How to Take Payments in GoTo: PCI-Compliant Contact Centre Payments

By Shuttle Team, May 27, 2026

GoTo Connect is a cloud-based UCaaS platform built for SMB and mid-market businesses, combining business phone, video, and messaging in one place. The GoTo Contact Center add-on extends that into an omnichannel contact centre with voice, SMS, web chat, email, and social channels including Messenger, Instagram, and WhatsApp. It is used by thousands of businesses to manage customer calls, support queues, and agent workflows from a single interface.

What GoTo Connect and GoTo Contact Center do not include is native card capture for the contact-centre or voice channel. GoTo has no PCI DSS payment product for agents taking card payments on calls. The only payment integrations in the GoTo ecosystem relate to the separate GoTo Webinar and GoTo Training products, which handle event ticketing. These have nothing to do with contact-centre payments. If a customer calls to pay a bill, top up an account, or place an order, there is no built-in mechanism inside GoTo to capture that card securely. The card capture has to come from somewhere else.

This guide is written for two audiences. The first is merchants who run their contact centre on GoTo and want to take PCI-compliant payments over voice or via payment links without rebuilding their infrastructure. The second is system integrators (SIs) who implement GoTo for clients and want to close the payment gap as part of a GoTo deployment. Shuttle is the payment layer that fills that gap, capturing card data in its own certified environment so it never reaches the platform your agents already use.

The Payment Challenge in GoTo

When a customer reads their card number aloud on a GoTo call, or types it into the GoTo chat interface, the card data travels through GoTo's voice stream, potentially into call recordings, and across agent screens. Every system that touches card data is pulled into PCI scope. That includes your telephony platform, your recording solution, your CRM, and your contact centre software. Under PCI DSS, you must demonstrate that each of those systems is secured, audited, and compliant.

The cost of building and maintaining that compliance in-house is significant. Initial certification for a Level 1 PCI programme typically runs above $500,000. Ongoing compliance, including annual assessments, penetration testing, vulnerability scanning, and internal resource costs, adds another $200,000 or more per year. That is before accounting for the time your engineering team spends managing scope, responding to audit requests, and keeping controls current as your infrastructure changes.

GoTo itself carries strong security credentials: SOC 2 Type II, SOC 3, BSI C5, and HIPAA-ready configurations. However, PCI DSS is not part of its certification set, and it has made no public commitment to providing a PCI-compliant payment capture product for contact centres. The IVR functionality within GoTo Contact Center handles routing and self-service navigation via DTMF tone input, but it does not include a secure payment capture environment. Merchants who need to take card payments in GoTo need a dedicated solution that removes card data from GoTo's environment entirely.

How Shuttle Adds Payments to GoTo

Shuttle adds PCI-compliant card capture to your GoTo payment flows. When the customer is ready to pay, the card is captured inside Shuttle's PCI DSS Level 1 certified environment via Twilio Pay (Shuttle is Twilio's preferred payments partner), and the card data never reaches your GoTo recordings, transcription, or your agents. Shuttle customers already take payments this way on GoTo-based operations today.

The setup is light. It runs on Twilio Pay, so you need to be a Twilio customer, and you build a small integration on your side. Shuttle ships the secure PCI capture, payment links, IVR, and the payment APIs; what it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call wired for GoTo specifically. So the part you build is small: pass the payment amount to Shuttle through its API (the minimum data we need), connect the secure capture into your GoTo call flow over Twilio, and add your own agent screen if your workflow needs one. Customers running GoTo have already built exactly this. If that fits, book a call and we will scope your exact setup. There is practical detail in the "What to Expect" section further down.


How It Works

Agent workflow

The agent keeps the customer on the GoTo call. When payment is required, the agent triggers a Shuttle session. On a voice call, the customer is prompted to enter their card number, expiry, and CVV using their phone keypad, and the digits are captured inside Shuttle's certified environment via Twilio Pay, so neither the agent's ear nor the recording system picks them up. The agent sees a masked status in real time: a confirmation that capture is in progress and a success or decline notification when the transaction is processed. The agent never sees the card number at any point.

Customer experience

On voice, the customer stays connected to the same agent and is guided through the keypad entry in a few seconds. For digital or follow-up payments, they receive a hosted payment link from Shuttle, tap to open it on their device, and return to the conversation once payment is confirmed. There is no requirement to call back or visit a separate website. The experience is fast and straightforward from the customer's perspective, which matters for first-call resolution rates.

Multi-PSP Support

Shuttle connects to 30+ supported gateways. If you already use Stripe, Adyen, Worldpay, Checkout.com, Braintree, or Square, you do not need to change your acquiring arrangement. Shuttle routes transactions to the gateway you already have in place, and switching later is configuration, not a re-integration.

For businesses that operate multiple brands, multiple client accounts, or have inherited mixed payment stacks through growth or acquisition, Shuttle supports per-client routing. Each call or transaction can be directed to a different gateway based on business logic you define. This is particularly useful for BPOs and managed service providers who run contact centre operations for more than one client and need to keep payment flows separated.

One caveat for voice specifically: a few gateways (for example Braintree) don't permit raw card data to be passed to them, so they don't work for voice capture, though they do work for payment links.

PCI Compliance

Shuttle is a PCI DSS Level 1 Service Provider, which is the highest level of certification available. Card data is captured inside Shuttle's environment and does not enter GoTo at any point. This means the card capture process is out of scope for your GoTo platform, your call recordings, and your agents' workstations.

Because Shuttle removes card data from your environment, businesses that previously faced a SAQ-D assessment (the most extensive self-assessment questionnaire, covering systems that store, process, or transmit cardholder data) can work toward SAQ-A compliance instead. SAQ-A applies when card data handling is fully outsourced to a PCI-compliant provider. Reducing your assessment scope cuts the compliance burden significantly for your internal team and your external assessors.

Beyond Voice: Payment Links

Payment links are the most turnkey path, and they do not require Twilio. Shuttle generates a hosted payment link and sends it via SMS or email, including mid-call to a customer who is still on the line. The link opens a Shuttle-hosted checkout page where the customer completes payment securely, and the payment status is returned to the agent as soon as the transaction is processed. Shuttle provides the link interfaces out of the box.

This is useful for follow-up billing after a call, payment requests sent over SMS for field service or delivery scenarios, and collections workflows where a link is sent after an initial conversation. Links also work with gateways that do not support voice capture, all routing through the same 40+ gateway network.

For Solution Providers and GoTo Implementation Partners

SIs who implement GoTo Contact Center for clients frequently encounter the payment gap during discovery. Clients running call centres for billing, collections, order taking, or account management need a compliant way to take card payments, and GoTo does not provide one out of the box. This is a solvable problem that can be scoped into a GoTo delivery and presented as part of a complete contact centre solution.

Shuttle's voice capture runs on Twilio Pay, so the client needs to be a Twilio customer, and the agent-side interface is built against Shuttle's APIs as part of your delivery. There is no pre-built GoTo widget today, though we can build a native GoTo integration as a paid project for a specific deployment. Clients retain their existing acquirer or choose from 30+ gateways. Voice payments are $0.20 per successful transaction with no setup fees, no monthly fees, and no per-seat charges, which is easy to include in a project cost model and simple to explain to clients. Payment links are currently free (a new pricing model is coming). You can build a proof of concept against Shuttle's sandbox gateway and demo app before deploying for a client.

Use Cases

Bill-Pay and Collections

Utilities, telecoms, financial services, and debt collection businesses that use GoTo to handle inbound and outbound payment calls. Shuttle enables agents to take card or direct debit payments on the call without putting the contact centre into PCI scope.

Order Taking and E-commerce Support

Retail and e-commerce businesses that take orders by phone or chat and need to process card payments at the point of conversation. Shuttle captures the card during the GoTo interaction and routes to the merchant's existing gateway.

Account Payments

SaaS, insurance, and subscription businesses that handle account top-ups, premium renewals, and invoice payments through their GoTo contact centre. Agents can accept payment mid-call without transferring the customer or asking them to pay online separately.

Bookings and Deposits

Service businesses that take deposits or full payments at the point of booking, including hospitality, healthcare, and professional services. Shuttle handles the card capture while the agent manages the booking inside GoTo.

What to Expect

Shuttle is a payment layer you connect to your stack, not a pre-packaged GoTo plugin. Here is the honest detail so there are no surprises on the call:

  • It runs on Twilio Pay today. Shuttle's voice capture uses Twilio Pay, where Shuttle is the certified payment connector, so you need to be a Twilio customer. A carrier-agnostic version that removes the Twilio requirement is on our roadmap for later in 2026.

  • You build a small integration, not a payment system. Shuttle ships the secure PCI capture, IVR, payment links, and payment APIs. What it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call for GoTo specifically. So you build that minimal glue: pass the amount to Shuttle via its API (the minimum data we need), connect the capture into your GoTo call flow over Twilio, and add your own agent screen if your workflow needs one. It is light, and customers running GoTo have already done it.

  • A native GoTo integration is available as a paid project. If you would rather not build the integration yourself, we can build one for your deployment with you.

  • Point-of-payment capture is what is live. Securely capturing the card at the moment of payment works today. Shuttle staying present across the entire conversation, or handing the caller back to the same agent afterwards, is part of the fuller call control coming with the carrier-agnostic version.

Payment links are the most turnkey path and need the least build. Many teams start there and add voice capture later.


FAQ

Does GoTo process payments natively?

GoTo Connect and GoTo Contact Center do not include a native contact-centre payment product. The only GoTo payment integrations in the marketplace relate to GoTo Webinar and GoTo Training for event ticketing, which are separate products. There is no built-in card capture for agents handling payment calls.

Does Shuttle have a native GoTo integration?

Not today. Shuttle's voice capture runs on Twilio Pay (we're Twilio's preferred payments partner), and you invoke that setup rather than installing a Shuttle app in GoTo. For voice you'll need to be a Twilio customer and to build the agent-side trigger for your workflow against Shuttle's APIs. Payment links require no Twilio relationship. We can build a native GoTo integration as a paid project if you'd rather not build it yourself, and a carrier-agnostic version is on our roadmap.

Does this require Twilio?

For voice capture, yes, today. The secure card capture runs via Twilio Pay, where Shuttle is the certified payment connector. Payment links do not require Twilio. The carrier-agnostic version that removes the voice requirement is on our roadmap for later in 2026.

How do I take PCI-compliant payments in GoTo?

Agents trigger a Shuttle session from within their GoTo workflow. On voice, Shuttle captures the card in a secure Twilio Pay call; for digital or follow-up payments, it sends a hosted link via SMS or email. Card data is captured inside a PCI Level 1 environment that is fully separate from GoTo's infrastructure.

Which gateways does Shuttle support?

Shuttle supports 30+ payment gateways including Stripe, Adyen, Worldpay, Checkout.com, Braintree, and Square. You can keep your existing acquirer and use per-client routing to direct transactions to different gateways based on business rules. Switching is configuration, not a re-integration.

Can't I just build payment capture into GoTo myself?

Building and maintaining your own PCI-compliant payment capture environment typically costs more than $500,000 to set up and over $200,000 per year to sustain. You also bear the ongoing risk of audit failures, data breach liability, and the engineering overhead of keeping controls current. Using Shuttle removes card data from your environment and from your compliance scope.

Can Shuttle handle outbound payment collection in GoTo?

Yes. For outbound collections, agents can trigger a secure Twilio Pay capture during the outbound call or send a hosted payment link via SMS or email. Shuttle supports both inbound and outbound contact-centre payment scenarios.

Related Reading

Take Payments in Your GoTo Contact Centre

Shuttle adds PCI-compliant card capture to a GoTo-based operation, via Twilio for voice and via payment links over SMS or email, without bringing your contact centre into PCI scope. We'll walk you through what's live today and the path for your setup.

See Payment Services | Book a discovery call

Talk to us

See how Shuttle can power payments for your platform: multi-PSP, multi-channel, white-label.

Book a Call