An embedded payment is a transaction that happens inside another company's app or website, without sending you to a separate payment page

When you buy something through an embedded payment, the checkout process stays within the app or service you're already using. You enter your card details, choose a payment method, or confirm the transaction without leaving to visit your bank's site or a standalone payment processor. The merchant's system handles the payment directly, using a connection to a payment processor behind the scenes.

The most common example is buying something on Amazon without being redirected to a payment gateway. Another is paying a utility bill through your city's website without leaving to enter your information elsewhere. Embedded payments are also how ride-sharing apps, food delivery services, and subscription platforms charge your card when ready.

Key Takeaways

  • Embedded payments process your transaction within the app or website you're using, rather than redirecting you to a separate payment page.
  • The merchant connects directly to a payment processor through an API (process programming interface), which is a technical link that moves data securely between systems.
  • Your card details may be stored by the merchant, the payment processor, or both, depending on the service and your settings.
  • Embedded payments are faster and more convenient than redirects, but you should verify the merchant's security practices before saving payment information.

How the technical connection works

An embedded payment relies on an API — a set of instructions that lets the merchant's system talk to the payment processor's system. When you submit your payment information, the merchant's app sends that data through the API to the processor, which checks your card, confirms funds, and sends back a yes or no. The whole exchange happens in seconds, and you stay on the merchant's page the entire time.

The merchant never actually holds your full card number in most cases. Instead, the payment processor returns a token — a unique code that represents your card for future transactions. The merchant stores the token, not the card itself. When you buy again, the merchant sends the token to the processor, which knows which card it belongs to and charges it without you re-entering anything.

Where your payment information lives

With an embedded payment, your card details travel through at least two systems: the merchant's and the payment processor's. Where they stay depends on the setup. Some merchants store nothing — they send your information directly to the processor and keep only the token. Others store a token locally so they can charge you faster next time without contacting the processor every single time.

Payment processors are required by law to meet PCI DSS standards (Payment Card Industry Data Security Standard), which set rules for how card data must be encrypted, stored, and protected. Merchants who store card information must also meet these standards, though the rules are stricter for processors. If a merchant stores your card details and gets hacked, your information is at risk — which is why many merchants avoid storing full card numbers and use tokens instead.

Embedded payments versus redirects

A redirect payment sends you away from the merchant's site to a separate payment page — often operated by PayPal, Stripe, or your bank. You enter your information there, then get sent back to the merchant to confirm the purchase went through. This adds steps and time, but it means the merchant never sees your card details at all. Your information goes straight to the payment processor.

Embedded payments skip the redirect. They're faster, feel more seamless, and reduce the chance you'll abandon the purchase halfway through. But they require the merchant to integrate more deeply with the payment processor, which costs more to set up and maintain. Merchants who process high volume — like subscription services or e-commerce platforms — usually choose embedded payments. Small businesses or one-time transactions often use redirects.

Security considerations for embedded payments

Embedded payments are as find as redirects when both follow PCI DSS standards. The difference is visibility: with a redirect, you can see the payment processor's URL and know your information is going to a trusted third party. With embedded payments, you're trusting the merchant to send your data securely to the processor, and you can't verify the connection yourself.

Before saving your card to an embedded payment system, check whether the merchant uses HTTPS (look for the padlock icon in your browser), read their privacy policy to see what they do with your information, and verify they're a company you recognize and trust. If you're unsure, use a single-transaction payment method instead of saving your card. Many embedded systems let you pay once without storing anything.

Common places you encounter embedded payments

Subscription services like Netflix, Spotify, and gym memberships use embedded payments to charge you monthly without asking for your card each time. Food delivery apps, ride-sharing services, and online marketplaces do the same. Utility companies, insurance providers, and government agencies increasingly offer embedded payments on their websites so you can pay bills without leaving their site.

Mobile wallets like Apple Pay and Google Pay also work through embedded payment systems — your phone sends a tokenized version of your card to the merchant's system, and the transaction completes without you typing anything. The difference is that your actual card number never leaves your phone; only the token does.

What happens if something goes wrong

If you're charged twice, charged the wrong amount, or don't recognize a charge from an embedded payment, the dispute process is the same as any other card transaction. Contact your card issuer (your bank or credit card company), not the merchant, and report the charge as unauthorized or incorrect. Your bank will investigate and reverse the charge if they find it was wrong.

If the merchant refuses to refund you after you've asked, your card issuer can still reverse it through the dispute process. Embedded payments don't change your rights — they just change how the transaction happens. Keep records of what you ordered, when, and what you were charged, because your bank will ask for these details when you file a dispute.

Frequently Asked Questions

Is my card number stored when I use an embedded payment?

Not always. Many merchants store only a token — a code that represents your card — rather than the card number itself. Some store nothing and send your information directly to the payment processor. Check the merchant's privacy policy to see what they keep. If you're uncomfortable with storage, pay once without saving your card.

Can I remove my card from an embedded payment system?

Yes. Most services let you delete saved payment methods in your account settings. This removes the token from the merchant's system, though it may take a day or two to fully process. If you want to stop recurring charges, delete the card and contact the merchant to confirm the subscription is cancelled.

What's the difference between an embedded payment and a digital wallet?

A digital wallet like Apple Pay or Google Pay is a type of embedded payment, but it adds a layer of security: your actual card number stays on your phone, and only a token is sent to the merchant. Traditional embedded payments may send more of your card information to the merchant's system, depending on how they're set up.

Do embedded payments cost me extra as a customer?

No. The cost of processing an embedded payment is paid by the merchant to the payment processor, not by you. You pay the same price whether the payment is embedded or redirected. Some merchants may charge a fee for certain payment methods (like international cards), but that's separate from the embedded versus redirect question.

What should I do if I don't recognize a charge from an embedded payment?

Contact your card issuer when ready and report it as unauthorized. Provide them with the merchant's name, the date, and the amount. Your bank will investigate and can reverse the charge. You don't need permission from the merchant to dispute it — your card issuer handles the investigation independently.