I have customers where we block all site to site AutoVPN connectivity with VPN firewall rules. Perhaps you could consider doing something similar with the VPN firewall rules?
If the backup link is cellular you can use cellular firewall rules.
https://documentation.meraki.com/MX/Cellular/3G%2F%2F4G_Cellular_Failover_with_USB_Modems#Cellular_F...
For AutoVPN, you can set a QoS marker, but AutoVPN itself doesn't do anything with it but pass it along. You can specify a priority for traffic heading to the Internet, but that is not this case.
having a think about this, I think you would be best to use a custom performance class.
https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Load_Balancing_and_Flow_Preferen...
You could direct all traffic to use one link, and your card machines to use another, and provide failover.
ps. When I have configured payment gateways in the past - they tend to have two. So I tend to configure the terminals to use one link to get to the first gateway and the second link to get to the second payment gateway. Then the terminals can do failover themselves as well.