Why the Number Being Sent Is Not the Card Number
Tokenization replaces a card number with a substitute value that is useless anywhere else. The real number stays with a token service provider, and the merchant stores only a token scoped to one merchant, one channel, or one transaction. A stolen token cannot be replayed, because the mapping back to the card never left that provider.
The distinction from encryption is where most merchants get lost, and it matters commercially. Encrypted data is still the card number, protected by a key that can be stolen with it. A token is not the card number at all, which is why tokenization removes systems from the scope of card data handling rather than merely securing them. Kept out of the video entirely is any claim about a specific compliance outcome for a specific merchant — scope reduction depends on the integration, and a video that promises it will be quoted back during an assessment.
This template walks the mechanism through eight scenes: two following one checkout from card entry to token, one contrasting tokenization with encryption, one on what a stolen token is worth, two on where tokens are used across recurring billing and card-on-file, one on what still has to be protected, and one on what changes for the merchant's own systems.

