Last reviewed: August 4, 2026 · Written by: Liaqat Hussain · Approximately 22-minute read
Online payment processing can look almost instant. A customer enters a card, clicks Pay, and receives a confirmation within seconds. Behind that simple moment is a coordinated exchange among your website, a payment gateway, a processor, card networks, banks, fraud systems, and settlement services.
This guide explains how online payment processing works in plain language. It also shows merchants how to compare providers, estimate the real cost of accepting payments, prepare for underwriting, reduce preventable disputes, and choose a payment processor that fits the way the business actually operates.
The short answer: do not choose a processor from the advertised rate alone. Start with your sales channels, average ticket, transaction volume, countries, currencies, refund rate, delivery timing, subscription needs, integration requirements, and tolerance for reserves or holds. Then compare the complete operating cost and contract terms.
What You Will Learn
- What payment processing means
- Who participates in a card transaction
- How a payment moves from checkout to settlement
- How processing fees work
- Why processors review merchants and sometimes hold funds
- How to build a safer checkout
- How to choose a payment processor
- How Stripe, Square, and Authorize.net differ
- What to ask before signing
What Is Online Payment Processing?
Online payment processing is the system that lets a business accept and receive electronic payments through a website, app, invoice, payment link, or other remote checkout. It performs four essential jobs:
- Collect payment details securely.
- Ask the customer’s bank to approve or decline the purchase.
- Record and capture the approved transaction.
- Settle the proceeds to the merchant, minus applicable fees and adjustments.
“Payment gateway,” “payment processor,” “merchant account,” and “acquirer” are related terms, but they are not exact synonyms.
| Term | Plain-English meaning | Why the merchant should care |
|---|---|---|
| Payment gateway | The secure connection that collects and transmits payment information. | It affects checkout design, integrations, fraud tools, tokenization, and reliability. |
| Payment processor | The service that routes transaction messages and helps move funds through the payment system. | It affects authorization performance, pricing, settlement, reporting, and support. |
| Merchant account | An account relationship that enables a business to accept card payments before proceeds reach its operating bank account. | Its underwriting, reserve, funding, and termination terms can directly affect cash flow. |
| Acquirer | The acquiring bank or institution supporting card acceptance for the merchant. | It carries merchant-side risk and participates in settlement. |
| Payment service provider | A provider that bundles several payment functions into one service. | Bundling simplifies setup but may reduce control over pricing or underwriting. |
Providers package these functions differently. Stripe and Square offer bundled payment platforms. Authorize.net can be used as a gateway with a separate merchant account or through an all-in-one arrangement. Traditional merchant service providers may combine an acquiring relationship, processor, gateway, equipment, and support under one agreement or several connected agreements.
Who Is Involved in an Online Card Payment?
A typical card transaction involves more parties than the customer and merchant:
- Customer or cardholder: the person making the purchase.
- Merchant: the business selling the product or service.
- Checkout and gateway: the technology collecting and transmitting the payment request.
- Processor: the service routing authorization, capture, and settlement messages.
- Acquirer: the merchant-side financial institution.
- Card network: a network such as Visa, Mastercard, American Express, or Discover that establishes operating rules and routes messages.
- Issuer: the bank or institution that issued the customer’s card and decides whether to approve the transaction.
How Online Payment Processing Works, Step by Step
Customer submits payment.
Gateway encrypts or tokenizes data.
Request travels to the issuer.
Issuer approves or declines.
Merchant confirms the charge.
Funds move through the system.
Net proceeds reach the merchant.
1. The customer starts checkout
The customer selects a product or service, enters delivery and billing information, and chooses a payment method. The checkout should clearly state the merchant name, price, currency, renewal terms when applicable, refund policy, and expected delivery.
2. Payment data is secured
The payment page transmits data through a secure connection. Modern hosted fields and checkout pages can keep raw card details away from the merchant’s server by sending them directly to the provider. The provider returns a token that the merchant can use without storing the actual card number.
3. An authorization request is routed
The gateway and processor send transaction details through the acquiring side and card network to the card issuer. The request may include the amount, currency, merchant category, billing data, authentication results, and fraud signals.
4. The issuer approves or declines
The issuer checks available credit or funds, account status, fraud indicators, card controls, and other rules. It returns an approval or decline response. An approval usually places a temporary hold on the customer’s available funds; it does not always mean the merchant has received the money.
5. The merchant captures the payment
Capture tells the system to complete an authorized charge. Some businesses authorize and capture immediately. Others—such as hotels, equipment rentals, or merchants shipping later—may authorize first and capture after confirming the final amount or fulfillment. Authorization windows vary, so merchants must capture before an authorization expires.
6. Transactions are cleared and settled
Captured transactions are submitted for clearing and settlement. Fees, refunds, disputes, reserves, or other adjustments may affect the amount credited to the merchant’s payment balance.
7. The provider sends a payout
The processor or payment platform transfers available proceeds to the merchant’s linked bank account according to the funding schedule. Settlement timing and payout frequency are different concepts: money can become available after a set period and then be paid daily, weekly, monthly, or manually.
Important: a checkout confirmation, successful authorization, available payment balance, and bank deposit are four different events. Merchants should reconcile all four.
Authorization, Capture, Settlement, and Payout
| Stage | What happened? | Can something still change? |
|---|---|---|
| Authorized | Issuer approved and generally reserved the amount. | Yes. The authorization can expire, be reversed, or be captured for an eligible amount. |
| Captured | Merchant requested completion of the charge. | Yes. Refunds, disputes, and settlement adjustments can follow. |
| Settled | Funds and transaction records moved through the payment system. | Yes. Disputes or later adjustments remain possible. |
| Paid out | Available net proceeds were sent to the merchant’s bank. | Yes. Future refunds, disputes, or negative balances can affect later payouts. |
How Online Payment Processing Fees Work
The advertised rate is only one component of payment cost. Depending on the arrangement, a merchant may encounter:
- Interchange: a fee associated with the card and transaction, generally paid through the acquiring side to the issuer.
- Network assessments: fees established by payment networks.
- Processor or provider markup: the provider’s charge for processing and services.
- Gateway or platform fees: monthly or per-transaction technology charges.
- Card-not-present or manually keyed pricing: often higher because remote transactions carry different risk.
- Cross-border and currency-conversion charges.
- Dispute, retrieval, refund, failed-payment, or account-updater charges.
- Optional software fees: subscriptions, invoicing, fraud tools, tax tools, terminals, reporting, or support.
- Reserve or delayed-funding impact: not always a fee, but a meaningful cash-flow cost.
Flat-rate vs. interchange-plus pricing
| Model | How it works | Potential advantage | Watch for |
|---|---|---|---|
| Flat rate | A simple percentage plus fixed fee for a transaction type. | Predictable and easy to understand. | The blended price may cost more as volume grows or ticket size changes. |
| Interchange plus | Underlying interchange and assessments are passed through, with a stated provider markup. | More transparent and may be economical for suitable established merchants. | Statements are more complex; other fees and contract terms still matter. |
| Tiered or bundled | Transactions are grouped into pricing categories. | Can look simple at first. | Definitions and downgrades can make comparisons difficult. |
Calculate effective processing cost
Use this formula for a complete month:
Effective cost percentage = total payment-related cost ÷ gross processed sales × 100
Include transaction fees, monthly fees, gateway charges, cross-border charges, fraud tools, dispute fees, non-returned processing fees on refunds, and any other unavoidable payment costs. Calculate chargebacks and refunds separately as operating-risk indicators rather than hiding them inside one percentage.
Why average ticket size changes the answer
The fixed part of a fee matters more on small transactions. The illustration below applies a hypothetical 2.9% + $0.30 rate—not a provider quote—to show the effect.
| Sale amount | Hypothetical fee | Effective percentage |
|---|---|---|
| $10 | $0.59 | 5.90% |
| $50 | $1.75 | 3.50% |
| $100 | $3.20 | 3.20% |
| $500 | $14.80 | 2.96% |
Illustrative effective fee by ticket size
Illustration only. Actual pricing varies by provider, payment method, card, country, contract, and merchant profile.
Why Payment Processors Review Merchants
A processor takes on financial and compliance exposure when it enables a merchant to accept payments. A customer can dispute a transaction after the merchant has already received a payout. Refunds, fraud, insolvency, delayed delivery, recurring billing, and regulatory issues can create additional exposure.
Underwriting commonly considers:
- Products and services sold;
- Countries served and currencies accepted;
- Average ticket, maximum ticket, and expected monthly volume;
- Delivery timing and whether goods are sold before fulfillment;
- Refund, cancellation, and subscription practices;
- Processing history, disputes, refunds, and fraud;
- Ownership and business registration;
- Website clarity and policy pages;
- Financial condition and ability to cover future liabilities; and
- Whether the business model is supported by the provider’s policies.
Payment facilitator vs. dedicated merchant-account arrangements
Many easy-to-start platforms use a payment-facilitator model that onboards merchants under a larger payment arrangement. This can reduce initial friction, but automated or ongoing reviews may still occur. A separately underwritten merchant account usually involves more information before activation and may provide more tailored terms. Neither model guarantees uninterrupted processing.
Reserves, payout delays, transaction limits, or additional verification are risk controls—not necessarily signs of wrongdoing. Merchants should learn when these controls may apply and how they can change.
How to Build a Safer Online Checkout
Outsourcing the payment form can reduce the amount of card data touching your systems, but it does not eliminate merchant responsibility. PCI DSS scope depends on the payment flow and integration. Confirm your responsibilities with your payment provider and qualified security adviser.
Practical security and fraud controls
- Use HTTPS across the entire website.
- Prefer hosted checkout or secure provider-hosted payment fields when appropriate.
- Never store card security codes.
- Use tokenization for saved payment methods.
- Protect administrator accounts with multifactor authentication.
- Keep WordPress, plugins, themes, ecommerce software, and integrations updated.
- Limit employee permissions and review access regularly.
- Use address, card-security-code, device, velocity, authentication, and risk rules thoughtfully.
- Make the billing descriptor recognizable.
- Send immediate receipts and clear delivery updates.
- Maintain evidence of customer authorization, fulfillment, and communication.
- Test backups and create a payment-incident response plan.
Fraud prevention is a balance
A strict rule can block fraud but also reject good customers. Track approval rate, false declines, fraud losses, manual-review time, refunds, and disputes together. Improving only one metric can damage another.
Preventable Causes of Payment Disputes
Not every dispute is criminal fraud. Some arise because customers do not recognize the merchant name, misunderstand renewal terms, cannot reach support, or believe the product was not delivered as promised.
- Use a recognizable statement descriptor.
- Show the total price and currency before payment.
- Explain trial, renewal, cancellation, and refund terms next to the purchase action.
- Send order confirmations and renewal reminders when appropriate.
- Use delivery tracking and retain proof of service.
- Make customer support easy to find.
- Resolve legitimate complaints before they become disputes.
- Do not make cancellation materially harder than enrollment.
Choosing a processor for a complex online business?
Hopar Payments can help you organize the business model, payment flow, expected volume, delivery practices, and documentation before you approach a provider. Provider acceptance and terms remain subject to independent review.
How to Choose a Payment Processor
Use the following sequence instead of starting with a provider’s homepage.
Step 1: Map how you sell
- Online checkout, invoices, payment links, subscriptions, marketplaces, or in-person POS?
- Physical goods, digital goods, services, bookings, deposits, or delayed fulfillment?
- Domestic customers only or international buyers?
- One-time transactions, card on file, installments, or usage-based billing?
Step 2: Build a merchant profile
Record expected monthly volume, number of transactions, average and maximum ticket, refund rate, dispute rate, delivery window, countries, currencies, and seasonal peaks. Providers cannot be compared meaningfully without this baseline.
Step 3: List non-negotiable capabilities
Examples include WooCommerce support, recurring billing, Apple Pay and Google Pay, ACH, multicurrency display, multiple merchant accounts, marketplace splitting, saved cards, fraud rules, invoicing, virtual terminal, accounting integration, and data export.
Step 4: Compare total cost under your real transaction mix
Model at least three months: a normal month, a high-volume month, and a month with refunds or disputes. Include international and manually keyed transactions rather than assuming every sale receives the lowest advertised rate.
Step 5: Review risk and funding terms
Ask about reserves, payout timing, transaction caps, delayed fulfillment, prohibited and restricted businesses, notification requirements, negative balances, and how account termination works.
Step 6: Test the checkout and operations
A provider can have attractive pricing and still be a poor fit if the integration is unreliable, reconciliation is difficult, support is slow, or the checkout creates unnecessary customer friction.

Merchant processor scorecard
| Category | Suggested weight | Questions to score |
|---|---|---|
| Business-model fit | 25% | Is the product, fulfillment model, geography, and sales channel supported? |
| Total cost | 20% | What would a real month cost under the full transaction mix? |
| Risk and funding | 20% | Are reserve, payout, refund, and termination terms workable? |
| Integration and reliability | 15% | Does it integrate cleanly and provide useful status, logs, and webhooks? |
| Security and fraud | 10% | Are authentication, tokenization, controls, and reporting appropriate? |
| Support and portability | 10% | Can the merchant reach support, export data, and change providers without unreasonable disruption? |
Stripe vs. Square vs. Authorize.net
The following is a practical orientation, not a universal ranking. Public pricing shown is for U.S. accounts and was reviewed August 4, 2026. Eligibility, features, custom pricing, and contract terms vary. Always confirm the live provider page and your written agreement.
| Consideration | Stripe | Square | Authorize.net |
|---|---|---|---|
| Typical orientation | Online-first, APIs, SaaS, subscriptions, platforms, international payment methods. | In-person and omnichannel small businesses using an integrated POS ecosystem. | Gateway flexibility, virtual terminal, recurring billing, fraud controls, and merchant-account choice. |
| Public starting point reviewed | Standard U.S. online domestic cards: 2.9% + 30¢; additional charges can apply. | Square Free U.S. online payments: 3.3% + 30¢; paid plans list different rates for some channels. | All-in-One: $25/month plus 2.9% + 30¢; Gateway Only: $25/month plus 10¢ per transaction and a daily batch fee, excluding the separate merchant-account cost. |
| In-person strength | Terminal supports integrated in-person payment experiences. | Broad POS hardware and business software ecosystem. | Can connect through compatible solutions; it is not primarily a proprietary POS ecosystem. |
| Recurring billing | Strong configurable billing and subscription tooling, with separate product pricing. | Useful recurring invoices and subscriptions for supported use cases. | Automated Recurring Billing is included in current plans. |
| Pricing structure | Standard pay-as-you-go or eligible custom pricing. | Plan- and channel-based published pricing, with custom pricing discussions for eligible volume. | Gateway pricing plus either bundled or separate merchant-account economics. |
| Potential drawback | Complex product fees and engineering choices can require careful cost and implementation planning. | Businesses focused only on ecommerce should compare online pricing and feature needs closely. | Separate gateway and merchant-account relationships can add contracts, fees, and operational complexity. |
Who may prefer Stripe?
An online-first business that values modern developer tools, broad payment-method support, subscriptions, marketplace capabilities, or international reach may place Stripe on its shortlist. Merchants should model add-on product charges, international cards, currency conversion, disputes, refunds, and payout options—not only the base card rate.
Who may prefer Square?
A retailer, restaurant, salon, mobile seller, or service business that wants POS hardware, in-person payments, ecommerce, inventory, invoicing, and business software in one ecosystem may prefer Square. Compare plan costs and channel-specific rates using the business’s actual mix.
Who may prefer Authorize.net?
An established merchant that wants to pair a familiar gateway with a separately selected merchant account, or needs built-in recurring billing, customer profiles, virtual terminal, and configurable fraud controls, may consider Authorize.net. Review both the gateway terms and the merchant-account agreement.
No provider is automatically the safest, cheapest, or most stable for every merchant. Account reviews, reserves, holds, disputes, technical incidents, and changing terms are possible under any model.
Payment Processor Evaluation Checklist
Business and eligibility
- Does the provider support our industry, products, fulfillment model, and countries?
- Which activities are prohibited or restricted?
- What documentation is required initially and during later reviews?
- Must we notify the provider before changing products, ownership, volume, or delivery timing?
Pricing
- What is charged for online cards, wallets, ACH, card on file, manual entry, international cards, and currency conversion?
- Are there gateway, statement, PCI, minimum, batch, account-updater, refund, dispute, or early-termination charges?
- Are processing fees returned after a refund?
- Can pricing change, and how much notice is provided?
Funding and reserves
- What is the initial payout timing and normal settlement timing?
- Can a reserve be imposed? How is it calculated, reviewed, and released?
- Are there transaction, daily, monthly, or ticket-size limits?
- What happens to funds if the account is suspended or terminated?
Technology and operations
- Does the provider have a maintained integration for our ecommerce platform?
- Are hosted checkout, tokenization, saved cards, subscriptions, webhooks, and testing tools available?
- Can finance staff reconcile gross sales, fees, refunds, disputes, reserves, and net payouts?
- Can customer and payment-token data be migrated if we change providers?
- What support channels and hours apply to our plan?
Documents to Prepare Before Applying
Exact requirements vary, but a prepared merchant commonly has:
- Legal business name, entity type, registration documents, EIN or applicable tax identification;
- Owner and control-person identification;
- Business address and bank-account verification;
- Website with clear product or service descriptions and prices;
- Privacy, refund, cancellation, shipping or delivery, and terms pages;
- Customer-support contact information;
- Expected volume, average ticket, maximum ticket, and delivery window;
- Recent processing statements, bank statements, or financial records when requested;
- Supplier, fulfillment, or licensing documentation relevant to the model; and
- A plain-language explanation of the complete payment and delivery flow.
Never submit altered or inconsistent documents. Use the same legal name and address formats across applications, bank records, tax records, and the website where applicable.
Common Merchant Mistakes
- Choosing only by the lowest advertised rate. The transaction mix, fixed fee, software charges, refunds, and risk terms may matter more.
- Applying before the website is complete. Missing prices, policies, contact information, or delivery details creates unnecessary uncertainty.
- Understating volume or ticket size. Sudden activity outside the stated profile can trigger review.
- Using a personal descriptor customers do not recognize. Descriptor confusion can create preventable disputes.
- Ignoring cancellation and renewal clarity. Subscription terms must be prominent and understandable.
- Assuming hosted checkout removes every compliance obligation. Merchants still control the surrounding website, users, policies, and integrations.
- Launching without reconciliation. A sales total is not a payout report.
- Depending on one provider with no continuity plan. Document exports, customer communications, and an incident process reduce disruption.
Frequently Asked Questions
What is the difference between a payment gateway and a payment processor?
A gateway securely collects and transmits the payment request. A processor routes transaction messages and supports authorization, clearing, and settlement. Many modern providers bundle both, which is why the terms are often used together.
Do I need a merchant account to accept online payments?
You need a payment arrangement that supports merchant acceptance, but it may not appear as a separately branded account. Payment facilitators can provide access under a master arrangement, while traditional setups may include a dedicated merchant account.
How long does an online card payment take?
Authorization often returns within seconds. Settlement and payout usually take longer and vary by provider, country, merchant risk, payment method, bank, and payout schedule. Initial payouts may take longer than later payouts.
Why was a legitimate card declined?
The issuer or risk system may decline because of insufficient funds, incorrect data, authentication failure, card controls, fraud indicators, geographic mismatch, velocity, or other rules. A generic decline message may not reveal the exact reason.
What is a rolling reserve?
A rolling reserve is a percentage of processed funds held for a defined period to cover potential refunds, disputes, or other liabilities. The percentage, duration, and release conditions should be documented.
Is the cheapest payment processor always best?
No. A lower rate can be outweighed by unsuitable risk terms, weak support, missing features, integration costs, lower approval rates, reconciliation work, or delayed funding.
Can I use more than one processor?
Some businesses use multiple providers for different countries, brands, channels, or continuity needs. This adds operational, technical, compliance, and reconciliation complexity and should not be used to hide activity or evade provider rules.
Does PCI compliance prevent all card fraud?
No. PCI DSS focuses on protecting account data. Fraud prevention also requires authentication, risk monitoring, access control, fulfillment evidence, customer communication, and ongoing operational discipline.
Final Decision Framework
The right payment processor is the one that can support your legitimate business model under terms you understand and can operate successfully. A responsible decision follows this order:
- Document the business and payment flow.
- Confirm provider eligibility.
- Identify required payment methods and integrations.
- Model the complete monthly cost.
- Review underwriting, reserve, payout, and termination terms.
- Test checkout, reporting, reconciliation, refunds, and support.
- Launch with security, dispute prevention, and continuity procedures.
If a proposal is unclear, ask for written explanations before signing. If a provider cannot support the business model, choose a provider that can; do not disguise the business or route activity in a way that violates an agreement.
Need help organizing your merchant profile?
Hopar Payments provides educational application guidance for online businesses. We can help you clarify the payment flow and prepare the information providers commonly request. We are not a bank or payment processor, and approval, pricing, reserves, and timing are determined independently by the provider.
Authoritative Sources and Further Reading
- Authorize.net: How payments work
- PCI Security Standards Council: Guide to Safe Payments for Small Merchants
- Stripe: U.S. pricing and product fees
- Stripe documentation: Payout schedules and settlement timing
- Square: U.S. payment processing fees
- Square: Payment dispute process
- Authorize.net: Gateway and All-in-One pricing
Editorial disclaimer: This guide provides general educational information and is not legal, tax, security, financial, or underwriting advice. Payment-provider pricing, availability, requirements, restricted-business rules, and contract terms change. Confirm current information directly with each provider and review the written agreement that applies to your business.