Home>B2B & Wholesale>Payment Terms & Credit>Vaulted Cards in Shopify B2B vs Saved Cards

What is vaulted-card payment for B2B, and how is it different from storing a card on a regular customer account?

Vaulted cards in Shopify B2B are saved to a company location, not to a person. Every customer with permissions for that location can charge that card at checkout (Shopify Help Center, September 2026). A retail saved card belongs to one shopper. The B2B version is a shared corporate instrument, and it requires Shopify Payments.

The one difference that matters: whose card is it

"Credit card vaulting allows customers to securely save credit card information so that cards can be charged without having to enter the information every time" (per Shopify Help Center, September 2026). That description fits both retail and B2B. The ownership does not.

Retail saved cardB2B vaulted card
Attached toOne customer accountOne company location
Who can use itThat customerEvery customer with permissions for that location
Who can delete itThat customerAny customer with location permissions
Merchant-initiated chargeNot a routine flowStaff with Draft orders > Charge vaulted card permission
GatewayVariousShopify Payments only

A three-buyer purchasing department with one company card is the normal wholesale case, and the location-level model fits it. It also means the card is a shared credential in the operational sense: the person who added it and the person who spends on it need not be the same person, and the audit trail you want lives in your order records rather than in a card-management screen.

The risk posture is genuinely different

A retail saved card is the shopper's own instrument and the shopper carries the dispute. A B2B vaulted card sits on an account where the cardholder, the buyer and the approver can be three different employees of a company you have a contract with. The chargeback arrives against a corporate card with an internal approval story you cannot see.

Two practical consequences:

  • Departures break payment silently. When the employee whose card is in the vault leaves, the card is cancelled by their employer's finance team and nobody tells you. The failure surfaces on the next charge attempt, which on a net-terms account is 30 to 60 days after the order.
  • A deleted card does not orphan its existing orders. Shopify keeps a deleted vaulted account usable for payment-terms orders already placed against it, while blocking new ones (per Shopify Help Center, September 2026, describing vaulted bank accounts). Do not treat deletion as a stop-payment.

Vaulted bank accounts sit alongside, with tighter limits

Bank account vaulting for B2B works the same way and debits by ACH Direct Debit. It is "available only to merchants in the United States that use Shopify Payments and to customers with United States bank accounts" (per Shopify Help Center, September 2026). At checkout on a payment-terms order, the buyer nominates which vaulted bank account to debit when the term expires. The debit is not automatic: a person charges it, or a Shopify Flow automation does.

When NOT to vault

  • When you intend the card to be a credit limit. A vaulted card is a payment instrument, not a guarantee. Nothing checks available balance before an order.
  • When the account pays by wire and always has. Vaulting an emergency card that nobody uses is a card you are storing for no reason.
  • When the buyer is not on Shopify Payments. There is no vaulting without it, and switching gateways to get it is a much larger decision than this feature justifies on its own.

The Deploi point of view

Our own position, from building on Shopify. Separate from the facts above.

  • Our take: Treat a vaulted card as a convenience for the buyer and a collection mechanism for you, never as security for the terms. If the commercial intent is "we have recourse," the recourse is a signed credit application and a limit you enforce, not a card on file.
  • What we’ve seen: The stale-card problem is the one that actually costs money, and it is invisible until a term expires. We ask clients to run a low-value authorization against every vaulted card on a schedule they choose, so a dead card surfaces on their calendar rather than on the buyer's due date.
  • Where we disagree: Vaulting is routinely presented as the reason a B2B store can extend terms safely. It is not. The card reduces the friction of collecting from a customer who intends to pay. It does nothing about the customer who does not, which is the only case the risk budget is for.
  • What this page adds: that the vault is attached to the company location rather than the person, that deleting a vaulted account leaves existing payment-terms orders able to use it, and that the practical failure mode is a cancelled corporate card discovered 30 to 60 days late.

Reviewed by Martin Dejnicki, Director of SEO & AI Search. Facts verified 2026-09-14.