Apple Pay lets you pay by holding an iPhone or Apple Watch near a contactless payment terminal, or by authorizing a payment inside an app or on the web. What makes it interesting from a security standpoint isn't the tap itself — it's what doesn't happen during that tap. Your actual card number is never transmitted to the merchant, and in many cases it isn't even stored on your device.

Adding a Card: What Happens During Setup

When you add a debit or credit card to the Wallet app, your device sends the card details to your card issuer (the bank that issued the card) to verify it and determine whether it's eligible for Apple Pay. If approved, the issuer — not Apple — creates a substitute number called a Device Account Number. This number is encrypted and stored in a dedicated hardware chip on your device called the Secure Element, which is physically isolated from the rest of the operating system. Your actual card number is not stored on the device or on Apple's servers in a form that's accessible during a purchase.

Tokenization: The Core Security Mechanism

The Device Account Number is a form of "tokenization" — a security technique where a sensitive number (your real card number) is replaced with a substitute token that's only meaningful in a specific, narrow context. Even if this token were somehow intercepted during a transaction, it generally can't be used to make purchases elsewhere, because it's tied to your specific device and, on top of that, each individual transaction uses a further one-time dynamic security code layered on top of the token.

This is a meaningful structural difference from swiping or inserting a physical card, where the actual card number is what gets transmitted and stored (at least temporarily) by the merchant's payment system.

Biometric or Passcode Authentication

Every Apple Pay transaction requires authentication — typically Face ID, Touch ID, or your device passcode, depending on your device and settings. This step confirms that the person holding the device is authorized to use it before the payment is approved. Biometric data itself (your face or fingerprint data) is processed and stored locally in a separate secure hardware area and is not shared with Apple, the merchant, or your card issuer as part of a transaction.

What Happens at the Terminal

During an in-store tap-to-pay transaction, your device communicates with the terminal over near-field communication (NFC) — a very short-range wireless connection that only works within a couple of centimeters. The terminal receives the Device Account Number and a transaction-specific dynamic code, not your actual card number, and passes that along to be processed through the normal card payment network, similar to how a regular contactless card transaction is processed.

In-App and Online Purchases

The same tokenization principles apply when you use Apple Pay to check out inside an app or on a supporting website, rather than tapping a physical terminal. You authenticate with Face ID, Touch ID, or your passcode, and the merchant's payment system receives the device-specific token rather than your card details, which reduces how much sensitive payment data online merchants need to store or handle at all.

What Apple Pay Does and Doesn't Share

A common misconception

Apple states that Apple Pay transactions are designed so that Apple does not store the details of what you purchased, and merchants receive a device-specific token rather than your actual card number or your name in most transaction flows. Your card issuer, however, still processes the underlying transaction and retains visibility into it, the same as it would for any purchase made with that card — tokenization changes what the merchant sees, not what your bank sees.

If Your Device Is Lost or Stolen

Because Apple Pay transactions require biometric or passcode authentication, a lost or stolen device alone doesn't automatically grant someone the ability to make purchases with your cards. As an added precaution, Apple's Find My service allows you to remotely suspend Apple Pay on a lost device, and you can also contact your card issuer directly to suspend or remove a specific card from Apple Pay if you're concerned about unauthorized use.

How This Compares to Standard Contactless Cards

Many physical debit and credit cards now also support tap-to-pay using similar NFC contactless technology. The meaningful security difference is authentication and tokenization: a standard contactless card transaction below a certain amount typically doesn't require a PIN or signature, and it transmits data tied more directly to the actual card, whereas an Apple Pay transaction requires biometric or passcode confirmation on every transaction and relies on the device-specific token structure described above.

Frequently Asked Questions

Does Apple Pay store my actual credit card number?

No. Your device stores an encrypted, device-specific Device Account Number issued by your card provider, not your actual card number, and this token is stored in an isolated hardware chip called the Secure Element rather than in general device storage.

Can someone use Apple Pay if they steal my phone?

Every Apple Pay transaction requires authentication via Face ID, Touch ID, or your device passcode, which meaningfully limits what a thief could do without also having your biometric access or passcode. You can also remotely suspend Apple Pay through Find My if your device is lost.

Does the merchant see my name and card number when I use Apple Pay?

In most transaction flows, the merchant receives a device-specific payment token rather than your actual card number. Whether your name and other order details are shared depends on the specific merchant and transaction type, similar to any other card payment.

MyAVLock Editorial Team

Our editorial team researches consumer technology and payment security topics and writes explanatory guides for general readers. We are not affiliated with Apple and do not sell or process payments.