The stored card edit flow that quietly kills repeat purchase conversion
Most merchants optimise the acquisition funnel obsessively and leave the account management layer almost entirely untouched. That asymmetry has a real cost, and Baymard Institute has now put a name and a mechanism to it: the forced delete-then-add sequence that greets customers trying to update an expired or replaced payment card.
The pattern is widespread because it appears to follow logically from PCI-DSS constraints. Merchants cannot store or display full card numbers, so editing a saved card at the token level is technically not possible in the way editing a postal address is. The mistake is treating that infrastructure constraint as a UX constraint. It is not. The delete-and-create token logic can be wrapped inside a single interface action that presents to the customer as a normal, unremarkable edit. Compliance position unchanged. Experience transformed.
For Dutch and Belgian merchants, this is not a marginal edge case. Stored credential use is growing as subscription models and one-click checkout become standard expectations rather than premium features. The customers most likely to hit a broken card update flow are exactly the ones worth protecting: people who have already converted more than once and were actively trying to transact again. Losing them at this moment is particularly damaging because they leave no signal. There is no abandoned cart event, no failed payment notification. They simply do not come back.
The practical implication is straightforward. Pull up your saved payment method screens today and walk through a card update as a customer would. If the flow requires a visible delete step before adding new card details, you have a documented conversion problem with a ready solution that introduces zero compliance risk. That belongs in the next sprint, not the next quarter.
Source: baymard.com



