Web

How to Choose a Payment Gateway: What to Check Before You Sign

Talha AslanTalha Aslan 16 min read

Choosing a payment gateway looks like a pricing decision, but it quietly shapes your cash flow, your fraud exposure and your checkout conversion. I have set up online payments with clients since 2012. The same pattern keeps repeating: teams compare the headline fee and skip payout timing, refunds and licence checks. This guide walks through the criteria I actually use. I will not recommend a specific provider. Instead, you get a framework to judge any offer on your desk.

What is a payment gateway and what does it actually do?

A payment gateway is the service that securely passes card and wallet payments from your website to the banks that approve them. The customer enters card details, the gateway sends them for authorisation, and the money reaches your account after a settlement period. It is the bridge between your checkout and the card networks.

In practice, people use the term loosely. Some providers bundle three things: the gateway, the merchant account and the payment processing. Others only sell the gateway, so you still need a merchant account from a bank. Therefore, the first step is to ask exactly which parts each offer includes. Otherwise, you compare packages that are not comparable.

Also, a payment gateway is not only for online shops. Consultants take deposits through payment links. Clinics charge booking fees. Software companies bill subscriptions every month. So even if your site has no shopping cart, you probably need a reliable way to take card payments.

Should you choose a bank merchant account or a payment service provider?

The core difference is who you sign with. With a bank merchant account, you contract directly with an acquiring bank. With a payment service provider (PSP), a licensed intermediary aggregates many merchants and works with acquirers on your behalf. Both models have their place.

CriterionBank merchant accountPayment service provider
OnboardingSlower, often needs trading historyUsually fast, open to small businesses
PricingNegotiable at higher volumeFlat published rates, less room to negotiate
Payment methodsMostly cardsCards, wallets and local methods
IntegrationBank specific documentationReady plugins and one API
Account stabilityUnderwritten upfrontRisk reviews can happen after launch

For a new brand, a PSP usually means less friction. However, as monthly volume grows, a direct bank relationship can become cheaper. That is why many businesses start with a PSP, then add or switch to a bank account later.

How do you verify that a payment provider is properly licensed?

Check the regulator's public register before you sign anything. In the European Union, payment institutions operate under the revised Payment Services Directive, PSD2 (Directive (EU) 2015/2366), and national supervisors keep registers. In the UK, you can search the FCA Financial Services Register. Other countries run similar databases.

Here is the catch: the brand name and the legal entity often differ. So search for the legal name in your contract, not the logo on the website. Then confirm which services that entity may provide. For example, a firm licensed only for money remittance may not be allowed to acquire card payments.

  • Match the contract's legal entity against the official register.
  • Read the list of permitted payment services.
  • Look for how customer funds are safeguarded.
  • Check that a written complaints route exists.

Working with an unlicensed intermediary shifts all the risk to you. If the firm freezes or disappears, your settlements go with it. That is a risk no discount can justify.

How should you compare payment gateway fees?

The headline percentage is only one line of the bill. Real cost also includes a fixed fee per transaction, cross-border and currency conversion charges, refund fees, chargeback fees, monthly minimums and sometimes setup costs. Together, these define what you really pay.

Therefore, model your own sales mix before comparing offers. What share of orders comes from domestic cards? What is your average order value? How often do customers ask for refunds? Without these three numbers, any comparison is guesswork.

Worked example: imagine 400 orders a month with an average basket of 25 units of your currency. Offer A has a slightly lower percentage plus a fixed fee per transaction. Offer B has a slightly higher percentage and no fixed fee. With small baskets, the fixed fee can easily cost more than the rate difference. You can run your own numbers in minutes with the percentage calculator.

Also ask whether fees carry VAT in your jurisdiction and how invoices are issued. The VAT calculator helps your accountant check each line.

How do payout schedules affect your cash flow?

A payout schedule, or settlement period, is the time between a successful payment and the money landing in your bank account. Even at the same fee, a different payout rhythm can change your working capital a lot. Faster payouts often cost more; in other words, you pay for speed.

For a store that buys inventory upfront, this balance is critical. If you pay suppliers today and receive customer money weeks later, cash gets tight. On the other hand, a service business without stock may accept slower payouts in return for lower fees.

Watch for rolling reserves as well. Some providers hold back a percentage of each payout for months as protection against chargebacks. That money is yours, but you cannot use it. So ask in writing: how long is the payout delay, is there a reserve, and when is it released?

In practice, I ask clients to build a simple cash calendar. One column lists expected sales. The next shows payout dates. A third lists supplier payments. As a result, you see in advance which weeks will be tight. That table also strengthens your hand when you negotiate payout terms.

Do buy now, pay later and instalment options really lift sales?

Instalments and buy now, pay later (BNPL) can make higher priced purchases easier to commit to. However, the effect depends heavily on the product. For small baskets, most customers simply pay in full. For furniture, electronics or courses, visible instalment options can matter more.

Still, these options are not free. BNPL providers typically charge merchants a higher fee than standard card processing. Consumer credit rules also vary by country, and some regulators are tightening them. Therefore, check both the cost and the compliance position before switching them on.

  • Who pays the instalment cost: you or the customer?
  • Is the instalment price shown clearly on the product page?
  • How are refunds handled on a split payment?
  • Does the option work on mobile without extra redirects?

From my field experience, hiding payment options until the last step is a missed chance. Showing "pay in instalments" on the product page supports the decision earlier. This ties directly to the friction points I describe in UX mistakes that kill sales.

Why does 3D Secure matter so much?

3D Secure is the authentication layer where the cardholder's bank verifies the buyer during checkout, usually through a banking app or a one time code. The current version, EMV 3-D Secure, is published by EMVCo. It aims to reduce friction on low risk payments while still checking risky ones.

In the European Economic Area, strong customer authentication (SCA) under PSD2 makes this kind of check a regulatory expectation for many online card payments. Outside Europe, 3D Secure is often optional. Even so, it is worth it for one main reason: liability shift. When a payment passes authentication and the cardholder later claims fraud, liability generally moves away from the merchant.

That said, 3D Secure can cost some conversions. A slow banking app or a broken mobile challenge page makes customers leave. So test the flow on your own phone before committing. Try cards from several banks, note how long the challenge takes, and check the error messages. Then ask the provider to report authentication failure rates every month.

Hosted payment page or embedded checkout: which is better?

There are two basic integration routes. In the first, customers leave your site and pay on the provider's hosted page. In the second, the payment form appears inside your checkout, although card data still goes straight to the provider. Each route has different effects on security, design and conversion.

A hosted page is the simplest to launch, because card data never touches your server. However, the brand experience breaks, and some shoppers hesitate when the domain changes. Embedded fields, delivered through an iframe or the provider's JavaScript library, feel smoother. If you build them badly, though, you take on more security work.

My preference is embedded fields from the provider's secure components. As a result, the design stays consistent and card numbers never reach your server. Plan this at the start of a web design project; retrofitting it later is always more expensive.

Does PCI DSS compliance apply to small businesses?

Yes, it does. PCI DSS is the card industry security standard for any business that stores, processes or transmits cardholder data. The PCI Security Standards Council maintains it, and the current major version is the 4.x series. For small merchants, the workload depends mostly on the integration model.

If card data never touches your systems, your scope shrinks and the self assessment becomes simpler. By contrast, if your own form collects card numbers and sends them to an API, your responsibility grows considerably.

  • Never store raw card numbers in your own database.
  • Use the provider's tokens for repeat payments.
  • Limit third party scripts on the checkout page.
  • Protect your admin panel with two factor authentication.

Asking a provider for its PCI DSS attestation is also reasonable. A serious provider shares it without hesitation.

How do you test integration before going live?

Your ecommerce platform shapes the choice. On a hosted platform, check for an official plugin maintained by the provider. On custom software, the quality of the API documentation decides a lot. Weak documentation means more developer hours and more bugs.

Never launch without a sandbox. A good provider gives you test cards and simulated scenarios. Run through a successful payment, a declined card, a failed authentication and a timeout. Then test partial and full refunds.

Above all, test webhooks. If a customer closes the tab right after paying, the order must still be marked as paid. Without that, you collect money for orders that sit in "pending" in your system. In my own projects, this is the most common problem I find. Also confirm that a duplicated notification does not create a duplicated order.

How do refunds and chargebacks work?

Refunds are part of selling online. In the EU, for instance, consumers generally have a 14 day right of withdrawal for distance purchases, and sellers must refund within a set period. Your provider should let you issue full and partial refunds from the dashboard in seconds.

Next, ask about fees on refunds. With some providers, the original processing fee is not returned when you refund a sale. On high refund categories such as fashion, this detail adds up.

A chargeback is different: the cardholder disputes the payment with their bank. You then need evidence such as delivery confirmation, invoices and customer messages. So keep tracking numbers and communication records organised. Also check how many days the provider gives you to respond, and whether it charges a fee per dispute.

Which fraud prevention tools should a provider offer?

Stolen card orders cluster around products that are easy to resell. A good provider offers risk scoring, IP and device checks, velocity limits and block lists. Without them, you often notice the fraud only after the parcel has shipped.

However, rules that are too strict turn away honest buyers. Therefore, tune them to your own sales data. For example, you could route high value orders from unexpected countries to manual review. That way, you stop suspicious orders without delaying normal customers.

Also use a short pre-shipment checklist. Is the billing address far from the delivery address? Were there several attempts with different cards in a few minutes? Is the email address disposable? In my experience, these simple questions catch many bad orders early.

How does checkout design affect conversion?

The right payment gateway cannot rescue a badly designed checkout. Checkout is the most fragile stage of the funnel, because the customer has already decided to buy and can still walk away. So treat it as seriously as your ad budget.

  1. Cut form fields to the minimum.
  2. Show total, shipping and any fees at a glance.
  3. Open the numeric keyboard for card fields on mobile.
  4. Place error messages next to the field, in plain language.
  5. Add trust signals, but keep them understated.

Because mobile traffic is high for most stores, design checkout for phones first. I cover this approach in mobile first design. In addition, measure checkout as a separate step inside your conversion funnel. Then you can see whether the leak sits on the product page or at payment.

What should you look for when selling internationally?

Cross-border sales raise different questions. First, which local payment methods do your target markets prefer? In several European countries, bank based methods and wallets compete strongly with cards. A gateway that only takes cards may lose those buyers.

Second, look at currency. Can you show prices in the buyer's currency? Who converts, at which rate, and with what markup? This line looks small, yet it can eat your margin quietly.

Third, consider tax and consumer rules in each market. If you run a multilingual store, the payment page should match the language and currency of the rest of the site. Otherwise, the switch at the last step feels suspicious.

What matters for subscriptions and recurring payments?

Subscriptions need different features from one off sales. Asking customers to re-enter their card every month drives churn. Therefore, the provider must support tokenised cards and automatic billing.

Failed payments are a second issue. Cards expire, limits run out and banks decline. A good setup retries failed payments on a schedule and notifies the customer. Some networks also offer card updater services that refresh expired card details. Without these, you lose revenue without noticing.

Finally, make cancellation easy. A cancellation flow that fights the customer comes back as chargebacks and complaints. In short, keep customers who want to stay, and let go of those who want to leave without friction.

Which contract clauses deserve a careful read?

Payment contracts look long and generic. However, the real risks hide in short clauses. Before signing, read these topics carefully.

  • Termination terms and when held funds are paid out.
  • Reserves, their size and release conditions.
  • The provider's right to change fees and the notice period.
  • The list of prohibited products and services.
  • How fraud and chargeback losses are shared.
  • Minimum volume commitments and penalties.

The prohibited list matters most. If your sector is on it, your account can be frozen at any moment. So describe your business accurately during onboarding. An account opened on vague information may close at the first review.

What documents and website pages do providers usually ask for?

Requirements differ by provider and country, yet there is a common core. Expect company registration details, proof of identity for directors and owners, bank account details and your website address. Sole traders face a shorter list.

Your website is checked as well. Providers usually expect clear terms and conditions, a refund policy, a privacy notice and visible contact details. So prepare these pages before applying. Missing legal pages are one of the most common reasons for onboarding delays.

Also use an email address on your own domain. An application from a free mailbox can raise trust questions. I cover this in the guide on business email on a custom domain.

How should reconciliation and reporting work?

A payment gateway is also a data source for your bookkeeping. You should be able to export daily transactions, fee breakdowns and payout reports. Without them, matching a lump sum in your bank account to individual orders becomes painful.

For example, if 300 orders arrive as one payout line, finding the missing one can take hours. Therefore, check that your order number travels with each transaction. That makes automated reconciliation possible.

Next, ask for fees per transaction rather than netted totals. Seeing gross amount, fee and net payout on each line lets you verify that contract rates are applied. I recommend a quarterly check. If you find a wrong deduction, raise it with the provider in writing.

How do you build your own payment gateway scorecard?

The most reliable way to compare offers is a weighted scorecard. Give each criterion a weight that fits your business, then score every provider from 1 to 5. As a result, one attractive number cannot dominate the decision.

My starting criteria are total cost, cash flow, security and licensing, integration quality, support speed and reporting. These weights are a starting point based on field experience, not a guarantee. For instance, an inventory heavy store may weight payouts more heavily.

To test support, skip the sales rep and send a technical question to the support team. Note how fast and how well they answer. A team that is slow before you sign will not get faster when your payouts are stuck. Finally, connect the decision to your website conversion goals; the payment gateway serves those goals.

What are the most common payment gateway mistakes?

The mistakes I see over the years look very similar. Use this list as a self check.

  • Comparing only the headline rate instead of total cost.
  • Skipping the licence check and trusting a recommendation.
  • Not testing refunds and error cases in the sandbox.
  • Going live without webhooks.
  • Ignoring reserve and termination clauses.
  • Never testing checkout on a phone.

What these mistakes share is treating payments as a technical detail. Yet payment is the moment a customer confirms their trust with money. Get it right, and your SEO and ad spend keep their return. Get it wrong, and gains from work like site speed disappear at the last step.

In short, a payment gateway is not a set and forget choice. Review fees, refund rates and checkout drop off at least once a year. If you need a second opinion on the whole setup, my ecommerce consulting work usually starts exactly there.

Frequently Asked Questions

Do I need a registered business to get a payment gateway?
Usually yes, although requirements vary. Banks typically expect a registered company and some trading history. Many payment service providers also accept sole traders after identity checks. In every case, you need to be able to invoice and pay tax on the income. So settle your legal structure with an accountant first, then apply.
How much does a payment gateway cost?
There is no single honest number, because cost depends on volume, sector, card mix, currency and payout speed. Add the percentage fee, fixed fee per transaction, currency charges, refund and chargeback fees together. Then model two or three offers with your own monthly orders and average basket to see the real total.
How can I check if a payment provider is licensed?
Search the financial regulator's public register in your country. In the UK, that is the FCA register; in the EU, national supervisors publish registers under PSD2. Look up the legal entity named in your contract, not the brand, and check which payment services it is authorised to provide.
Is it risky to accept payments without 3D Secure?
Yes, it can be. Without authentication, fraud related chargebacks usually land on you as the merchant. With 3D Secure, liability generally shifts to the card issuer. In the European Economic Area, strong customer authentication is also a regulatory expectation for many payments. If conversion worries you, speed up the mobile flow instead of switching authentication off.
What is a rolling reserve?
A rolling reserve is a share of each payout that a provider holds back for a set period to cover possible chargebacks. The money is still yours, but you cannot use it until release. Ask for the reserve percentage, the holding period and the release terms in writing before you sign, because it directly affects cash flow.
Is it hard to switch payment gateways later?
Usually not, especially on platforms with official plugins. Still, plan the move. Test payments, refunds and webhooks in the sandbox first. Keep the old account open until pending refunds, payouts and disputes are settled. For subscriptions, discuss token migration with both providers early, so customers do not need to re-enter cards.
#payment gateway#online payments#merchant account#3D Secure#PCI DSS#ecommerce#checkout
Share:
Talha Aslan
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

No middlemen, no layers: you talk directly to the expert doing the work. The first consultation is free, I listen to your goal and come back with a clear roadmap.

WhatsApp Call Now