We have been analyzing the NCR Retail Online (NRO) business and our NCR Industry Solutions Board, an internal team that helps set strategy, has decided to set the NRO product to End of Life on March 31, 2018 . The CPOnline Product was also recently announced with an end of life date of September 30th, 2017 . The End of Life terms indicate that all current customers will need to be transitioned off their respective product and the servers turned off by 9/30/17 (CPO) & 3/31/18 (NRO) . Your NCR Counterpoint business partner has been notified of this decision in advance and has started taking steps to help you transition your eCommerce solution.

Next Steps

As of today, we are encouraging all customers to reach out to your current NCR Counterpoint Partner to begin the transition to a new eCommerce platform. Your partner will be your best resource in planning and transitioning to a new eCommerce solution.

NCR has worked with several partners to create options for your new eCommerce solution. Please refer to the below chart for information about these options. Your partner can provide you with further documentation about these solutions to assist you with the decision process. You can also view a list of FAQ’s about moving from NRO to one of the below options by clicking here .

We will be discussing this transition directly with the users that attend our Synergy User Conference at the end of June. We will be offering a presentation on eCommerce and we will have representatives at the exhibit booth to handle your questions. In the meantime, please reach out to your partner to help determine your next steps.

We appreciate your business and look forward to taking this next, innovative step together.

Recommended eCommerce Solutions

Solution Cost Platform Additional Notes
Commerce5
  • Upfront: Starts at $2500**
  • Monthly: Starts at $495.00 plus hosting
Magento Most tightly integrated with Counterpoint and offers the most advanced features
CP Magento
  • Upfront: Starts at $2,500**
  • Monthly: Starts at $200.00 including hosting
Magento Integrated with Counterpoint and offers features similar to NRO
CP Shop
  • Upfront: Starts at $999**
  • Monthly: Starts at $125.00 plus hosting
Woo Commerce Catalog, Inventory, and Orders are integrated with Counterpoint

Safely Handling NCR's Stored Payment Tokens Before Shutdown

Retailers across Melbourne, Brisbane, and the regional centres of New South Wales who built their ecommerce presence on NCR Retail Online now face a hard deadline. The platform has been discontinued, and shops need to move operations to alternatives such as Magento or WooCommerce through NCR Counterpoint partners. Buried inside that transition sits a quiet but serious responsibility: the credit card tokens resting in the NCR database.

Stored payment tokens are not actual card numbers. They are the encrypted placeholders that let returning customers check out with one tap, skip re-entering card details, and keep the experience familiar to anyone who has used tap-and-go at a Sydney café. That same data sits inside an environment bound by the Privacy Act 1988 and the Notifiable Data Breaches scheme, which means mishandling it can trigger real consequences for an Australian business.

What a Payment Token Really Represents in Your NCR Database

A token replaces the primary account number with a non-sensitive reference that points back to the real card data held by a payments processor or vault. In Australia, where contactless payments made up the bulk of in-store transactions well before the pandemic, customers got used to that speed and rarely tolerate being asked to re-enter card details at checkout. Tokens preserve that experience while limiting exposure of the actual card number, and they let a store in Parramatta or Fitzroy recognise a returning shopper on the second visit.

That distinction matters during a migration. The token itself is meaningless to anyone outside the issuing processor, but a poorly handled export file or a sloppy database backup can drag the original cardholder data along with it. APRA-regulated entities and PCI DSS obligations treat that kind of exposure seriously, and the Office of the Australian Information Commissioner has shown it will act on complaints about lax handling of financial identifiers.

Mapping Every Token to a Customer and an Order

Before deciding what to do with a token, you need to know which customer it belongs to and which transactions reference it. A common first step is running an audit report inside NCR that pulls every active token, the masked card brand, the last four digits, the issuing country, and the linked customer record. This exercise mirrors the steps outlined for auditing your current inventory data before the move, except here the focus is payment data rather than stock levels.

A clean map also surfaces tokens that point to customers who have not ordered in two years. Aged tokens from dormant accounts in Hobart or Darwin are useful candidates for removal because their owners are unlikely to notice them disappear. Tokens tied to active subscription buyers, on the other hand, deserve a different treatment because losing them forces every recurring customer back through the entry screen.

Choosing the Right Path for Each Token

Once you know what you are dealing with, the path forward depends on the volume of repeat business, the appetite of your new platform, and the regulator's expectations. Some teams wipe every token and start fresh, while others pay for a vault migration service so that loyal customers keep their one-tap checkout. The table below sketches how the four most common paths compare for an Australian retailer working under local privacy rules.

Approach Best fit Customer experience Compliance effort Residual risk
Delete all tokens before cutover Stores with mostly one-off buyers Returning customers re-enter card Low Lowest
Migrate tokens via new processor vault Subscription or repeat-heavy stores Returning customers keep one-tap checkout Moderate Moderate
Leave tokens in NCR until licence ends Short window before full decommission Behaviour unchanged briefly Higher Higher
Encrypt and archive offline Compliance-driven retention policy Customers re-enter on new platform Highest upfront Lowest active

For a small suburban operation that sells mostly through Afterpay and rarely sees a second order from the same card, wiping tokens makes sense and removes a class of risk. For a wine club near Adelaide's Rundle Mall with thousands of recurring members, a vault migration through the new platform's preferred processor usually pays for itself in recovered checkout conversions.

Cleaning Up Backups, Logs, and Forgotten Exports

Even after the live tokens have been addressed, copies linger in places people forget. Database snapshots saved to a shared drive, CSV exports emailed to a manager, and error logs dumped into a ticketing system can all carry the same tokenised references, and in some cases the truncated card data needed to reconstruct the original number. A walk through the shared drives on the office NAS in Brisbane or the cloud storage bucket used by the marketing team often turns up files nobody has touched since 2021.

Those files need to be deleted, not archived, unless the business has a documented retention requirement under Australian financial record-keeping rules. A retention policy that names a specific cut-off and the staff member who authorised the archive is far easier to defend if the OAIC ever comes asking. Anything outside that policy should be erased, with the deletion logged in a register that the auditor can review.

Coordinating the Cutover with Your New Platform

The cutover itself is where most data mishaps happen, because two systems are live at the same moment. NCR is winding down, the new platform is warming up, and a small window exists where a token could be written to the old system by a delayed cron job and never make it across. Scheduling the migration for an Australian Sunday morning between midnight and 6 am AEST, when transaction volume from local shoppers is at its lowest, gives the team time to reconcile and roll back if the export counts do not match.

Communication with customers matters here as well. A short email explaining that stored card details will need to be re-entered, sent a week before the cutover, tends to deflect the support tickets that arrive the moment a regular buyer in Fremantle tries to check out and finds the saved card gone. The broader security considerations when switching cover what the new platform should support before any card data is accepted.

A practical safety net is to run the export twice and diff the resulting files. If the two dumps match line for line, the token population is stable. If they do not, the discrepancy usually points to a background process that has not been disabled and is still adding new tokens to the NCR database, which means the cutover is not yet safe to start.

Verifying That Nothing Was Left Behind

Once the new platform is live and NCR is being decommissioned, verification is the only way to know the work is finished. A final report from NCR showing zero active tokens, supported by confirmation that the decommission script completed without errors, is the cleanest form of evidence. Pair that with a fresh penetration test that scans the old database files for stray references, and you have a paper trail that satisfies both internal auditors and the OAIC.

For the rare cases where an old tokenised PDF receipt or a legacy export has to stay readable, remember that signed PDFs cannot be edited without breaking the signature, which is why some teams look at tools like PDF Decrypter Pro only as a last resort for legitimate redaction work, not as a way to keep card data alive in a forgotten file. The cleaner outcome is to retire the document entirely.

The practical work here is unglamorous and the rewards are invisible until something goes wrong. An Australian retailer who walks through this checklist, audits every token, picks the right disposal path for each one, scrubs the backups, times the cutover for a quiet Sunday morning, and verifies the result with a clean report has done the responsible thing. Tokens quietly disappear from the old database, customers re-enter cards once on the new platform, and the next quarter's PCI scope shrinks back to a manageable size.

After you have completed your move to a new eCommerce platform, don’t forget to submit the Store Closure Request form to close your NRO site and cancel your billing subscription.