Taking money online is simpler than it was and the vocabulary is still confusing. Here is what the parts do, what they cost, and what you are responsible for.
The three roles
The gateway collects the card details securely and passes them on. It is the form the customer types into.
The processor and card networks route the request to the customer's bank and get an answer.
The merchant facility is where the money lands before it reaches your business account.
Traditionally these were three separate arrangements. Modern providers combine them into one account you can open in a day, which is why most small businesses no longer think about the distinction. Larger merchants sometimes still separate them to negotiate rates independently.
What it actually costs
Headline pricing is usually a percentage plus a small fixed fee — often around 1.4 per cent plus twenty pence for a UK consumer card.
The variations matter:
- Business and corporate cards cost more, sometimes considerably. If you sell to businesses, your blended rate will be above the headline.
- Cards issued outside the UK attract higher fees, plus currency conversion if applicable.
- Refunds may not return the original fee. Check, because for businesses with high return rates this is a real cost.
- Chargebacks carry a fee regardless of whether you win the dispute.
- Payouts may be daily, weekly or on a delay. A seven-day hold on funds is a cash flow consideration rather than a fee, and it matters.
Compare providers on your actual mix rather than the advertised rate. A business selling mainly to other businesses internationally will pay a very different effective rate to a UK consumer retailer.
Strong customer authentication
Most online card payments in the UK must be verified with two independent factors — typically something the customer has, such as their phone, plus something they know or are, such as a passcode or fingerprint.
In practice the customer is redirected to their bank's app or a verification screen mid-checkout.
Two consequences for you:
It must be implemented properly. A badly handled authentication step is a checkout that fails silently. Test it with real cards from several banks, because the experience differs.
Exemptions exist. Low-value transactions, recurring payments after the first, and trusted merchant arrangements can be exempted. Your provider handles most of this, but it is worth knowing why some payments prompt and others do not.
Your security obligations
Card data handling is governed by the PCI standard, and the practical question is whether card details ever touch your systems.
If you use a provider's hosted payment page or their embedded fields, the details go straight to them. You never store or transmit a card number, which places you in the lightest compliance category — a self-assessment questionnaire rather than an audit.
If you build your own card form and post it through your server, you take on a far heavier obligation. There is essentially no good reason for a small business to do this.
The simplest security decision in ecommerce is ensuring card numbers never reach your server. Everything about your compliance position follows from it.
Beyond cards
Digital wallets. Apple Pay and Google Pay convert noticeably better on phones because they remove typing entirely and satisfy authentication with a fingerprint. If you sell to consumers, enable them.
Direct debit. For recurring payments, considerably cheaper than cards and it does not expire. Slower to set up and slower to collect, so it suits subscriptions rather than one-off sales.
Bank transfer at checkout. Open banking payments are growing, with low fees and no chargeback risk. Adoption among consumers is still building.
Buy now, pay later. Increases average order value for consumer retail and costs several per cent. Worth testing rather than assuming.
Invoicing on account. For trade customers, often what they actually want — covered in selling B2B online.
Reducing chargebacks and fraud
Most disputes are not fraud. They are customers who did not recognise a statement entry, or did not receive what they expected.
Prevention is straightforward: use a recognisable trading name on statements, send a clear order confirmation, provide tracking, state delivery timescales honestly, and make your returns process easy. A customer who can get a refund from you will not go to their bank.
For fraud, use your provider's screening, be cautious with mismatched billing and delivery addresses on high-value orders, and remember that a blocked genuine order costs you a customer as surely as a fraudulent one costs you stock.
Choosing a provider
- Model your actual card mix, including business and international, and compare effective rates.
- Check payout timing and whether funds are held.
- Confirm it integrates with your shop platform and your accounting system — see connecting accounting to operations.
- Test the authentication experience on a phone before committing.
- Read the terms on account freezes and reserves. Providers can hold funds, and businesses with unusual patterns are sometimes caught by automated risk rules.
- Check support: if payments stop on a Saturday, who answers?
Our ecommerce team sets up payments for UK businesses and connects them through to accounting. Start a conversation.








