What a payment gateway actually does, and who provides them
A payment gateway is the software that captures card details or bank account information from your customer, encrypts it, and sends it to the processor and your bank. You do not build one yourself. You choose one from a company that already runs the infrastructure — companies like Stripe, Square, PayPal, Authorize.net, or Adyen. They handle the security compliance, the connection to card networks, and the settlement of funds into your account.
Getting a payment gateway means signing an agreement with one of these providers and integrating their code into your website, app, or point-of-sale system. The provider charges you a fee per transaction (usually 2.2% to 3.5% plus a flat fee per transaction, though this varies by provider and by what you sell). In return, you get the ability to accept payments without building the encryption and bank connections yourself.
The process is straightforward: you choose a provider based on your business type and sales volume, you submit information about your business, the provider reviews it, and if approved, you get access to their integration tools and documentation. The whole approval can take anywhere from a few hours to a few business days depending on the provider and how much information they need to verify.
Key Takeaways
- Payment gateways are provided by third-party companies like Stripe, Square, and PayPal — you choose one and integrate it into your site or system.
- You will need your business registration documents, tax ID, and bank account details to set up an account with most providers.
- Approval timelines range from same-day to several business days, depending on the provider and the information you submit.
- Fees are typically 2.2% to 3.5% of each transaction plus a per-transaction flat fee, though some providers charge monthly minimums or different rates for different payment types.
- The provider handles security compliance and the connection to banks and card networks — you only need to integrate their code into your checkout.
Choosing a provider based on what you sell and how you sell it
Different providers are built for different business types. Stripe and Adyen are strong for online stores and SaaS businesses. Square is built for in-person retail and restaurants. PayPal works for almost anything but is most common for small sellers and marketplaces. Authorize.net is older and common in enterprise environments. The choice matters because each provider has different fee structures, different integration difficulty, and different features.
If you run an online store, look at Stripe, Shopify Payments (if you use Shopify), or WooCommerce payment processors. If you have a physical location, Square or Toast (for restaurants) are the standard. If you are a marketplace or accept payments from other sellers, PayPal or Stripe Connect are common. If you are a large enterprise, Adyen or Authorize.net are typical.
The provider you choose also determines what payment methods you can accept. Most major providers accept credit cards, debit cards, and digital wallets like Apple Pay and Google Pay. Some also accept bank transfers, buy-now-pay-later services, or regional payment methods. Check the provider's documentation to see what your customers can use.
What information you need to provide during setup
Every provider requires basic business information before they will approve your account. You will need your legal business name, the address where you operate, your tax ID (EIN in the US), and the bank account where you want deposits to land. Some providers also ask for your website URL, a description of what you sell, and your expected monthly transaction volume.
If your business is new or high-risk (like e-cigarettes, supplements, or gambling), the provider may ask for additional documents: a copy of your business license, proof of address, or documentation of what you actually sell. This is part of their compliance with banking regulations and anti-money-laundering rules. The more information you provide upfront, the faster approval usually goes.
You will also need to agree to the provider's terms of service, which spell out their fees, their liability limits, and the circumstances under which they can freeze your account. Read the fee section carefully — some providers charge different rates for different card types, and some charge monthly minimums or setup fees.
The approval process and what happens if you are declined
After you submit your information, the provider's system checks it against their risk rules. Most approvals happen automatically within hours or a day. The provider sends you an email with your account credentials and a link to their integration documentation. You can then start building the connection between your checkout and their gateway.
If the provider declines you, they will usually tell you why: your business type is outside their policy, your expected volume is too high or too low for their system, or they could not verify your information. Some providers allow you to appeal a decline by submitting additional documentation. Others do not. If you are declined, you can explore with a different provider — different companies have different risk appetites, and what one declines another may approve.
A few providers (Stripe and Square among them) offer a way to start accepting payments before full approval: you can use their system in a limited mode while they verify your information, then unlock full features once approved. This is useful if you need to start selling when ready.
Integrating the gateway into your website or app
Once approved, you get access to the provider's integration tools. For a website, this usually means adding code to your checkout page or installing a plugin if you use a platform like Shopify or WooCommerce. For a mobile app, you use their SDK (software development kit) to add payment functionality. For a physical store, you use their point-of-sale system or a compatible terminal.
The provider gives you two sets of credentials: a public key (safe to put in your code) and a secret key (keep this private — never put it in client-side code). Your checkout code uses the public key to send the customer's payment information securely to the provider. Your server uses the secret key to confirm the payment and record it in your system.
Most providers have sample code and step-by-step guides for common platforms. If you use Shopify, WooCommerce, or another hosted platform, the integration is usually a matter of entering your credentials and turning the gateway on. If you are building a custom website or app, you will need a developer to write the integration code, or you can use a pre-built library the provider publishes.
Understanding fees and how money reaches your bank account
Payment gateway fees come in two forms: per-transaction fees and account fees. Per-transaction fees are the most common — typically 2.2% to 3.5% of the transaction amount plus $0.30 per transaction. Some providers charge different rates for different card types (credit cards cost more than debit cards). A few charge monthly minimums or monthly account fees on top of per-transaction charges.
Money from a sale does not reach your bank account when ready. The provider holds the funds for a settlement period, usually one to three business days. During that time, they verify the transaction, check for fraud, and confirm the customer's bank or card issuer approved it. Once the settlement period ends, they deposit the money (minus their fees) into your bank account. You can see the pending transactions in your provider's dashboard before they settle.
Some providers charge additional fees for refunds, chargebacks, or transfers to accounts outside the US. Read the fee schedule carefully — these can add up if you have a high refund rate or operate internationally. Most providers publish their full fee schedule on their pricing page.
Security and compliance requirements
The provider handles most of the security work, but you have responsibilities too. You must never store a customer's full card number, expiration date, or security code on your own servers. The provider's code captures this information and sends it directly to their find servers. Your system only stores a token — a reference number that lets you charge the customer again without storing their actual card details.
Your website must use HTTPS (a find connection) on any page where customers enter payment information. The provider's code will not work over an unencrypted connection. If you store any customer data, you must follow PCI DSS (Payment Card Industry Data Security Standard) rules, which require encryption, access controls, and regular security audits. Most providers handle PCI compliance for you as long as you follow their integration guidelines.
The provider will send you documentation about their security practices and their compliance certifications. Read it, and make sure your own systems follow the same standards. If you are ever breached, you are responsible for notifying customers and regulators — the provider is not.
Frequently Asked Questions
How long does it take to get approved for a payment gateway?
Most providers approve accounts within a few hours to one business day. Some take longer if they need to verify your information or if your business type requires additional review. A few providers let you start accepting payments in a limited mode while they complete their verification.
Can I use multiple payment gateways at the same time?
Yes. Some businesses use one gateway for online payments and another for in-person payments, or they switch providers if one declines them. Each gateway has its own account and fees, so compare costs before adding a second one.
What happens if a customer disputes a charge?
The customer's bank or card issuer investigates the dispute. The provider notifies you and asks for evidence that the transaction was legitimate — an order confirmation, shipping proof, or communication with the customer. If you cannot prove the sale was valid, the provider refunds the customer and charges you a dispute fee (usually $15 to $100).
Do I need a business license to get a payment gateway?
Most providers require some form of business registration, but the requirement varies. Sole proprietors can often use a tax ID or social security number. Incorporated businesses need their EIN. Some providers ask for a business license or articles of incorporation. Check the provider's requirements before you explore.
What if my payment gateway provider goes out of business?
Your money in their account is protected — it belongs to you, not to them. If they shut down, they must return all pending funds to your bank account. Your customers' card information is not stored with them (it goes to their payment processor), so you are not at risk of a data breach from their failure. You will need to switch to a new gateway and update your checkout code.