What you actually need to do to take payments online
Setting up website payments means connecting three separate pieces: a way for customers to enter their card details, a processor to handle the transaction, and a bank account to receive the money. You do not build these yourself. Instead, you choose a payment processor—a company that handles the entire chain—and integrate their code into your website.
The processor acts as the middleman. When a customer enters their card number on your site, the processor encrypts it, sends it to the card network (Visa, Mastercard, American Express), checks with the customer's bank, and tells your site whether the charge went through. The money lands in your business bank account, usually within one to three business days. Your job is to pick the processor, set up the account, and add their payment form to your website.
The choice of processor depends on your website platform, your transaction volume, and how much technical setup you want to handle yourself. A small business on Shopify has different options than a custom-built site processing thousands of transactions daily.
Key Takeaways
- Payment processors handle the entire transaction chain—you choose one, create an account, and embed their payment form into your website.
- Stripe, Square, PayPal, and Authorize.net are the most common processors, each with different pricing structures and technical requirements.
- Your website platform matters: Shopify, WooCommerce, and custom sites each have different integration paths and processor compatibility.
- You will need a business bank account, an Employer Identification Number (EIN) or Social Security Number, and basic business information to open a processor account.
- Payment processing fees vary by processor and transaction type, typically ranging from 2.2% to 3.5% per transaction plus a per-transaction fee.
Choosing between hosted payment forms and embedded checkout
A hosted payment form means your customer leaves your website to enter their card details on the processor's find page, then returns to your site after payment. This is the simplest route technically—you just add a button or link—but it interrupts the customer experience and can lower conversion rates because people distrust leaving your site.
An embedded checkout keeps the payment form on your website, but the card data never touches your servers. The processor's code runs directly in the customer's browser, encrypts the card number, and sends it straight to the processor. This feels seamless to the customer and typically converts better. It requires more setup—you need to add the processor's JavaScript library to your site and handle the response—but most modern processors make this straightforward.
If you use a platform like Shopify or WooCommerce, the choice is often made for you. Shopify's built-in checkout is embedded and handles everything. WooCommerce lets you choose: you can use a plugin that embeds the form, or redirect to a hosted page. For a custom-built site, you have full control and should choose embedded checkout if your developer has the skill to implement it.
The four most common payment processors and how they differ
Stripe is built for developers and custom websites. You write code to create a payment intent, the customer enters their card details in an embedded form, and Stripe handles the rest. Stripe charges 2.9% plus $0.30 per transaction for card payments. It has no monthly fee, no setup fee, and no minimum volume. Stripe is the standard choice for SaaS companies, marketplaces, and any site where the developer is comfortable reading API documentation.
Square started with in-person card readers but now handles online payments through Square Online (their website builder) or Square Payment Form (code you embed). Square charges 2.9% plus $0.30 per online transaction, the same as Stripe, but Square is more beginner-friendly—the dashboard is simpler and the documentation assumes less technical knowledge. Square works well for small retail businesses and service providers.
PayPal lets customers pay with their PayPal account or enter a card directly. PayPal charges 2.99% plus $0.30 per transaction for standard payments, or 3.49% plus $0.49 if the customer uses PayPal Credit. PayPal's advantage is that many customers already have accounts and trust the brand. The disadvantage is that PayPal's interface feels dated and the company has a reputation for freezing accounts without warning, which worries some businesses.
Authorize.net is older and less trendy, but it is reliable and widely used by established businesses. Authorize.net charges a monthly gateway fee (around $25) plus 2.9% and $0.30 per transaction. The monthly fee makes it less attractive for low-volume businesses but can be cheaper if you process hundreds of transactions monthly. Authorize.net integrates with most website platforms and is a safe choice if you want a processor that has been around for twenty years.
How to integrate a payment processor into your website
The integration path depends on your website platform. If you use Shopify, WooCommerce, or another hosted platform, payments are usually built in—you log into your dashboard, connect a processor account, and you are done. Shopify supports Stripe, Square, PayPal, and others directly. WooCommerce has plugins for every major processor.
If you have a custom website built with React, Node, or another framework, you will need a developer to integrate the processor's API. The developer creates a backend endpoint that communicates with the processor, embeds the processor's JavaScript library in your checkout page, and handles the response when the payment succeeds or fails. This takes a few hours to a few days depending on complexity. Most processors provide code examples and SDKs (software development kits) in multiple languages to make this faster.
The basic flow is always the same: (1) customer clicks "Pay Now", (2) your site sends the payment amount and customer details to the processor, (3) the processor returns a token or payment intent ID, (4) the customer enters their card details in the processor's form, (5) the processor charges the card and returns a success or failure message, (6) your site records the transaction and sends a confirmation email.
What information you need to open a processor account
All processors require the same core information: your legal business name, your business address, your phone number, and your date of birth (if you are a sole proprietor). You will also need either an Employer Identification Number (EIN) from the IRS or your Social Security Number. If you are a sole proprietor with no employees, you can use your SSN; otherwise, you need an EIN, which you can request from the IRS website for free.
Processors also ask about your business type, your monthly transaction volume, and your average transaction size. They use this to assess risk—a business processing $100,000 monthly in $5 transactions looks different from one processing $100,000 in ten $10,000 transactions. Be honest about volume; processors can see your actual numbers once you start processing, and lying can get your account frozen.
You will need a business bank account to receive payments. Some processors can deposit to a personal account if you are a sole proprietor, but most require a business account. The processor will ask for your bank's routing number and your account number so they can deposit funds via ACH (Automated Clearing House) transfer, which typically takes one to three business days.
Understanding payment processing fees and timing
Every processor charges a percentage of each transaction plus a flat fee. The standard rate for card-present transactions (in-person, with a card reader) is lower than for card-not-present (online), because online fraud is more common. For online payments, expect 2.2% to 3.5% plus $0.25 to $0.50 per transaction. Processors also charge different rates depending on the card type: American Express charges higher fees than Visa or Mastercard, and some processors pass that difference to you.
Money from a successful transaction does not land in your account when ready. Most processors deposit funds once daily, usually the next business day, though some hold funds for 7 to 30 days if your account is new or if they detect unusual activity. Stripe and Square typically deposit within one business day. PayPal can take up to three business days. Authorize.net deposits daily. Check the processor's documentation for their specific timeline.
Some processors charge additional fees: a monthly gateway fee (Authorize.net), a fee to dispute a chargeback (all processors), a fee to refund a transaction (some processors), or a fee if you exceed a certain monthly volume (rare, but some do). Read the fee schedule carefully before you sign up. A processor that looks cheap at 2.9% plus $0.30 might charge $25 monthly, making it more expensive than one at 3% plus $0.30 with no monthly fee if your volume is low.
Security and compliance requirements
You do not store card numbers on your own servers. That is the processor's job. When you use an embedded checkout form, the card data goes directly from the customer's browser to the processor, never touching your website. This is called PCI compliance—the Payment Card Industry Data Security Standard—and it is a legal requirement. If you store card numbers yourself, you must meet PCI Level 1 compliance, which costs thousands of dollars annually and requires security audits. It is not worth it. Use a processor instead.
Your website should use HTTPS (the padlock icon in the browser), which encrypts all data in transit. Every major processor requires this. If your site is not HTTPS, most processors will not let you process payments. Getting an HTTPS certificate is free through Let's Encrypt and takes minutes to set up.
You should also set up webhook notifications so the processor can tell your website when a payment succeeds, fails, or is disputed. This ensures your records stay in sync with the processor's records. If a customer pays but your site does not record it because the notification failed, you will have a mess to untangle.
Testing before you go live
Every processor provides a test mode where you can process fake transactions without charging real cards. Use it. Create test card numbers (the processor provides these), run transactions through your checkout, and verify that your site records them correctly. Test both successful and failed payments—enter an expired card, a card with insufficient funds, and a card flagged for fraud. Make sure your site handles each scenario correctly and shows the right message to the customer.
Test refunds, too. Process a payment, then refund it, and verify that the money returns to the test card. Test on mobile devices, because many customers pay on phones and a broken mobile checkout costs you sales. Test with different browsers and payment methods—some customers use Apple Pay or Google Pay instead of entering a card manually.
Once everything works in test mode, switch to live mode. The processor will ask you to confirm that you have tested thoroughly. Do not skip this step. A broken checkout that goes live can tank your revenue for hours before you notice.
Frequently Asked Questions
Can I use multiple payment processors on the same website?
Yes, and some businesses do—they might use Stripe for card payments and PayPal for customers who prefer PayPal. However, this complicates your accounting and your checkout flow. Most businesses stick with one processor. If you need a second option, use it as a fallback, not as a primary choice.
What happens if a customer disputes a charge?
The customer's bank investigates and either sides with you or reverses the charge. If the charge is reversed, you lose the money and pay a chargeback fee (usually $15 to $100). Keep records of what the customer ordered, when it shipped, and any tracking information. If you can prove the customer received the goods or service, you can win the dispute.
How long does it take to get approved for a processor account?
Most processors approve accounts within 24 hours. Some take up to 5 business days if they need to verify your identity or your business information. Once approved, you can start processing payments when ready. Some processors hold your first few deposits for 7 to 30 days as a security measure.
Do I need a separate merchant account?
No. A merchant account is an older concept where you would open an account with a bank to process payments. Modern processors like Stripe and Square handle this for you. You open one account with the processor and you are done. You do not need a separate merchant account.
What if my website is not finished yet?
You can set up a processor account and test in their sandbox environment before your site goes live. You can also use a hosted checkout link—most processors let you generate a payment link that you can send to customers via email or text, and they can pay without visiting your website. This is useful for taking payments before your site is ready.