How to Take Payments in GoTo: PCI-Compliant Contact Centre Payments

By Shuttle Team, May 27, 2026

GoTo Connect is a cloud-based UCaaS platform built for SMB and mid-market businesses, combining business phone, video, and messaging in one place. The GoTo Contact Center add-on extends that into an omnichannel contact centre with voice, SMS, web chat, email, and social channels including Messenger, Instagram, and WhatsApp. It is used by thousands of businesses to manage customer calls, support queues, and agent workflows from a single interface.

GoTo is not a payment processor. If your GoTo Connect or GoTo Contact Center setup has no secure card capture step, and a customer calls to pay a bill, top up an account, or place an order, the card capture has to come from somewhere else.

This guide is written for two audiences. The first is merchants who run their contact centre on GoTo and want to take PCI-compliant payments over voice or via payment links without rebuilding their infrastructure. The second is system integrators (SIs) who implement GoTo for clients and want to close the payment gap as part of a GoTo deployment. Shuttle is the payment layer that fills that gap, keeping card data out of the platform your agents already use.

The Payment Challenge in GoTo

When a customer reads their card number aloud on a GoTo call, or types it into the GoTo chat interface, the card data travels through GoTo's voice stream, potentially into call recordings, and across agent screens. Every system that touches card data is pulled into PCI scope. That includes your telephony platform, your recording solution, your CRM, and your contact centre software. Under PCI DSS, you must demonstrate that each of those systems is secured, audited, and compliant.

The cost of building and maintaining that compliance in-house is significant. Initial certification for a Level 1 PCI programme is expensive, and ongoing compliance, including annual assessments, penetration testing, vulnerability scanning, and internal resource costs, adds more every year. That is before accounting for the time your engineering team spends managing scope, responding to audit requests, and keeping controls current as your infrastructure changes.

GoTo itself carries strong security credentials: SOC 2 Type II, SOC 3, BSI C5, and HIPAA-ready configurations. The IVR functionality within GoTo Contact Center handles routing and self-service navigation via DTMF tone input. If your GoTo setup has no secure payment capture step, merchants who need to take card payments in GoTo need a dedicated solution that keeps card data out of GoTo's environment.

How Shuttle Adds Payments to GoTo

Shuttle adds PCI-compliant card capture to your GoTo payment flows. When the customer is ready to pay, the card is captured through Twilio Pay and passed to Shuttle's PCI DSS Level 1 environment, and the card data never reaches your GoTo recordings, transcription, or your agents.

The setup is light. It runs on Twilio Pay, so you need to be a Twilio customer, and you build a small integration on your side. Shuttle ships the secure PCI capture, payment links, IVR, and the payment APIs; what it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call wired for GoTo specifically. So the part you build is small: pass the payment amount to Shuttle through its API (the minimum data we need), connect the secure capture into your GoTo call flow over Twilio, and add your own agent screen if your workflow needs one. If that fits, book a call and we will scope your exact setup. There is practical detail in the "What to Expect" section further down.


How It Works

Agent workflow

The agent keeps the customer on the GoTo call. When payment is required, the agent triggers a Shuttle session. On a voice call, the customer is prompted to enter their card number, expiry, and CVV using their phone keypad, and the digits are captured through Twilio Pay and passed to Shuttle's PCI DSS Level 1 environment, so neither the agent's ear nor the recording system picks them up. The agent sees a masked status in real time: a confirmation that capture is in progress and a success or decline notification when the transaction is processed. The agent never sees the card number at any point.

Customer experience

On voice, the customer stays connected to the same agent and is guided through the keypad entry. For digital or follow-up payments, they receive a hosted payment link from Shuttle, tap to open it on their device, and return to the conversation once payment is confirmed. There is no requirement to call back or visit a separate website. The experience is fast and straightforward from the customer's perspective, which matters for first-call resolution rates.

Multi-PSP Support

Shuttle connects to 30+ supported gateways. If you already use Stripe, Adyen, Worldpay, or Checkout.com, you do not need to change your acquiring arrangement. Shuttle routes transactions to the gateway you already have in place, and switching later is configuration, not a re-integration, though saved cards stay with the gateway that stored them.

For businesses that operate multiple brands, multiple client accounts, or have inherited mixed payment stacks through growth or acquisition, Shuttle supports per-client routing. This is particularly useful for BPOs and managed service providers who run contact centre operations for more than one client and need to keep payment flows separated.

One caveat for voice specifically: a few gateways (for example Braintree) don't permit raw card data to be passed to them, so they don't work for voice capture, though they do work for payment links.

PCI Compliance

Shuttle is a PCI DSS Level 1 Service Provider, which is the highest level of certification available. Card data is captured through Twilio Pay and does not enter GoTo at any point. This keeps card data out of your GoTo platform, your call recordings, and your agents' workstations, which limits their PCI scope.

Because Shuttle keeps card data out of your environment, businesses that previously faced a SAQ-D assessment (the most extensive self-assessment questionnaire, covering systems that store, process, or transmit cardholder data) can work toward SAQ-A compliance instead. SAQ-A applies when card data handling is fully outsourced to a PCI-compliant provider. Reducing your assessment scope cuts the compliance burden significantly for your internal team and your external assessors.

Payment links are the most turnkey path, and they do not require Twilio. Shuttle generates a hosted payment link and sends it via SMS or email, including mid-call to a customer who is still on the line. The link opens a Shuttle-hosted checkout page where the customer completes payment securely, and the payment status is returned to the agent as soon as the transaction is processed. Shuttle provides the link interfaces out of the box.

This is useful for follow-up billing after a call, payment requests sent over SMS for field service or delivery scenarios, and collections workflows where a link is sent after an initial conversation. Links also work with gateways that do not support voice capture, all routing through the same 40+ gateway network.

For Solution Providers and GoTo Implementation Partners

SIs who implement GoTo Contact Center for clients may meet the payment question during discovery. Clients running call centres for billing, collections, order taking, or account management need a compliant way to take card payments, and where the deployment has no secure capture step, it has to come from somewhere else. This is a solvable problem that can be scoped into a GoTo delivery and presented as part of a complete contact centre solution.

Shuttle's voice capture runs on Twilio Pay, so the client needs to be a Twilio customer, and the agent-side interface is built against Shuttle's APIs as part of your delivery. There is no pre-built GoTo widget today. Clients retain their existing acquirer or choose from 30+ gateways. Voice payments cost $49 per live instance per month, plus from $0.20 per transaction, falling with volume, billed through your Twilio account, with no per-seat charges, which is easy to include in a project cost model and simple to explain to clients. See pricing. You can build a proof of concept against Shuttle's sandbox gateway and demo app before deploying for a client.

Use Cases

Bill-Pay and Collections

Utilities, telecoms, financial services, and debt collection businesses that use GoTo to handle inbound and outbound payment calls. Shuttle enables agents to take card or direct debit payments on the call while limiting the contact centre's PCI scope.

Order Taking and E-commerce Support

Retail and e-commerce businesses that take orders by phone or chat and need to process card payments at the point of conversation. Shuttle captures the card during the GoTo interaction and routes to the merchant's existing gateway.

Account Payments

SaaS, insurance, and subscription businesses that handle account top-ups, premium renewals, and invoice payments through their GoTo contact centre. Agents can accept payment mid-call without transferring the customer or asking them to pay online separately.

Bookings and Deposits

Service businesses that take deposits or full payments at the point of booking, including hospitality, healthcare, and professional services. Shuttle handles the card capture while the agent manages the booking inside GoTo.

What to Expect

Shuttle is a payment layer you connect to your stack, not a pre-packaged GoTo plugin. Here is the honest detail so there are no surprises on the call:

  • It runs on Twilio Pay today. Shuttle's voice capture uses Twilio Pay, where Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways, so you need to be a Twilio customer. Shuttle works with Twilio today, and any carrier coming soon.

  • You build a small integration, not a payment system. Shuttle ships the secure PCI capture, IVR, payment links, and payment APIs. What it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call for GoTo specifically. So you build that minimal glue: pass the amount to Shuttle via its API (the minimum data we need), connect the capture into your GoTo call flow over Twilio, and add your own agent screen if your workflow needs one. It is light.

  • Point-of-payment capture is what is live. Securely capturing the card at the moment of payment works today. Shuttle staying present across the entire conversation is not available today, and Shuttle does not ship call hand-back after payment out of the box. What happens to the caller after payment is part of the call flow you build in Twilio. Works with Twilio today, and any carrier coming soon.

Payment links are the most turnkey path and need the least build. Many teams start there and add voice capture later.


FAQ

Does GoTo process payments natively?

GoTo is not a payment processor. If your GoTo Connect or GoTo Contact Center setup has no secure card capture step, the capture for payment calls has to come from a separate provider.

Does Shuttle have a native GoTo integration?

Not today. Shuttle's voice capture runs on Twilio Pay, and you invoke that setup rather than installing a Shuttle app in GoTo. For voice you'll need to be a Twilio customer and to build the agent-side trigger for your workflow against Shuttle's APIs. Payment links require no Twilio relationship. Shuttle works with Twilio today, and any carrier coming soon.

Does this require Twilio?

For voice capture, yes, today. The secure card capture runs via Twilio Pay, where Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways. Payment links do not require Twilio. Shuttle works with Twilio today, and any carrier coming soon.

How do I take PCI-compliant payments in GoTo?

Agents trigger a Shuttle session from within their GoTo workflow. On voice, Shuttle captures the card in a secure Twilio Pay call; for digital or follow-up payments, it sends a hosted link via SMS or email. Card data is captured inside a PCI Level 1 environment that is fully separate from GoTo's infrastructure.

Which gateways does Shuttle support?

Shuttle supports 30+ payment gateways including Stripe, Adyen, Worldpay, and Checkout.com. You can keep your existing acquirer and put each client on its own gateway. Switching gateways is configuration, not a re-integration, though saved cards stay with the gateway that stored them.

Can't I just build payment capture into GoTo myself?

Building and maintaining your own PCI-compliant payment capture environment is expensive to set up and to sustain every year. You also bear the ongoing risk of audit failures, data breach liability, and the engineering overhead of keeping controls current. Using Shuttle keeps card data out of your environment, which limits your compliance scope.

Can Shuttle handle outbound payment collection in GoTo?

Yes. For outbound collections, agents can trigger a secure Twilio Pay capture during the outbound call or send a hosted payment link via SMS or email. Shuttle supports both inbound and outbound contact-centre payment scenarios.

Take Payments in Your GoTo Contact Centre

Shuttle adds PCI-compliant card capture to a GoTo-based operation, via Twilio for voice and via payment links over SMS or email, while limiting your contact centre's PCI scope. We'll walk you through what's live today and the path for your setup.

See Payment Services | Book a discovery call

Talk to us

See how Shuttle can power payments for your platform: multi-PSP, multi-channel, white-label.

Book a Call