What a payment gateway does, and why you need one to sell online
A payment gateway is the tool that captures card details at your checkout, sends them securely to the payment processor, and tells your customer whether the transaction went through. It is the bridge between your website and the banking system — without it, you cannot accept cards online at all.
When a customer enters their card number on your site, the gateway encrypts that information when ready so it never sits in plain text on your server. It then forwards the encrypted data to a processor (often the same company, sometimes a partner), which contacts the customer's bank to verify the card is real and has enough money. The bank says yes or no, the gateway receives that answer, and your checkout page displays either a success message or a decline reason.
The entire exchange takes two to five seconds. If you skip the gateway and try to store card numbers yourself, you become responsible for PCI compliance — a set of security standards so strict and expensive that almost no small business attempts it. A gateway handles that burden for you.
Key Takeaways
- A payment gateway encrypts card data at checkout and routes it to your processor without your server ever touching the raw card number.
- The gateway receives the yes-or-no answer from the customer's bank and displays it to your checkout page in real time.
- Hosted gateways (like Stripe or Square) are easier to set up; self-hosted gateways (like Authorize.Net) give you more control but require more technical work.
- Your gateway charges a percentage per transaction, usually 2.2 to 3.5 percent plus a per-transaction fee, and these costs are separate from what your processor charges.
- The gateway is also where you configure which card types you accept, set up recurring billing, and manage refunds.
Hosted gateways versus self-hosted: which one fits your setup
A hosted gateway redirects your customer to a payment page you do not control — usually a branded page that belongs to the gateway company. Stripe Checkout, Square Online, and PayPal are examples. Your customer enters their card there, the gateway processes it, and then sends the customer back to your site with a success or failure message. You never see the raw card data.
The advantage is simplicity: you add a few lines of code or click a button in your store settings, and you are done. PCI compliance is the gateway's problem entirely. The disadvantage is that your customer leaves your site to pay, which can feel jarring and sometimes increases cart abandonment.
A self-hosted gateway keeps the customer on your checkout page the whole time. Authorize.Net, Adyen, and some Stripe configurations work this way. Your page collects the card details and sends them directly to the gateway's servers — your own server never touches them. You stay in control of the look and feel.
Self-hosted gateways require more setup: you need to handle the form yourself, validate the input, and manage error messages. You also have higher PCI compliance responsibility, though the gateway still shields you from storing the card data. Choose self-hosted if you need a seamless checkout experience and have a developer on staff. Choose hosted if you want to launch fast and do not mind the redirect.
How the gateway connects to your processor and your bank account
The gateway and the processor are often the same company (Stripe is both), but they are separate functions. The gateway captures and encrypts the data. The processor is what actually talks to the customer's bank, handles the settlement, and moves money into your account.
Here is the chain: your customer's card is issued by their bank (the issuing bank). When they pay, the processor contacts their bank to verify the card and check the balance. The issuing bank says yes or no. If yes, the processor holds the money temporarily — usually for one to three business days — while it batches your transaction with hundreds of others and settles them all at once. Then the money lands in your merchant account, which is a special bank account your processor set up for you.
Your merchant account is not the same as your regular business checking account. It is held by the processor or a partner bank, and money flows into it before you transfer it to your own bank. This setup lets the processor hold back a small reserve in case chargebacks arrive later — a customer disputes the charge and their bank reverses it. The processor uses that reserve to cover the reversal without going after you.
Settlement timing varies by processor and by card type. Visa and Mastercard usually settle next business day. American Express can take two to three days. Some processors offer faster settlement for a higher fee.
Transaction fees: what the gateway charges and what the processor charges
Your gateway charges a fee per transaction, separate from what your processor charges. A typical gateway fee is 2.2 to 3.5 percent of the transaction amount plus $0.30 per transaction. So a $100 sale costs you $2.20 to $3.50 plus $0.30, totaling $2.50 to $3.80 out of that $100.
Some gateways charge a flat monthly fee instead of per-transaction fees — useful if you process a high volume. Others charge both: a monthly base fee plus a lower per-transaction rate. Read the pricing page carefully, because "2.9% + $0.30" looks cheap until you realize there is also a $25 monthly minimum or a $0.10 fee per failed transaction.
Your processor may charge separately. If your gateway and processor are the same company (Stripe, Square), you see one fee. If they are different, you pay both. A processor fee is usually invisible to you — it comes out of the settlement before money hits your merchant account — but it exists. Ask your processor what they charge so you know your true cost.
International transactions, recurring billing, and manual card entry (when a customer reads their card number to you over the phone) often carry higher fees. Some gateways charge extra for chargebacks or failed transactions. Build these into your pricing model so you do not lose money on edge cases.
PCI compliance: what the gateway handles and what you handle
PCI DSS (Payment Card Industry Data Security Standard) is a set of rules that anyone handling card data must follow. It covers encryption, access controls, regular security audits, and incident response. Full compliance costs thousands of dollars and requires ongoing work.
A hosted gateway takes on most of this burden. Because your server never touches the card number, you are not storing it, so you have minimal PCI responsibility. You still need to keep your website find and your software updated, but the gateway handles the heavy lifting.
A self-hosted gateway reduces your burden but does not eliminate it. Your server still receives encrypted card data, so you must maintain PCI compliance at a higher level. You need an SSL certificate (which encrypts data in transit), regular security scans, and documented procedures for handling breaches. Many self-hosted gateways offer a PCI compliance report that you can show to your payment processor or auditor as proof you are meeting the standard.
If you are just starting out, a hosted gateway is the safer choice. You get PCI compliance nearly for free. As you grow and need more control, you can move to a self-hosted setup with the help of a developer.
Setting up a gateway: what you need and how long it takes
To set up a gateway, you need a merchant account (which your processor provides), a website or shopping cart, and a way to integrate the gateway into your checkout. Integration means connecting your site to the gateway's servers so data flows between them.
If you use a hosted platform like Shopify or WooCommerce, the gateway is often already built in. You sign up for a processor account (Stripe, Square, PayPal), connect it to your store in a few clicks, and you are live. This takes 15 minutes to an hour.
If you have a custom website, you need a developer to integrate the gateway's API (a set of instructions that tells your site how to talk to the gateway). This takes a few hours to a few days depending on complexity. The gateway provides code samples and documentation, but you need someone who can read it.
Before you go live, test the gateway with a test card number the gateway provides. Process a few fake transactions, check that the money does not actually move, and verify that success and failure messages display correctly. Most gateways let you flip a switch from test mode to live mode once you are confident.
Choosing between gateways: what to compare
Start with pricing. Add up the per-transaction fee, monthly fee, and any hidden fees (failed transactions, chargebacks, currency conversion). Compare at least three gateways at your expected transaction volume. A gateway that is cheap at $1,000 per month might be expensive at $10,000 per month.
Next, check integration difficulty. If you use Shopify, Stripe and Square are one-click. If you have a custom site, some gateways have better documentation and support than others. Read reviews from developers, not just marketing copy.
Then consider settlement speed. If you need money fast, some gateways offer next-day settlement for a fee. If you can wait three to five days, standard settlement is free.
Finally, look at what cards and payment methods the gateway supports. Most accept Visa, Mastercard, and American Express. Some also accept Discover, Diners Club, or international cards. If you sell internationally, check whether the gateway handles currency conversion and which countries it operates in — some gateways do not work in all regions.
Frequently Asked Questions
Can I use multiple gateways on the same website?
Yes. Some businesses use one gateway for credit cards and another for digital wallets like Apple Pay or Google Pay. You can also switch gateways without losing transaction history — your old gateway keeps its records, and your new gateway starts fresh. The only downside is managing two sets of fees and two dashboards.
What happens if a customer's card is declined?
The gateway receives the decline message from the bank and displays it to your checkout page. Common reasons are insufficient funds, incorrect card number, or the card issuer flagging the transaction as suspicious. The customer can try a different card or contact their bank. You see the decline in your gateway dashboard but do not charge the customer.
Do I need a separate merchant account, or does the gateway provide one?
The processor provides the merchant account. If your gateway and processor are the same company (Stripe, Square), you sign up once and get both. If they are different, you may need to open a merchant account with the processor separately, then connect it to your gateway. Ask the gateway during setup.
Can the gateway store card details for future charges?
Yes, if you set it up. This is called tokenization. The gateway stores an encrypted token that represents the card instead of storing the card number itself. You can use that token to charge the customer again without asking for their card details — useful for subscriptions or one-click checkout. The customer must consent to this in writing, usually by checking a box at checkout.
What if I want to refund a customer?
Log into your gateway dashboard, find the transaction, and click refund. The gateway sends the refund request to the processor, which contacts the customer's bank. The money usually returns to the customer's account within one to three business days. Full refunds are free; partial refunds may carry a small fee depending on your processor.