Last reviewed: August 4, 2026 · Written by: Liaqat Hussain · Approximately 22-minute read

Online payment processing can look almost instant. A customer enters a card, clicks Pay, and receives a confirmation within seconds. Behind that simple moment is a coordinated exchange among your website, a payment gateway, a processor, card networks, banks, fraud systems, and settlement services.

This guide explains how online payment processing works in plain language. It also shows merchants how to compare providers, estimate the real cost of accepting payments, prepare for underwriting, reduce preventable disputes, and choose a payment processor that fits the way the business actually operates.

The short answer: do not choose a processor from the advertised rate alone. Start with your sales channels, average ticket, transaction volume, countries, currencies, refund rate, delivery timing, subscription needs, integration requirements, and tolerance for reserves or holds. Then compare the complete operating cost and contract terms.

What You Will Learn

What Is Online Payment Processing?

Online payment processing is the system that lets a business accept and receive electronic payments through a website, app, invoice, payment link, or other remote checkout. It performs four essential jobs:

  1. Collect payment details securely.
  2. Ask the customer’s bank to approve or decline the purchase.
  3. Record and capture the approved transaction.
  4. Settle the proceeds to the merchant, minus applicable fees and adjustments.

“Payment gateway,” “payment processor,” “merchant account,” and “acquirer” are related terms, but they are not exact synonyms.

TermPlain-English meaningWhy the merchant should care
Payment gatewayThe secure connection that collects and transmits payment information.It affects checkout design, integrations, fraud tools, tokenization, and reliability.
Payment processorThe service that routes transaction messages and helps move funds through the payment system.It affects authorization performance, pricing, settlement, reporting, and support.
Merchant accountAn account relationship that enables a business to accept card payments before proceeds reach its operating bank account.Its underwriting, reserve, funding, and termination terms can directly affect cash flow.
AcquirerThe acquiring bank or institution supporting card acceptance for the merchant.It carries merchant-side risk and participates in settlement.
Payment service providerA provider that bundles several payment functions into one service.Bundling simplifies setup but may reduce control over pricing or underwriting.

Providers package these functions differently. Stripe and Square offer bundled payment platforms. Authorize.net can be used as a gateway with a separate merchant account or through an all-in-one arrangement. Traditional merchant service providers may combine an acquiring relationship, processor, gateway, equipment, and support under one agreement or several connected agreements.

Who Is Involved in an Online Card Payment?

A typical card transaction involves more parties than the customer and merchant:

How Online Payment Processing Works, Step by Step

1. Checkout
Customer submits payment.
2. Secure transmission
Gateway encrypts or tokenizes data.
3. Authorization
Request travels to the issuer.
4. Decision
Issuer approves or declines.
5. Capture
Merchant confirms the charge.
6. Settlement
Funds move through the system.
7. Payout
Net proceeds reach the merchant.

1. The customer starts checkout

The customer selects a product or service, enters delivery and billing information, and chooses a payment method. The checkout should clearly state the merchant name, price, currency, renewal terms when applicable, refund policy, and expected delivery.

2. Payment data is secured

The payment page transmits data through a secure connection. Modern hosted fields and checkout pages can keep raw card details away from the merchant’s server by sending them directly to the provider. The provider returns a token that the merchant can use without storing the actual card number.

3. An authorization request is routed

The gateway and processor send transaction details through the acquiring side and card network to the card issuer. The request may include the amount, currency, merchant category, billing data, authentication results, and fraud signals.

4. The issuer approves or declines

The issuer checks available credit or funds, account status, fraud indicators, card controls, and other rules. It returns an approval or decline response. An approval usually places a temporary hold on the customer’s available funds; it does not always mean the merchant has received the money.

5. The merchant captures the payment

Capture tells the system to complete an authorized charge. Some businesses authorize and capture immediately. Others—such as hotels, equipment rentals, or merchants shipping later—may authorize first and capture after confirming the final amount or fulfillment. Authorization windows vary, so merchants must capture before an authorization expires.

6. Transactions are cleared and settled

Captured transactions are submitted for clearing and settlement. Fees, refunds, disputes, reserves, or other adjustments may affect the amount credited to the merchant’s payment balance.

7. The provider sends a payout

The processor or payment platform transfers available proceeds to the merchant’s linked bank account according to the funding schedule. Settlement timing and payout frequency are different concepts: money can become available after a set period and then be paid daily, weekly, monthly, or manually.

Important: a checkout confirmation, successful authorization, available payment balance, and bank deposit are four different events. Merchants should reconcile all four.

Authorization, Capture, Settlement, and Payout

StageWhat happened?Can something still change?
AuthorizedIssuer approved and generally reserved the amount.Yes. The authorization can expire, be reversed, or be captured for an eligible amount.
CapturedMerchant requested completion of the charge.Yes. Refunds, disputes, and settlement adjustments can follow.
SettledFunds and transaction records moved through the payment system.Yes. Disputes or later adjustments remain possible.
Paid outAvailable net proceeds were sent to the merchant’s bank.Yes. Future refunds, disputes, or negative balances can affect later payouts.

How Online Payment Processing Fees Work

The advertised rate is only one component of payment cost. Depending on the arrangement, a merchant may encounter:

Flat-rate vs. interchange-plus pricing

ModelHow it worksPotential advantageWatch for
Flat rateA simple percentage plus fixed fee for a transaction type.Predictable and easy to understand.The blended price may cost more as volume grows or ticket size changes.
Interchange plusUnderlying interchange and assessments are passed through, with a stated provider markup.More transparent and may be economical for suitable established merchants.Statements are more complex; other fees and contract terms still matter.
Tiered or bundledTransactions are grouped into pricing categories.Can look simple at first.Definitions and downgrades can make comparisons difficult.

Calculate effective processing cost

Use this formula for a complete month:

Effective cost percentage = total payment-related cost ÷ gross processed sales × 100

Include transaction fees, monthly fees, gateway charges, cross-border charges, fraud tools, dispute fees, non-returned processing fees on refunds, and any other unavoidable payment costs. Calculate chargebacks and refunds separately as operating-risk indicators rather than hiding them inside one percentage.

Why average ticket size changes the answer

The fixed part of a fee matters more on small transactions. The illustration below applies a hypothetical 2.9% + $0.30 rate—not a provider quote—to show the effect.

Sale amountHypothetical feeEffective percentage
$10$0.595.90%
$50$1.753.50%
$100$3.203.20%
$500$14.802.96%

Illustrative effective fee by ticket size

$10 sale — 5.90%

$50 sale — 3.50%

$100 sale — 3.20%

$500 sale — 2.96%

Illustration only. Actual pricing varies by provider, payment method, card, country, contract, and merchant profile.

Why Payment Processors Review Merchants

A processor takes on financial and compliance exposure when it enables a merchant to accept payments. A customer can dispute a transaction after the merchant has already received a payout. Refunds, fraud, insolvency, delayed delivery, recurring billing, and regulatory issues can create additional exposure.

Underwriting commonly considers:

Payment facilitator vs. dedicated merchant-account arrangements

Many easy-to-start platforms use a payment-facilitator model that onboards merchants under a larger payment arrangement. This can reduce initial friction, but automated or ongoing reviews may still occur. A separately underwritten merchant account usually involves more information before activation and may provide more tailored terms. Neither model guarantees uninterrupted processing.

Reserves, payout delays, transaction limits, or additional verification are risk controls—not necessarily signs of wrongdoing. Merchants should learn when these controls may apply and how they can change.

How to Build a Safer Online Checkout

Outsourcing the payment form can reduce the amount of card data touching your systems, but it does not eliminate merchant responsibility. PCI DSS scope depends on the payment flow and integration. Confirm your responsibilities with your payment provider and qualified security adviser.

Practical security and fraud controls

Fraud prevention is a balance

A strict rule can block fraud but also reject good customers. Track approval rate, false declines, fraud losses, manual-review time, refunds, and disputes together. Improving only one metric can damage another.

Preventable Causes of Payment Disputes

Not every dispute is criminal fraud. Some arise because customers do not recognize the merchant name, misunderstand renewal terms, cannot reach support, or believe the product was not delivered as promised.

Choosing a processor for a complex online business?

Hopar Payments can help you organize the business model, payment flow, expected volume, delivery practices, and documentation before you approach a provider. Provider acceptance and terms remain subject to independent review.

Prepare your merchant inquiry

How to Choose a Payment Processor

Use the following sequence instead of starting with a provider’s homepage.

Step 1: Map how you sell

Step 2: Build a merchant profile

Record expected monthly volume, number of transactions, average and maximum ticket, refund rate, dispute rate, delivery window, countries, currencies, and seasonal peaks. Providers cannot be compared meaningfully without this baseline.

Step 3: List non-negotiable capabilities

Examples include WooCommerce support, recurring billing, Apple Pay and Google Pay, ACH, multicurrency display, multiple merchant accounts, marketplace splitting, saved cards, fraud rules, invoicing, virtual terminal, accounting integration, and data export.

Step 4: Compare total cost under your real transaction mix

Model at least three months: a normal month, a high-volume month, and a month with refunds or disputes. Include international and manually keyed transactions rather than assuming every sale receives the lowest advertised rate.

Step 5: Review risk and funding terms

Ask about reserves, payout timing, transaction caps, delayed fulfillment, prohibited and restricted businesses, notification requirements, negative balances, and how account termination works.

Step 6: Test the checkout and operations

A provider can have attractive pricing and still be a poor fit if the integration is unreliable, reconciliation is difficult, support is slow, or the checkout creates unnecessary customer friction.

Merchant reviewing payment processor features including ecommerce, recurring billing, security, payouts and support
Choose a provider by matching capabilities and risk terms to the merchant’s actual operating model.

Merchant processor scorecard

CategorySuggested weightQuestions to score
Business-model fit25%Is the product, fulfillment model, geography, and sales channel supported?
Total cost20%What would a real month cost under the full transaction mix?
Risk and funding20%Are reserve, payout, refund, and termination terms workable?
Integration and reliability15%Does it integrate cleanly and provide useful status, logs, and webhooks?
Security and fraud10%Are authentication, tokenization, controls, and reporting appropriate?
Support and portability10%Can the merchant reach support, export data, and change providers without unreasonable disruption?

Stripe vs. Square vs. Authorize.net

The following is a practical orientation, not a universal ranking. Public pricing shown is for U.S. accounts and was reviewed August 4, 2026. Eligibility, features, custom pricing, and contract terms vary. Always confirm the live provider page and your written agreement.

ConsiderationStripeSquareAuthorize.net
Typical orientationOnline-first, APIs, SaaS, subscriptions, platforms, international payment methods.In-person and omnichannel small businesses using an integrated POS ecosystem.Gateway flexibility, virtual terminal, recurring billing, fraud controls, and merchant-account choice.
Public starting point reviewedStandard U.S. online domestic cards: 2.9% + 30¢; additional charges can apply.Square Free U.S. online payments: 3.3% + 30¢; paid plans list different rates for some channels.All-in-One: $25/month plus 2.9% + 30¢; Gateway Only: $25/month plus 10¢ per transaction and a daily batch fee, excluding the separate merchant-account cost.
In-person strengthTerminal supports integrated in-person payment experiences.Broad POS hardware and business software ecosystem.Can connect through compatible solutions; it is not primarily a proprietary POS ecosystem.
Recurring billingStrong configurable billing and subscription tooling, with separate product pricing.Useful recurring invoices and subscriptions for supported use cases.Automated Recurring Billing is included in current plans.
Pricing structureStandard pay-as-you-go or eligible custom pricing.Plan- and channel-based published pricing, with custom pricing discussions for eligible volume.Gateway pricing plus either bundled or separate merchant-account economics.
Potential drawbackComplex product fees and engineering choices can require careful cost and implementation planning.Businesses focused only on ecommerce should compare online pricing and feature needs closely.Separate gateway and merchant-account relationships can add contracts, fees, and operational complexity.

Who may prefer Stripe?

An online-first business that values modern developer tools, broad payment-method support, subscriptions, marketplace capabilities, or international reach may place Stripe on its shortlist. Merchants should model add-on product charges, international cards, currency conversion, disputes, refunds, and payout options—not only the base card rate.

Who may prefer Square?

A retailer, restaurant, salon, mobile seller, or service business that wants POS hardware, in-person payments, ecommerce, inventory, invoicing, and business software in one ecosystem may prefer Square. Compare plan costs and channel-specific rates using the business’s actual mix.

Who may prefer Authorize.net?

An established merchant that wants to pair a familiar gateway with a separately selected merchant account, or needs built-in recurring billing, customer profiles, virtual terminal, and configurable fraud controls, may consider Authorize.net. Review both the gateway terms and the merchant-account agreement.

No provider is automatically the safest, cheapest, or most stable for every merchant. Account reviews, reserves, holds, disputes, technical incidents, and changing terms are possible under any model.

Payment Processor Evaluation Checklist

Business and eligibility

Pricing

Funding and reserves

Technology and operations

Documents to Prepare Before Applying

Exact requirements vary, but a prepared merchant commonly has:

Never submit altered or inconsistent documents. Use the same legal name and address formats across applications, bank records, tax records, and the website where applicable.

Common Merchant Mistakes

  1. Choosing only by the lowest advertised rate. The transaction mix, fixed fee, software charges, refunds, and risk terms may matter more.
  2. Applying before the website is complete. Missing prices, policies, contact information, or delivery details creates unnecessary uncertainty.
  3. Understating volume or ticket size. Sudden activity outside the stated profile can trigger review.
  4. Using a personal descriptor customers do not recognize. Descriptor confusion can create preventable disputes.
  5. Ignoring cancellation and renewal clarity. Subscription terms must be prominent and understandable.
  6. Assuming hosted checkout removes every compliance obligation. Merchants still control the surrounding website, users, policies, and integrations.
  7. Launching without reconciliation. A sales total is not a payout report.
  8. Depending on one provider with no continuity plan. Document exports, customer communications, and an incident process reduce disruption.

Frequently Asked Questions

What is the difference between a payment gateway and a payment processor?

A gateway securely collects and transmits the payment request. A processor routes transaction messages and supports authorization, clearing, and settlement. Many modern providers bundle both, which is why the terms are often used together.

Do I need a merchant account to accept online payments?

You need a payment arrangement that supports merchant acceptance, but it may not appear as a separately branded account. Payment facilitators can provide access under a master arrangement, while traditional setups may include a dedicated merchant account.

How long does an online card payment take?

Authorization often returns within seconds. Settlement and payout usually take longer and vary by provider, country, merchant risk, payment method, bank, and payout schedule. Initial payouts may take longer than later payouts.

Why was a legitimate card declined?

The issuer or risk system may decline because of insufficient funds, incorrect data, authentication failure, card controls, fraud indicators, geographic mismatch, velocity, or other rules. A generic decline message may not reveal the exact reason.

What is a rolling reserve?

A rolling reserve is a percentage of processed funds held for a defined period to cover potential refunds, disputes, or other liabilities. The percentage, duration, and release conditions should be documented.

Is the cheapest payment processor always best?

No. A lower rate can be outweighed by unsuitable risk terms, weak support, missing features, integration costs, lower approval rates, reconciliation work, or delayed funding.

Can I use more than one processor?

Some businesses use multiple providers for different countries, brands, channels, or continuity needs. This adds operational, technical, compliance, and reconciliation complexity and should not be used to hide activity or evade provider rules.

Does PCI compliance prevent all card fraud?

No. PCI DSS focuses on protecting account data. Fraud prevention also requires authentication, risk monitoring, access control, fulfillment evidence, customer communication, and ongoing operational discipline.

Final Decision Framework

The right payment processor is the one that can support your legitimate business model under terms you understand and can operate successfully. A responsible decision follows this order:

  1. Document the business and payment flow.
  2. Confirm provider eligibility.
  3. Identify required payment methods and integrations.
  4. Model the complete monthly cost.
  5. Review underwriting, reserve, payout, and termination terms.
  6. Test checkout, reporting, reconciliation, refunds, and support.
  7. Launch with security, dispute prevention, and continuity procedures.

If a proposal is unclear, ask for written explanations before signing. If a provider cannot support the business model, choose a provider that can; do not disguise the business or route activity in a way that violates an agreement.

Need help organizing your merchant profile?

Hopar Payments provides educational application guidance for online businesses. We can help you clarify the payment flow and prepare the information providers commonly request. We are not a bank or payment processor, and approval, pricing, reserves, and timing are determined independently by the provider.

Contact Hopar Payments

Authoritative Sources and Further Reading


Editorial disclaimer: This guide provides general educational information and is not legal, tax, security, financial, or underwriting advice. Payment-provider pricing, availability, requirements, restricted-business rules, and contract terms change. Confirm current information directly with each provider and review the written agreement that applies to your business.

Leave a Reply

Your email address will not be published. Required fields are marked *