Article by Jason Mace, founder of SOTpay and hotel owner.
If your hotel takes bookings over the phone, you already know the routine. A guest calls, reads out their card number and expiry date, and someone on your team keys it into the terminal to hold the room or take a deposit. It has worked for years. In France, it is about to start getting declined.
That card-by-phone method has a name in the payments world: MOTO, short for Mail Order and Telephone Order. The Banque de France, through the Observatoire de la sécurité des moyens de paiement (the OSMP), is closing the door on it for hotels on a fixed timetable.

A MOTO payment is any card payment where the cardholder is not present and does not authenticate. They read their card details over the phone, or send them by email or post, and the merchant enters them. There is no 3-D Secure step, no one-time passcode, no app approval. For a hotel, that is exactly what makes it convenient. A guest calling from abroad to hold a suite for next month can pay without an app, a card reader, or a working data connection.
That convenience is also the weak point. Because nobody authenticates a MOTO payment, anyone who has a card number and expiry date can put one through. The OSMP's own figures show the fraud rate on these payments sits structurally higher than on payments made through 3-D Secure, and that gap is the reason the regime is changing.
Under the EU's second Payment Services Directive, strong customer authentication is the default for remote card payments, and MOTO has sat under an exemption. In France, hotels and similar accommodation businesses (Merchant Category Codes 3500 to 3999 and 7011) have also been exempt from the velocity limit that otherwise caps card-by-phone takings.
The OSMP is now removing that exemption in stages, on a timetable published by the Banque de France. For the hotel and lodging group, the cap on MOTO payments falls like this:
Velocity here means the cumulative amount taken from one card, at one merchant, over a rolling 24-hour period. So by late 2026 a hotel will not be able to take more than €500 from a single guest's card by phone in a day. A €900 deposit on a phone booking, a week-long stay settled over the phone, a group reservation: all of them start running into the ceiling.

When a payment goes over the limit, the issuing bank rejects it, in most cases by soft decline. The guest is not told why. From the front desk it simply looks like the card failed. Your team tries again, splits the amount, asks for another card, or loses the booking while they sort it out. Multiply that across a busy reservations line and the exemption you barely noticed becomes a daily friction you cannot ignore.
The regime targets one thing: payments taken without authentication. Authenticate the payment and the velocity limit no longer applies, because it is no longer an unauthenticated payment.
That is where a pay-by-link approach changes the maths. Instead of keying a card over the phone, you send the guest a secure payment link while you are still talking to them. They open it on the device already in their hand, authenticate through their own bank in the normal 3-D Secure flow, and pay. The payment is authenticated, so the velocity limit does not touch it, and the fraud exposure that made card-by-phone risky in the first place goes with it.
The link can travel however the guest prefers: SMS, email, WhatsApp, whatever suits the conversation. What matters is that the guest authenticates, on their own device, every time. It replaces the part of taking payments by phone that the new rules are built to stamp out.
For a hotel, the payment is only half the job. The other half is the payment landing correctly against the booking. SOTpay connects into the systems hotels already run on, including Oracle OPERA, so an authenticated payment reconciles against the reservation instead of becoming a line your night audit has to chase. The guest gets a familiar, secure way to pay, and your team stops rekeying card numbers into a terminal.

The OSMP has been explicit that it wants the industry to develop a strong authentication solution for telephone payments during 2026, and has noted that no uniform one exists yet. An authenticated pay-by-link is that solution, available now, on the authentication rails guests and banks already trust. Hotels that move before the €500 ceiling arrives will have the friction solved while their competitors are still working out why the terminal keeps saying no.
If you take card bookings by phone and you serve guests in France, this is worth getting ahead of. We work with hotels on exactly this.
Jason Mace
Founder, SOTpay
Jason Mace is the Founder of SOTpay and the entrepreneur behind Gala Tent, one of the UK's leading event shelter manufacturers. With more than 25 years of experience building businesses across events, hospitality, ecommerce, and payments, Jason has developed a strong reputation for identifying operational inefficiencies and creating practical commercial solutions around them.
Alongside SOTpay, Jason also operates Empress Rooms, a modern self-service hotel designed around streamlined guest experiences, secure keycode access, and operational efficiency. His experience across both hospitality and payments provides a unique perspective on the growing importance of frictionless customer journeys within modern business operations.

This article summarises the OSMP's published recommendations for general guidance and is not legal or compliance advice. The binding text is the French-language version issued by the Banque de France.
Need to ask a question: Request a callback from the team
Need merchant support? Visit Merchant Support