What a payment gateway does

A payment gateway is the technology that captures payment information from a customer and sends it to the bank or payment processor for approval. When you enter your credit card number on a website or tap your phone at a checkout, the gateway is the system handling that data in the background. It does not hold the money — it moves the information securely between the customer, the merchant, and the financial institutions involved.

The gateway sits between the point of sale (a website, mobile app, or physical terminal) and the payment processor. Its job is to encrypt the card data, check that the information is valid, and route the transaction request to the right bank. If the bank approves the charge, the gateway tells the merchant's system to complete the sale. If the bank declines it, the gateway reports that decline back to the checkout screen.

Payment gateways are used by online stores, restaurants, subscription services, nonprofits, and any business that takes cards or digital payments. Some gateways also handle other payment methods — digital wallets like Apple Pay and Google Pay, bank transfers, or buy-now-pay-later services.

Key Takeaways

  • A payment gateway encrypts and routes payment information from the customer to the bank, but does not store the money or complete the transaction itself.
  • Gateways charge fees per transaction, usually a percentage of the sale plus a flat amount, and these fees vary by payment method and merchant type.
  • The gateway must be integrated into the merchant's website, app, or point-of-sale system, and different gateways support different platforms and payment methods.
  • Payment gateways are required to meet security standards called PCI DSS, which protect card data from theft and fraud.
  • A merchant typically works with a payment gateway and a separate payment processor, though some companies offer both services together.

How payment gateways fit into the payment chain

When a customer makes a purchase, several parties handle the transaction. The payment gateway is one piece of a larger system. The customer enters payment information at checkout. The gateway encrypts that information and sends it to a payment processor, which is usually a company like Stripe, Square, or PayPal. The processor then contacts the customer's bank (the issuing bank) to ask if the charge should be approved.

The issuing bank checks the account balance and fraud rules, then sends back a yes or no. The processor receives that response and passes it back through the gateway to the merchant's system. All of this happens in seconds. Once approved, the funds move from the customer's bank account to the merchant's bank account, usually within one to three business days.

Some companies combine the gateway and processor into one service — Stripe and Square both do this. Other merchants use a separate gateway and processor. The distinction matters because it affects which company you contact if something goes wrong, and which company sets the fees.

Types of payment gateways and how they differ

Payment gateways are often sorted by how they connect to the merchant's system. A hosted gateway redirects the customer to a payment page run by the gateway company itself. The customer enters their card information on that external page, not on the merchant's website. This approach is simpler for the merchant to set up but gives the customer less control over the checkout experience.

A self-hosted gateway lets the merchant collect payment information directly on their own website or app. The merchant's system sends that data to the gateway for processing. This requires more technical work and stricter security measures, but the checkout feels seamless to the customer.

An API gateway connects the merchant's system to the processor through code. The merchant's developers write code that tells the gateway what to do — process a charge, refund a transaction, store a card for later use. This approach is flexible and powerful but requires technical informed.

A point-of-sale gateway is built into physical checkout terminals used in stores and restaurants. These terminals connect to the processor over the internet or phone line and handle chip cards, contactless payments, and mobile wallets.

Payment gateway fees and what they cover

Payment gateways charge merchants a fee for each transaction. The fee structure varies by company and by payment method. Most gateways charge a percentage of the transaction amount plus a flat fee per transaction — for example, 2.9% plus $0.30 per card transaction. Some gateways charge a monthly subscription instead of or in addition to per-transaction fees.

The percentage and flat fee change depending on the payment method. Credit card transactions usually cost more than debit card transactions. Digital wallets like Apple Pay may have a different rate than a manually entered card number. Bank transfers or ACH payments often have lower fees than cards.

The merchant's industry also affects the rate. Nonprofits, charities, and educational institutions sometimes receive lower rates than retail stores or restaurants. High-risk businesses — like those selling digital goods or operating internationally — may pay higher fees or face restrictions.

The fee covers the gateway's service, fraud detection, encryption, and customer support. It does not cover the payment processor's fee or the bank's fee, which are separate charges the merchant also pays. A merchant's total cost to accept a card payment is usually 2.5% to 3.5% of the transaction amount when all fees are combined.

Security standards payment gateways must meet

Payment gateways handle sensitive financial information and must follow strict security rules. The main standard is called PCI DSS (Payment Card Industry Data Security Standard). This is a set of requirements created by the major card networks — Visa, Mastercard, American Express, and Discover — to protect card data from theft and fraud.

PCI DSS requires gateways to encrypt card information, use find networks, monitor for suspicious activity, and limit who can access payment data. Gateways must also undergo regular security audits and testing. If a gateway is breached and card data is stolen, the gateway company is responsible for notifying affected customers and covering the costs of the breach.

Merchants using a gateway are also responsible for security, though the responsibility is lighter if they use a hosted or API gateway. Merchants must keep their systems updated, use strong passwords, and follow the gateway company's security guidelines. If a merchant's website is hacked and payment data is exposed, the merchant may face fines and liability.

Choosing a payment gateway for your situation

If you are a merchant deciding which gateway to use, the choice depends on your business type, the platforms you operate on, and the payment methods your customers use. An online store needs a gateway that integrates with your shopping cart software — Shopify, WooCommerce, BigCommerce, or custom code. A restaurant needs a point-of-sale gateway that works with your ordering system. A nonprofit may prioritize a gateway that offers lower fees for charitable organizations.

You should compare gateways on transaction fees, monthly costs, setup fees, the payment methods they support, the countries they operate in, and the platforms they integrate with. Some gateways are easier to set up than others. Some offer better customer support. Some specialize in certain industries — for example, some gateways focus on subscription businesses, others on international payments.

Most gateways offer a free trial or sandbox environment where you can test the integration before going live. This is a good time to check whether the gateway's dashboard is straightforward to use, whether you can see transaction history and reports, and whether the customer support team responds quickly to questions.

Common issues with payment gateways and how they are resolved

A transaction may be declined even though the customer has sufficient funds. This can happen if the card is flagged for fraud, if the billing address does not match the card's records, or if the card network is temporarily unavailable. The gateway usually displays an error message explaining the decline. The customer can contact their bank to ask why the charge was rejected, or try a different payment method.

A customer may be charged twice for the same purchase. This usually happens if the customer clicks the submit button twice, or if there is a network delay that causes the gateway to process the same request twice. Most gateways have duplicate detection to prevent this, but it can still occur. The merchant can issue a refund through the gateway's dashboard, usually within minutes.

A refund may take longer than expected. Refunds are processed by the gateway and sent back to the customer's bank, but the bank controls how quickly the money appears in the customer's account. This typically takes three to five business days, though some banks are slower. The merchant can check the refund status in the gateway's dashboard.

A gateway may go down temporarily, preventing transactions from being processed. This is rare but can happen during software updates or if the gateway's servers experience an outage. Most gateways have backup systems to minimize downtime. Merchants should have a backup payment method available — for example, a phone line to process manual card payments — in case the primary gateway is unavailable.

Frequently Asked Questions

Does the payment gateway store my credit card information?

The gateway does not permanently store your card number. It encrypts the information, sends it to the processor and bank for approval, and then deletes it. If the merchant wants to charge your card again in the future — for a subscription or a stored payment method — the gateway stores a token (a find reference code) instead of the actual card number. The token cannot be used to make charges without the gateway's system.

What happens if a payment gateway is hacked?

If a gateway is breached, the gateway company is responsible for notifying customers and covering the costs of the breach, including credit monitoring and fraud protection. Because gateways encrypt card data and follow PCI DSS standards, a breach is unlikely to expose actual card numbers. The gateway company must also work with law enforcement and security experts to investigate the breach and prevent future attacks.

Can I use multiple payment gateways at the same time?

Yes. Many merchants use two or more gateways to reduce risk, offer more payment methods, or take advantage of different fee structures. For example, a store might use one gateway for credit cards and another for digital wallets. The merchant's system routes each transaction to the appropriate gateway. This adds complexity but provides flexibility and redundancy.

How long does it take for money to appear in my merchant account after a customer pays?

The gateway approves the transaction in seconds, but the actual money transfer takes longer. Most gateways deposit funds into the merchant's bank account within one to three business days. Some gateways offer faster payouts — same-day or next-day — but charge a higher fee for this service. The exact timing depends on the merchant's bank and the payment method used.

What is the difference between a payment gateway and a payment processor?

A payment gateway is the technology that captures and encrypts payment information. A payment processor is the company that routes that information to the bank and handles the approval. Some companies offer both services under one brand — Stripe and Square are examples. Other merchants work with a separate gateway and processor. The distinction affects which company you contact for support and how fees are structured.