For manually entered or phone orders, enter the guest’s correct billing zip code.
Use a payment processor with Address Verification Service (AVS).
Note that AVS is not verified immediately but provides documentation for disputes.
Note: AVS and billing zip code verification apply to manually entered and phone orders. Toast does not currently perform real-time AVS/zip-code verification on online orders—an incorrect billing zip code will not prevent an online order from going through, so don't rely on this as a fraud check for that channel.
Avoid storing guest data unless necessary and ensure PCI compliance and encryption.
Avoid transactions with multiple declined cards.
Prefer EMV dip or tap for card-present transactions.
For phone or manually keyed orders, avoid keying in card details when a dip or tap option is available—keyed entries lose liability shift protection.
Note: This guidance is for in-person and phone orders. Online orders are inherently card-not-present and can't be avoided this way if you offer online ordering—see Protect against online order fraud below for that channel.
Online orders are always card-not-present, so this risk can't be fully eliminated. Toast runs automatic backend fraud checks (using signals like device, IP, and payment history) on every online order; there's no setting for restaurants to configure here.
If you notice a pattern of fraudulent online orders—for example, repeat chargebacks tied to the same guest—contact Toast Customer Care. Toast's Fraud team can block the email address and/or phone number tied to those orders from placing future orders.
Blocking a credential only prevents that guest from ordering again; it will not reverse or help win a chargeback already in progress on an existing order.
For specific chargeback disputes, use the Chargebacks report in Toast Web to review history and submit evidence through Chargeback Challenger.