Why Booking Platforms Won't Release Card Data
Back to Blog

Why Booking Platforms Won't Release Card Data

Your clients' saved cards are locked in your booking platform. Here's why card data portability is so hard, and what you can do about it before you switch.

·5 min read

TL;DR: Saved card data is governed by PCI compliance rules, and the entity that tokenized the card controls the token. Your booking platform is almost always that entity, which means your clients' card-on-file data doesn't leave with you when you switch software. Knowing the mechanics before you give notice can prevent months of lost recurring billing.

You can export your client list. You can pull appointment history along with notes, and intake forms and contact details come with them. What you almost certainly cannot grab on your way out the door is the card data your clients stored for memberships and packages, or for quick checkout.

For a spa or salon running recurring memberships, that restriction is not a minor inconvenience. It is the thing that makes switching software feel financially dangerous. Owners stay on platforms they dislike for years because re-collecting card information from hundreds of clients seems worse than writing another monthly check.

Understanding why this happens and what the actual rules are makes the decision cleaner. Knowing what your options look like helps too.

Why the Card Data Isn't Yours to Take

When a client saves a card at checkout, the raw card number is never stored anywhere near your booking software's database. PCI DSS (the Payment Card Industry Data Security Standard) prohibits storing full card numbers in plain text. What happens instead is that the payment processor tokenizes the card: the actual digits are replaced with a unique token that only the processor can decode.

Your booking platform stores that token, not the card. The token is processor-specific. It works only with the processor that created it. Move to a different processor and the token is worthless. Move to a different booking platform that uses a different processor, same result.

This is why the restriction is structural, not arbitrary. The card data your clients handed you lives inside the processor's vault. The platform you're leaving controls that vault, or has a commercial agreement with the entity that does.

What the Platforms Actually Say

The policies vary by platform, and the details matter if you're planning a move.

Fresha's help center states, as of September 2026, that client card details can't be exported or transferred. Full stop. The architecture doesn't include a path for it.

Mindbody's support center says, as of September 2026, that card data can be exported to a new provider only when the business cancels its Mindbody subscription completely, and that there is a charge for the export. So the card release is gated behind cancellation and behind a fee. You pay to leave with data that your clients gave you.

Other platforms have their own policies and processor relationships. The pattern is consistent: the entity that tokenized the card controls whether and how those tokens transfer.

This is worth reading before you sign any software contract, not after.

What a Transfer Request Actually Involves

In some cases, a card transfer is possible. Processor-to-processor transfers happen in the industry, particularly when two platforms share a processor or when a processor agrees to re-tokenize cards for a receiving platform.

When a spa switches to Tersavia, we request the transfer of its clients' saved cards from its current payment processor, so card-on-file clients, memberships, and recurring billing can come with it. The current processor controls the release. We make the request, but the outcome depends on the processor's policies and the relationship between platforms.

That distinction matters. Any vendor promising you'll keep every saved card is overpromising. A good migration process makes the request and tracks the result. It then gives you a clear picture of what transferred and what didn't so you can re-collect the gaps before a billing cycle runs.

More detail on how this works in practice is at Tersavia's saved cards migration page.

What Happens to Memberships When Cards Don't Transfer

If you run recurring memberships and a billing cycle runs before you've re-collected a client's card, the charge fails. Depending on your software's handling, the client either gets an automated notice or the failure is silent until a staff member catches it in a report.

A failed billing cycle is recoverable. It is also avoidable with planning.

The standard approach: run your last billing cycle on the old platform before cutover. Time your switch to start the day after that cycle clears. Build a 30-day window for re-collecting card information from members whose cards didn't transfer, using your usual communication channels. A simple "we've upgraded our system, please update your payment method" message converts most of it.

Owners who've been through this before they were ready will tell you the payment re-collection is not what's hard. It's explaining to a client why they need to enter their card again when they already have a membership. Clear, early communication handles most of that friction.

The card-on-file migration guide covers the full pre-switch checklist if you want to work through the sequence.

The Broader Export Picture

Card data is the most locked-down element of your client file, but it's worth understanding what else varies by platform before you assume everything else moves cleanly.

Appointment notes and intake responses have their own export logic, and so does purchase history. Some platforms export these as clean CSV files. Others require a support ticket. Some charge for the export itself, separate from any card-related fee. The data export fees post breaks down what the major platforms charge and where the walls are.

The short version: the closer data gets to financial or identity information, the more tightly the platform controls the exit path. Contact details are usually easy. Payment history is harder. Saved cards are hardest.

Planning a switch means working backward from the hardest data type, not the easiest.

FAQ

Can I download my clients' saved credit card numbers from my booking platform?

No. Full card numbers are never stored by booking software. They are tokenized by the payment processor at the moment of entry. What exists in your platform is a processor-specific token, not the card itself. You cannot export raw card numbers, and no legitimate platform would allow it.

What does Fresha say about card data export?

Fresha's help center states, as of September 2026, that client card details can't be exported or transferred. There is no documented transfer path available through their platform.

Does Mindbody charge to release card data when you cancel?

Mindbody's support center states, as of September 2026, that card data can be exported to a new provider only after the business cancels its Mindbody subscription completely, and that there is a charge for the export.

What should I do about memberships if my card transfer request is denied?

Time your platform switch so your last billing cycle runs before cutover. Then build a re-collection window (typically 30 days) and send members a clear message asking them to update their payment method. Most members respond quickly when the communication is straightforward.