go into Square hardware. Certified environment. You’re covered.
  • Square Online / Square-hosted checkout: the customer enters their card on a Square-hosted page. The raw number never reaches your website’s code. You’re covered.
  • A branded app or web ordering built on the Square Web Payments SDK: payment fields are hosted and tokenized by Square, so your app receives a token, never the card number. You’re covered.

Where owners occasionally get into trouble is doing something manual and well-intentioned — like taking a phone order and typing the card into a notes app, or emailing a card number to reconcile a catering deposit. That is exactly the behaviour PCI exists to stop. If you take phone orders, route them through the proper flow rather than jotting the number down.

The safest card number is the one your business never sees. Every reputable Square-based ordering channel is built so the raw card data goes straight to Square and comes back as a token.

Why “no PCI fee” is a bigger deal than it sounds

Many traditional merchant-account providers bundle a PCI compliance fee into your statement — often a few dollars to $20+ per month — plus a PCI non-compliance fee (sometimes $20–$45/month) if you fail to complete their annual questionnaire. Those fees are real line items that quietly erode your margin, and the non-compliance penalty punishes exactly the small operators least equipped to do the paperwork.

Square does not charge a PCI fee at all. Compliant processing is included in the standard transaction rate. That’s one fewer surcharge to audit — and it pairs with the broader work of understanding what Square’s fees actually are so you can see your true cost per order clearly.

How to keep your café’s card handling clean

None of this requires a security consultant. A short, practical checklist keeps you firmly inside Square’s coverage:

  1. Run every card through Square. Hardware in person; Square-hosted checkout online. Never build or bolt on a payment flow that captures raw card numbers.
  2. Never store card numbers manually. No sticky notes, no spreadsheet, no “I’ll type it in later” note on your phone. For recurring or catering payments, use Square’s card-on-file feature, which tokenizes the card inside Square.
  3. Lock down account access. Use a strong, unique password on your Square account, turn on two-factor authentication, and give staff their own permissions rather than sharing one login.
  4. Vet third-party tools before connecting them. If a tool asks to handle card data directly (rather than handing off to Square’s hosted payment fields), treat that as a red flag and ask how it affects your PCI scope.
  5. Keep devices current. Update your Square app and the operating system on the phones or tablets running it. Encryption and security patches only protect you if they’re installed.

Follow those five and, for a typical café, card data never touches anything you own — which is the whole point.

Where a branded app fits

If you’re adding online ordering or a branded mobile app, the security question to ask a vendor is blunt: “Does a raw card number ever pass through your servers, or does it go straight to Square?” The right answer is that it goes straight to Square via the Square Web Payments SDK, returning only a payment token to the app. That keeps your PCI scope exactly where it is for in-person payments — minimal.

That’s how Tany is built: a branded iOS and Android ordering app plus web ordering on top of your existing Square POS, with payments handled through Square’s own hosted, tokenized flow. So the card security story doesn’t change when you add a mobile channel — Square’s Level 1 compliance still covers the payment, live in about a day for $99 CAD/month per location. Adding a sales channel shouldn’t add a compliance headache, and done correctly it doesn’t.

The bottom line

For an independent café on Square, PCI compliance is largely a solved problem — as long as you let Square do its job. Square is certified PCI DSS Level 1, it covers the card data it handles, it charges no PCI fee, and it does not require you to file compliance paperwork for Square-processed payments. Your remaining job is small and sensible: good passwords, no manually stored card numbers, and never routing payments through a tool that handles raw card data outside Square. Do that, and “PCI compliance” stops being a scary phrase and becomes a box that’s already checked.

Sources

Frequently asked questions

Is Square PCI compliant?
Yes. Square is certified as PCI DSS Level 1 compliant, which is the most rigorous level defined by the Payment Card Industry Security Standards Council. Square maintains this certification for the card data it stores, processes, and transmits on your behalf, and it does not charge merchants a PCI compliance fee.
Do I need to do anything to be PCI compliant if I use Square?
For payments that run entirely through Square hardware and software, no. Square handles storage, processing, and transmission of card data, so you do not need to complete a Self-Assessment Questionnaire or validate compliance for those transactions. You are still responsible for basic security hygiene like strong passwords and not writing card numbers down.
Does Square charge a PCI compliance fee?
No. Unlike many traditional merchant-account providers that bill a monthly or annual PCI fee (and a non-compliance penalty if you skip the paperwork), Square includes PCI-compliant processing at no additional cost with no monthly contract or assessment requirement.
What could make my café responsible for PCI compliance again?
Using a third-party payment integration, custom checkout, or any tool that touches raw card numbers can pull part of the compliance burden back onto you. As long as every card is entered into Square hardware or a Square-hosted checkout, that raw data never reaches your systems and your scope stays minimal.