At 1:54 p.m. Eastern on a Thursday in September 2023, Square stopped working. Not slowly — all at once, across the country.
It came back 15 hours and 25 minutes later. In between, an ice cream shop with three locations lost between $8,000 and $10,000. A Cincinnati pizzeria lost $651 in sales and about $90 in staff tips. A New Jersey empanada shop lost around $2,000, and its owner said the line that should be printed on the wall of every POS vendor's office:
— Harry Coleman, Empanada Harry's, to NBC News
The root cause was mundane. A firewall rule change at 11:04 a.m. expanded further than intended; a DNS change went out two minutes after the failures began. Square's own post-incident report is admirably direct about it.
The sentence in that report that should interest you most is this one: "Sellers without offline mode support were most severely impacted."
The short answer
Cash still works. Live card authorization stops. What else survives depends on your architecture: a local or hybrid POS keeps ringing orders and printing kitchen tickets, a pure-cloud POS may not. Gift cards, loyalty redemption, online ordering, delivery apps and multi-terminal sync go down almost everywhere.
Offline mode stores the card and bills it later — at your risk, not your vendor's. It is a payment-capture feature, not an operations feature, and it has to be configured before the outage, not during it.
Six different outages, and only one is "the internet"
A card tap crosses eight links before anyone says yes. Almost every article on this topic stops at link three.
In the last four years, merchants have been knocked offline by their own internet provider, by their POS vendor, by their acquirer, by a card network, by a cloud provider, and by a security vendor's software update. Six different causes. Six different remedies.
Cellular failover fixes exactly one of them.
| What actually failed | Card auth | POS rings orders | Kitchen tickets | Multi-terminal sync | Does offline mode help? |
|---|---|---|---|---|---|
| Reader or Bluetooth drop | No | Yes | Yes | Yes | No — the card can't be read at all |
| Router / local network down | No | Each device alone | No — printers unreachable | No | Partly. Cards store; tickets die. |
| Internet down, LAN alive | No live | Yes | Yes | If local sync exists | Yes — this is the case it was built for |
| POS vendor's cloud down | No | Architecture decides | Local/hybrid only | No | Sometimes — unless the vendor is also your processor |
| Acquirer / processor down | No | Yes | Yes | Yes | Yes, but the queue only drains when they return |
| Card network down | No for that scheme | Yes | Yes | Yes | Barely — and not at all for Interac |
Compiled from vendor documentation, September 2026. Behaviour varies by system; check yours against the links at the bottom.
What offline mode actually is
Offline mode does one thing. It moves authorization from before the customer leaves with the goods to after.
Stripe's documentation says it more plainly than any marketing page will: payment information is collected at the time of sale, and "authorization is only attempted after connectivity is restored."
Read that again with a customer standing in front of you. At the moment they walk out, nobody has checked whether that card is good, has funds, is stolen, or is real.
You have a promise. Not a payment.
Who eats the decline
Every major platform answers this question the same way, in writing, in language they clearly had a lawyer look at.
- Square: you're responsible for expired, declined or disputed offline payments — and Square "is unable to provide customer contact information or contact customers on your behalf."
- Toast: "You are responsible for any declined, expired, or disputed payments while operating in offline mode."
- Stripe: you "assume all decline and tamper-related risks," and if the payment can't be forwarded or the issuer declines it, "there's no way to recover the funds."
- Adyen: "You are fully liable."
- Moneris: same, and it caps your daily offline exposure at 20% of projected monthly volume whether you like it or not.
Adyen also publishes the number that lets you size the risk: authorization rates run from about 95% upward. Call it roughly one stored transaction in twenty that may never authorize.
Square's current support documentation states that from April 2026, offline payments are automatically enabled on all your devices unless you opt out. Offline card acceptance moved from opt-in to opt-out — which means a lot of sellers are now carrying store-and-forward decline risk by default, without ever having chosen it. Worth five minutes in your settings this week.
Toast operators: the equivalent setting, "Card authorization during payment disruptions," is also on by default and labelled "recommended."
Every vendor's offline limits, in one table
These numbers are hard to find and none of them are in a sales deck. All quoted from vendor documentation, September 2026.
| System | Per-transaction cap | Expiry window | Card entry offline | Excluded |
|---|---|---|---|---|
| Square POS | Merchant-set, $1–$50,000 within Square's band | 72h hard expiry; 24h recommended | Chip, tap, swipe | Gift cards, Tap to Pay, keyed cards, EBT, Interac |
| Toast | Optional threshold, manager override above it | 3 days max; auths can expire "as early as 24 hours" | Swipe only — chip disabled | Gift cards, loyalty, house accounts, pre-auth (bar tabs) |
| Clover Mini / Flex | Merchant-set | 7 days by default | Not published | Apps can override your caps |
| Clover Go | No offline support at all | |||
| Lightspeed Retail | Cash only by default; can't view inventory, sell or redeem gift cards, or search products by name | |||
| Lightspeed Restaurant | Manual payment types; 7 days max recommended; kitchen printing survives if the LAN is up | |||
| Shopify POS | Merchant-set per order and per device | No hard expiry stated; "ideally within 24 hours" | Chip + contactless | Swipe, Tap to Pay, keyed, Interac; unavailable in France |
| Stripe Terminal | $10,000 hard ceiling | Reader must have paired online within 24h; firmware under 30 days | Chip + tap only — swiping banned | Interac, US PIN-debit rails, QR wallets; no refunds until forwarded |
| Moneris | Within daily limit | Not published | Chip + PIN required | Interac ineligible; capped at 20% of monthly volume |
Note the contradiction inside Square's own material: its April 2024 press release says sellers have 24 hours to reconnect, while the current support article says payments expire after 72. Treat 72 hours as the hard wall and 24 as the target.
The trap nobody writes about: EMV fallback
Offline mode doesn't only delay authorization. On some systems it changes how the card is read — and that has legal consequences.
Toast's platform guide lists, under features not available offline: "Using EMV credit card mode (credit cards must be swiped)." Offline Toast payments are magstripe swipes.
Stripe forbids exactly that: "Because magnetic stripe data is easy to spoof, Stripe disallows this option while operating offline."
Two mainstream platforms, opposite rules, opposite consequences. Since the October 2015 EMV liability shift, processing a counterfeit chip card as a magstripe swipe moves the counterfeit-fraud loss onto the merchant. A swipe never generates the chip's one-time cryptogram.
So a restaurant running offline on a swipe-only system is stacking three liabilities at once: no authorization, contractual responsibility for the decline, and EMV fallback exposure on top. That's worth knowing before you decide what your offline cap should be.
Canada: the paragraph that matters most
Offline mode does not cover Interac. Square excludes it. Shopify excludes it. Stripe excludes it. Moneris — a Canadian acquirer — excludes it.
On 8 July 2022, the Rogers outage took Interac down nationwide. Interac's own statement noted the platform handles nearly 25 million transactions on a day like that one. Businesses could not accept debit regardless of which internet provider they used, because the failure wasn't at their end.
No offline mode would have saved a single one of those sales. If debit is most of your volume, your outage plan needs a second card rail or a cash plan, not a better POS setting.
The quiet failures that actually stop service
Losing card auth is the loud problem. These are the ones that stop the kitchen.
- Shared checks stop syncing. Toast disables sharing orders between devices offline. A server who opened table 12 on one tablet cannot close it on another. Toast's own advice is to have each employee pick one device and stay on it.
- Check numbers get reassigned. Toast renumbers offline checks as (device number + 2) × 1,000, so device 1 starts at 3000 — a small detail that tells you how completely the shared state is gone.
- Gift cards die everywhere. No local balance means no safe redemption. Square, Toast and Lightspeed all block sale and redemption offline.
- Loyalty redemption stops. Square lets you accrue points retroactively, but only if you manually link them afterwards.
- Bar tabs break. Toast can't pre-authorize cards offline. No pre-auth, no card-held tab.
- Tips can get stranded. Toast auto-captures payments after nightly closeout and warns that once that runs, payments can't be updated with tips. That's why the Cincinnati pizzeria's loss included $90 of staff tips, not just the owner's revenue.
- Retail oversells. Lightspeed Retail can't show inventory offline and can't search products by name — only by SKU or barcode.
- Refunds stop. Stripe can't refund an offline payment until it's been forwarded. A same-day refund on an offline sale simply isn't available.
- Online orders keep leaking after you're back. Delivery platforms pause storefronts that stop confirming, and reactivation isn't instant.
- You may not be able to close the day. Lightspeed Restaurant loses end-of-day reconciliation offline.
What it costs, and how long you actually have
A 2025 study of UK retail and hospitality put real numbers on something most operators only feel.
The same study found merchants average five or more significant outages a year, that 61% land in peak trading, and that 22% of businesses have no backup payment method at all.
Cash covers less of the gap than people assume. Cash is about 14% of US payments by count. Fewer than 30% of consumers carry any. And nearly two-thirds of the cash payments that do happen come from people who would rather have used a card.
Our model checks out against reality. Applied to the September 2023 Square outage it predicts roughly $2,900 for a typical full-service restaurant over that window — and the reported actuals bracket it: $651 at a small pizzeria, $2,700–$3,300 per location at the ice cream chain.
The pre-outage checklist
Do this on a quiet Tuesday. You cannot do it during a rush, because every one of these settings has to already be in place before the connection drops.
- Turn offline mode on deliberately and set your own caps. A per-transaction limit near your realistic largest ticket — not the vendor's maximum. Square will let you sit at $50,000. Almost nobody should.
- Set a total exposure ceiling you could absorb losing outright. That is the actual question: how much unauthorized card volume can you afford to write off?
- Check your excluded rails. Interac in Canada. EBT/SNAP on Square. Tap to Pay on phones. Find your gaps now, not mid-outage.
- Configure backup printers. On Toast, kitchen tickets fall back to "backup printers (if configured)." That parenthetical is doing a lot of work.
- Test it for real. Unplug the WAN cable on a slow morning and run three sales end to end. Do the tickets print? Can two servers still see one table? Does the terminal still take a card?
- Add cellular failover — a router with an LTE backup SIM, or a phone hotspot with a written procedure. It fixes the ISP case, which is the most common one.
- Keep a manual fallback kit at the pass: a pad of paper tickets, a pen, and a printed price list. Unglamorous and it has saved more services than any feature.
- Know your two status pages by heart — your POS vendor's and your processor's. "Is it us or them?" is the first question and it should take ten seconds.
The in-outage runbook
- Identify which link failed, in this order. Is another device on the same Wi-Fi online? Then it's not your ISP. Is the vendor status page red? Then it's not you. Can the card terminal reach its own processor independently? Then payments may still work even if the POS doesn't.
- Tell the room before they ask. A sign at the door and a line from whoever greets people. Customers forgive a problem they were told about; they leave over one they discover at the till.
- Decide your offline posture out loud. Are you storing cards, or going cash-only? If you're storing, say the cap to your staff as a number and mean it.
- Capture contact details on every offline sale. Name, phone or email on the ticket. When a decline lands 48 hours later, that scrap of paper is the only thing standing between you and eating it — Square won't give you the customer's details.
- Get tickets to the kitchen any way you can. Backup printer, handwritten pad, expo calling. Service continuing at all is worth more than service continuing cleanly.
- Watch the clock against the expiry window. Seventy-two hours on Square, and less in practice. If you're near the wall, stop storing and go cash.
- Reconcile the same day you're back. Every stored payment, every decline, every missing ticket. The Square outage left about thirty transactions unaccounted for at one merchant the next morning.
- Write down what broke. Not for the report — for the settings you'll change next Tuesday.
Where JET sits, honestly
Two structural things are true about how JET is built, and they're worth stating plainly rather than dressing up.
JET is hybrid. The station works online and offline — that's the design, and it's the reason we lead with it rather than with a feature list.
We are not your payment processor. Your card terminal is your own, connected to your own processor, on its own connection. That's normally discussed as a pricing advantage — and it is, which is why we wrote a whole guide on processor lock-in. But it's also a reliability property, and a less obvious one.
When your POS vendor is also your processor, a single company's bad afternoon takes out both your order screen and your ability to get paid. That's precisely what happened in September 2023. Separating those two things doesn't make outages impossible. It makes one outage into two smaller, independent ones.
No POS on earth authorizes a card with no connection to anyone — the issuing bank has to say yes, and the bank is not in your building. Any vendor implying otherwise is selling store-and-forward with better adjectives. The honest question isn't "does it work offline?" It's "which of the six links can I survive, and what does it cost me when I can't?"
What we'd do on Monday
Open your POS settings and find the offline section. Note the caps, the expiry window and whether it's already on. If you're on Square, check whether the April 2026 default has switched it on for you.
Then unplug your internet for ten minutes on the slowest morning of the week and watch what happens. You'll learn more in those ten minutes than in any comparison chart, including ours.
For a cross-vendor view of how systems are architected — rather than how they're marketed — WHICHpos publishes its scoring method, including how it weights reliability and lock-in.
Disclosure: WHICHpos is published by Solvr Solutions Inc. — the same company that makes JET. It is a sister site, not an independent referee. Read its scoring method and check its figures against the vendors’ own pages before you weigh anything it says about us.
