Why Is Link Saving My Customer’s Payment Info?

If you run a WooCommerce store that uses Stripe, there is a good chance you have Link enabled on your checkout right now and don’t know it. We know this because we have fielded several versions of the same support request lately, and it always starts with a confused or upset email from a customer.

The emails usually say something like:

“You saved my payment information without asking me. I tried to contact Link but they want me to sign into an account I never created. I need this account deleted.”

If you have received one of these, don’t worry. Nothing was hacked, nothing was leaked, and your store did not do anything wrong. But your customer’s confusion is understandable, and it helps to know exactly what happened so you can respond with confidence.

What Link actually is

Link is Stripe’s one-click checkout network. Here is how a customer ends up with a Link account:

  1. The customer pays on any store that uses Stripe.
  2. The payment form offers to save their information “for faster checkout with Link.” This is a small checkbox or toggle, and it is easy to miss.
  3. If they accept (knowingly or not), Stripe creates a Link account tied to their email address and stores their card or bank details on Stripe’s servers.
  4. The next time they shop at any store that uses Link, their info autofills.

Why it looks like a scam to your customer

Here is how the situation unfolds from your customer’s side:

  1. Some time after their order, they get an email from Link, a company they have never heard of, saying their payment information has been saved.
  2. They try to do something about it: click through from the email, look for a way to contact Link, or find an unsubscribe option.
  3. Everything they try leads to a sign-in screen for an account they never knowingly created, with no password they could possibly know.
  4. At this point it looks exactly like a phishing scam: a mystery company claims to have their payment details and wants them to “log in.” So they refuse, and they email the one party they recognize. You.

The missing piece is that Link accounts do not use passwords, for anyone. There is no login credential your customer is missing. Link signs everyone in with a one-time code sent to their email or phone, and that code is also how Link verifies the person is really the account owner. That is why every path leads to the sign-in wall: Link will not show account details to anyone until ownership is verified. It is a reasonable security design that reads as suspicious if nobody explains it, and nobody explains it.

What to tell your customer

A few plain facts usually resolve the situation:

  • Your store never stored their card information. Stripe processed the payment, which means Stripe already had the card details the moment the order went through. That is what a payment processor does. Link retained that information for reuse. Nothing new was captured.
  • There was a consent step. The save-with-Link option appeared on their payment form. It is subtle, and that is a fair criticism of Stripe’s design, but it is not zero consent.
  • Only the customer can delete the account. Neither you nor Stripe support can remove it on their behalf, because Link requires the account owner to verify ownership first.

Then give them the piece of information nobody else has given them: where to actually go, and the fact that no password exists. Here are the removal steps to send them:

  1. Go to link.com and enter your email address. There is no password, and you are not creating an account by doing this.
  2. Enter the one-time code Link sends to your email or phone. The code is the entire sign-in.
  3. Open the settings area.
  4. Delete your saved payment methods.
  5. Close the account.

The whole process takes about two minutes.

Should you keep Link enabled?

That depends on your customers.

Reasons to keep it:

  • Link genuinely speeds up checkout for people who use it.
  • For stores with an online-native audience, it can improve conversion.

Reasons to turn it off:

  • If your customers skew less technical, the confusion may cost you more than the faster checkout gains you.
  • One panicked customer who believes your store leaked their card number can undo a lot of trust.
  • These conversations take real time to untangle, for you and for your customer.

If you have already received one of these emails, that is usually a sign your audience falls in the second group.

The good news is that disabling Link is straightforward. In WooCommerce, it is a single setting inside the Stripe payment configuration. Turning it off does not affect normal card payments, existing orders, or anything else about how Stripe works on your site. It just stops the save-my-info prompts at checkout.

We can handle it for you

If you are a Cinch client and want Link turned off, or you are not sure whether it is even enabled on your store, just reach out. We will check your Stripe configuration, make the change, and test your checkout to confirm everything still runs clean.

And if one of your customers has already sent you the alarmed email, we are happy to help you draft a response that explains what happened and walks them through removing their information. We have done it a few times now.

Leave the first comment