One-click checkout · returning customers
Fewer steps for customers who come back
“One-click” in India is a promise about typing, not about security. A returning customer can skip the forms, but the bank still confirms the payment. This guide covers what can be remembered, what can't be skipped, and how to tell whether it's working.
Can go
Retyping contact details, address and card details
Stays
The payment authentication with the customer's bank
- 1Enter phone and email
- 2Type delivery address
- 3Choose a payment method
- 4Type card number, expiry, CVV
- 5Agree to save the card (optional)
- 6Authenticate with the card issuer
- 7Order placed
- 1Recognised: phone confirmed
- –Skipped: Type delivery address
- –Skipped: Choose a payment method
- –Skipped: Type card number, expiry, CVV
- –Skipped: Agree to save the card
- 2Confirm saved address and card ending 4821
- 3Authenticate with the card issuer
The rule that shapes every fast checkout
RBI's authentication directions, which payment system providers and participants had to comply with by 1 April 2026, say that all domestic digital payments must be authenticated with at least two distinct factors, and that for anything other than a card-present payment, at least one factor must be dynamic: unique to that transaction. Issuers can offer a choice of factors, and can add checks for riskier payments.
There are listed exemptions, including small-value contactless card payments and recurring charges under a registered e-mandate after the first. An ordinary online purchase by a returning customer isn't one of them. So a checkout that claims to take money with one tap and no authentication is either using an exemption or describing something else.
Where checkout time actually goes
| Step | Why it's slow | For a returning customer |
|---|---|---|
| Contact details | Typing on a phone keyboard | Recognise them: logged in, or a phone OTP to log in |
| Delivery address | Long, error-prone fields | Offer saved addresses; typing only for a new one |
| Choosing a method | Scanning a long list | Put their last-used method first |
| Card details | Sixteen digits, expiry and CVV | A saved, tokenised card: “Card ending 4821” |
| Payment authentication | OTP or app confirmation | Stays. It's the bank's step, not yours |
| Errors | A failure sends them back to the start | Keep the cart and details; offer another method |
What can be remembered, with consent
Everything a fast checkout remembers, it remembers because the customer agreed to it. That consent should be explicit, easy to withdraw and specific: saving an address is a different choice from saving a card.
Cards are the special case. Merchants and payment providers can't store card numbers; a saved card is a token, created with the customer's consent and their issuer's authentication. See card tokenisation.
- Who they areAccount login or phone numberYes
- Delivery addressesSaved in their accountYes
- Saved cardAs a token, never the numberYes, with issuer-authenticated consent
- Preferred methodLast-used UPI app or cardYes
- Card number or CVVCard issuers and networks onlyNo
- Skipping authenticationNot for ordinary purchasesNo
Two different questions: “who are you?” and “is this payment yours?”
Recognising the customer
You decide how: a logged-in session, or a phone OTP to log in. It gives them access to their saved details. It's your security question, answered by your system.
Authenticating the payment
The card issuer or the customer's bank decides, through their OTP, app confirmation or UPI PIN. It authorises the money to move. You can't replace it with your login.
Mixing the two up is how checkouts end up asking for an OTP twice, or promising to skip one that can't be skipped.
UPI in a fast checkout
On mobile, UPI is already close to one step for the customer: the checkout opens their UPI app with the amount filled in, and they confirm with their UPI PIN. The fast-checkout work is mostly about the steps around it: remembering which app they used last, and bringing them straight back to the order confirmation when they return from the app. See the UPI guide for how the payment itself works.
When the fast path fails
Card replaced
The issuer asks the customer's consent before linking the new card; until then the saved token may not work.
Token removed
The customer removed it at their bank or in your account settings.
Authentication fails
Wrong OTP, timed-out app confirmation, or the issuer's risk check.
Address outdated
A saved address the customer no longer uses.
The fallback is part of the product. Keep the cart and the details already confirmed, explain what happened in plain words, and offer the full list of methods. A fast checkout that fails into a blank form is slower than no fast checkout at all.
Designing the returning-customer screen
The fastest checkout is one screen that shows everything the customer already agreed to, lets them change any of it in one tap, and has a single button. The customer should never wonder what will be charged, to which card, or where it will be delivered.
Resist the temptation to hide the details to make it look faster. A returning customer who spots the wrong address after paying costs you a cancellation, a refund and some trust.
Welcome back, Priya
Illustrative- Deliver to
- Home · Flat 4B, Indiranagar
- Change
- Pay with
- Card ending 4821
- Change
- Total
- ₹1,899 incl. delivery
Pay ₹1,899
Saved details raise the stakes on your login
Once an account holds a saved address and a saved card, taking over that account becomes worth more to a fraudster. The payment itself is still protected by the bank's authentication, but a stolen account can still reveal personal details, redirect deliveries or be used to test cards.
- Protect the login in proportion to what it gives access to: confirm the phone number, and re-check when something changes, such as a new device or address.
- Tell customers when a card or address is added to their account, so they can object if it wasn't them.
- Show saved cards only as “ending 4821”, and never let the account page reveal more.
Don't punish first-time buyers
A fast path for returning customers shouldn't make the first purchase harder. Forcing an account before payment, or pushing “save your card” as if it were required, loses first-time buyers at exactly the moment you're trying to earn them.
Let people pay as a guest, offer to save details after the order is confirmed, and make saving each thing a separate, unticked choice. Customers who save willingly come back and use it; customers pushed into it remove it, or don't come back at all.
Measuring it honestly
Headline figures for “conversion uplift” are common and rarely comparable: they depend on how many customers return, what the old checkout looked like and how the test was run. We don't quote one. Measure your own.
Run a controlled test: returning customers split randomly between the old and new flow, for long enough to cover your weekly pattern. Compare the measures on the right, not just the headline.
- Checkout completion
- Orders paid, as a share of checkouts started by returning customers.
- Time to pay
- From checkout start to payment confirmed.
- Authentication success
- Payments authenticated, as a share of those sent for authentication.
- Fallback rate
- How often the fast path fails over to the full checkout.
One-click checkout questions
Can one-click checkout work across different merchants?
A saved card token is specific to the merchant it was created for, so saved cards don't follow the customer from one merchant to another. Some services remember customer details across merchants; what's shared, and with whose consent, is worth checking before relying on it.
Does a saved address need the customer's consent too?
Yes, in practice. Saving an address is saving personal data, so ask, say why, and make it easy to edit or delete. It's a separate choice from saving a card.
Does one-click checkout work for UPI?
The idea carries over: remember the customer's preferred UPI app and put it first, so paying is a tap into their app and a UPI PIN. The PIN is the payment authentication and stays.
Is it worth building for a small returning-customer base?
Probably not yet. The benefit grows with the share of orders from returning customers. If most of your orders come from first-time buyers, a clean guest checkout will do more.
Is true one-click payment allowed in India?
Not in the sense of paying with a single tap and no authentication. RBI's directions require domestic digital payments to be authenticated with at least two factors, one of them dynamic, unless the payment falls under a listed exemption such as recurring charges under an e-mandate after the first. One-click checkout removes typing and form steps; the authentication step remains.
What does a one-click checkout remember?
With the customer's consent: who they are, their delivery addresses, and their saved cards as tokens rather than card numbers. It can also remember their preferred payment method. It doesn't remember card numbers or skip the bank's authentication.
Is logging in with a phone OTP the same as authenticating the payment?
No. An OTP to log in tells you who the customer is. Authenticating the payment is done with the card issuer or the customer's bank or UPI app, and it's a separate step.
Will one-click checkout increase my conversion?
It can, because fewer steps usually means fewer drop-offs, but the effect depends on how many of your customers return and how your current checkout performs. Measure it with a controlled test rather than relying on anyone's headline figure, including ours.
What happens if a saved card no longer works?
The payment fails and the customer should fall back to the full checkout without losing their cart. Cards are replaced, tokens are removed by customers at their bank, and authentication can fail, so the fallback path matters as much as the fast one.
Can customers remove their saved details?
They should be able to, easily. For cards, RBI's tokenisation rules require merchants to offer a way to de-register a token, and issuers let customers remove tokens from their side too.
Does Peneu offer one-click checkout?
Which returning-customer features are available (saved cards through tokenisation, remembered details, preferred methods) depends on your setup and providers, and is confirmed during onboarding.
Speed up your returning customers
We'll look at your checkout and what can be remembered safely.
Talk to PeneuOfficial sources
- RBI — Authentication mechanisms for digital payment transactions Directions, 2025 (25 Sep 2025)Two factors for domestic digital payments, one dynamic for non-card-present payments; compliance by 1 April 2026; listed exemptions.
- RBI — Card-on-File Tokenisation (CoFT) Services (7 Sep 2021)Saved cards as tokens, consent with authentication, de-registration.
Last reviewed . Examples, amounts and screens marked illustrative are not Peneu figures.
