Smart Shopping

A Glossary of Online Shopping Security Terms

Share
Laptop screen displaying a secure padlock icon during an online checkout process
HTTPS padlock meaning Data is encrypted in transit between your browser and the site
PCI DSS governing body PCI Security Standards Council
Chargeback time limit (typical) 60–120 days from the transaction date, depending on card network
2FA second factor options SMS code, authenticator app, hardware key, or email code
CVV storage rule Merchants may not store CVV/CVC after authorization under PCI DSS (PCI DSS v4.0)
Common phishing delivery methods Email (most common), SMS ("smishing"), and voice calls ("vishing")

Why This Vocabulary Matters When You Shop Online

Online shopping involves a web of invisible security systems — encryption protocols, authentication layers, fraud-detection rules — that most shoppers never see. But when something goes wrong, understanding the vocabulary helps you act quickly and accurately. Knowing what a chargeback is before you need one, or recognizing a phishing attempt before you click, can be the difference between a resolved incident and a compromised account.

This reference covers the terms you're most likely to encounter on checkout pages, in account settings, in retailer security disclosures, and in fraud alerts from your bank. Each definition is written to be practical, not technical. For a broader look at staying safe wherever you shop, see Online Shopping Safety From Start to Checkout.

HTTPS padlock meaning Data is encrypted in transit between your browser and the site
PCI DSS governing body PCI Security Standards Council
Chargeback time limit (typical) 60–120 days from the transaction date, depending on card network
2FA second factor options SMS code, authenticator app, hardware key, or email code
CVV storage rule Merchants may not store CVV/CVC after authorization under PCI DSS (PCI DSS v4.0)
Common phishing delivery methods Email (most common), SMS ("smishing"), and voice calls ("vishing")

Core Security Terms Defined

The glossary below covers the terms most relevant to recognizing secure retail environments and protecting yourself from fraud. Encryption and authentication terms appear first, followed by payment-specific concepts, then the threat types most commonly used against online shoppers.

SSL / TLS

Secure Sockets Layer (SSL) and its successor Transport Layer Security (TLS) are encryption protocols that scramble data traveling between your browser and a website's server. When a site URL begins with "https://" and shows a padlock icon, TLS is active. This means payment details and login credentials are encrypted in transit.

Two-Factor Authentication (2FA)

A login method that requires two forms of identity verification — typically your password plus a one-time code sent to your phone or generated by an authenticator app. Even if someone steals your password, 2FA blocks them from accessing your account without the second factor.

Chargeback

A forced transaction reversal initiated through your card issuer when a charge is disputed — for example, due to fraud or an item that never arrived. Chargebacks are a consumer protection mechanism, but they are subject to deadlines and documentation requirements set by your card network.

Phishing

A fraudulent attempt to steal sensitive information — passwords, card numbers, account credentials — by disguising a message or website as a trustworthy source. Phishing typically arrives via email, text, or social media and often creates false urgency to prompt quick action.

Spoofing

The act of disguising a communication's origin to appear as a legitimate entity. Email spoofing makes a message look like it came from a known retailer; website spoofing copies a real store's design to capture your login or payment details.

PCI DSS

The Payment Card Industry Data Security Standard is a set of security requirements that any business handling credit or debit card data must meet. Compliance is managed by the PCI Security Standards Council and helps ensure merchants handle card data responsibly.

Tokenization

A process where your actual card number is replaced with a randomly generated token for storage and transmission. Even if a retailer's database is breached, the token has no usable value without the system that generated it.

CVV / CVC

The Card Verification Value (or Code) is the 3- or 4-digit security number on your payment card. Merchants are generally prohibited from storing this code after a transaction under PCI DSS rules, which limits its usefulness to fraudsters who obtain stored card data.

Cookie

A small text file a website stores in your browser to remember preferences, session status, or browsing behavior. Session cookies expire when you close the browser; persistent cookies remain longer and can track behavior across visits for advertising or analytics purposes.

Man-in-the-Middle Attack

A type of cyberattack where an attacker secretly intercepts and potentially alters communication between two parties — for instance, between your device and a shopping site. Public Wi-Fi networks are a common environment for this threat, which is why HTTPS matters.

Data Breach

An incident in which unauthorized parties gain access to a system and expose personal or financial records. Breached data — including email addresses, passwords, and card numbers — frequently appears for sale on dark web marketplaces.

Virtual Card Number

A temporary, single-use card number generated by some banks or payment services for online purchases. The virtual number links to your real account but expires quickly or is limited to one merchant, reducing fraud risk if the number is later stolen.

HTTPS Is Necessary, But Not Sufficient

A padlock in the browser bar confirms your connection is encrypted — it does not confirm the site is legitimate or trustworthy. Fraudulent sites can and do obtain TLS certificates. Always verify the full domain name carefully before entering payment details. For more signals of a trustworthy store, see The Anatomy of a Trustworthy Online Retailer.

Understanding the distinction between a data breach and a phishing attack matters practically: a breach at a retailer exposes data the company already held, while phishing targets you directly to hand over data voluntarily. Your response to each should differ. If you want to understand how your payment method shapes your fraud protection rights, Debit Card vs. Credit Card for Online Purchases is a useful companion. Account security decisions — including whether to save card details with a retailer — also tie directly to how you register: Guest Checkout vs. Creating an Account walks through those choices in detail.

Smart Shopping Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Smart Shopping Editorial Team →
Disclaimer: The content on this site is provided for informational purposes only and should not be considered a substitute for professional advice. While we strive to provide accurate and up-to-date information, we make no guarantees regarding its completeness or accuracy. Always consult a qualified professional for advice specific to your circumstances before making any decisions.