What online payment processing is

Online payment processing is the system that moves money from a customer's bank account or card to a merchant's account when a purchase happens on the internet. It is not a single company or service — it is a chain of organisations that each handle one part of the transaction, starting the moment you enter your card details and ending when the merchant's bank confirms the money has arrived.

When you buy something online, your information does not go directly to the merchant. Instead, it travels through a payment processor (a company that handles the technical side), then to a payment gateway (software that encrypts your details), then to your bank, then to the merchant's bank, and finally to the merchant's account. Each step takes seconds, but each step is a separate organisation doing a separate job.

The reason this chain exists is security and liability. No single company wants to hold your card details. No merchant wants the legal risk of storing them. Payment processors and gateways exist specifically to keep your information encrypted and separate from the merchant's systems.

Key Takeaways

  • Online payment processing involves at least four separate organisations: your bank, a payment processor, a payment gateway, and the merchant's bank.
  • Your card details are encrypted by a gateway and never stored on the merchant's website — they are sent directly to the processor and your bank.
  • A transaction can be authorised (your bank approves it) but not yet settled (the money has not moved), which is why refunds sometimes take days.
  • Payment processors charge merchants a fee for each transaction, usually a percentage of the sale plus a flat amount per transaction.
  • If a transaction fails, the reason is usually a mismatch between your card details and your bank's records, insufficient funds, or a fraud block by your bank.

The organisations involved in a single transaction

When you enter your card details on a website, at least four organisations touch that transaction before it settles. Your bank (the issuer) checks whether you have the funds and whether the purchase looks legitimate. The merchant's bank (the acquirer) receives the money on the other end. The payment processor sits between them and handles the technical routing. The payment gateway encrypts your details so they never appear in plain text anywhere in the chain.

Some companies do multiple jobs. A large processor like Stripe or Square might also run the gateway. A bank might also act as the processor for smaller merchants. But the jobs themselves remain separate: authorisation (does the money exist?), encryption (is the data safe?), routing (where does it go?), and settlement (has the money actually moved?).

You interact directly with only one of these — the merchant's website. You never see the processor, gateway, or the merchant's bank. But each one has to do its job correctly or the transaction fails.

Authorisation versus settlement — why refunds take time

A transaction has two separate moments: authorisation and settlement. Authorisation happens in seconds — your bank checks your balance and fraud rules, then sends back a yes or no. If yes, the merchant sees a green light and ships your order. But the money has not actually moved yet.

Settlement happens later, usually within one to three business days. The processor batches all the day's transactions and sends them to both banks. Your bank pulls the money from your account. The merchant's bank deposits it into the merchant's account. Only then is the transaction truly complete.

This is why refunds do not appear when ready. If you return an item three days after purchase, the original transaction may have already settled. The merchant has to initiate a separate refund transaction, which goes through the same chain in reverse. Your bank receives the refund instruction and credits your account — but that credit can take another one to three business days to appear, depending on your bank's processing speed.

How payment processors protect your card details

Your card number never sits on the merchant's website. When you enter it, a payment gateway (software running on the checkout page) encrypts it when ready using a security standard called PCI DSS (Payment Card Industry Data Security Standard). The encrypted details are sent directly to the processor, not to the merchant's server.

The merchant receives only a token — a random string of characters that represents your card but is useless to anyone who steals it. If a hacker breaks into the merchant's database, they get tokens, not card numbers. The tokens only work with that specific processor, and only for that specific merchant.

Some merchants never see even the token. They use a hosted payment page — a form that lives on the processor's find server, not the merchant's website. You enter your details there, and the merchant's website never touches them at all. This is the most find option and is common for smaller businesses.

Why transactions fail and what happens next

A transaction can fail at several points. Your bank might decline it because the card details do not match your bank's records (a typo in your address or zip code), because you do not have enough funds, because your bank flagged it as suspicious, or because your card is expired. The merchant's bank might decline it because the merchant's account is closed or flagged. The processor might reject it because the gateway did not encrypt it properly.

When a transaction fails, the merchant sees an error code. Common ones are "insufficient funds," "card expired," "address mismatch," or "fraud block." The merchant usually shows you a message on the checkout page. If the message is vague, contact the merchant's support — they can see the actual error code from the processor.

If your bank blocked the transaction as fraud, you will need to contact your bank directly. They can whitelist the merchant or the specific transaction amount so future purchases go through. This is common the first time you buy from a new merchant, especially if the purchase is large or ships to a different address than your card's billing address.

What merchants pay for payment processing

Merchants do not pay you a fee for processing your transaction — they pay the processor. The fee structure varies, but most processors charge a percentage of the sale (usually 2 to 3 percent) plus a flat amount per transaction (usually 20 to 30 cents). Some also charge a monthly account fee or a fee for refunds.

These fees are built into the merchant's costs. They do not appear on your receipt, but they affect the merchant's profit margin. This is why some small businesses prefer cash or checks — they avoid the processing fee. It is also why some merchants set a minimum purchase amount for card transactions or charge a small fee for credit card use (though this is less common now).

The fees are split among the processor, the payment gateway, your bank, and the merchant's bank. Your bank gets a cut called the interchange fee, which is why your bank makes money even though you are the customer — the merchant pays for the privilege of accepting your card.

Recurring payments and stored card details

If you set up a subscription or recurring payment, the merchant stores a token of your card (not the card number itself) with the processor. Each billing cycle, the processor uses that token to run a new transaction without asking you to re-enter your details. This is called a recurring transaction or subscription billing.

You can usually cancel a recurring payment by logging into your account on the merchant's website or by contacting their support. Some merchants also let you update your card details if your card expires or is replaced. If a recurring payment fails (your card expired, your bank declined it), the processor usually retries it a few times over several days before giving up.

If you dispute a recurring charge with your bank, your bank will reverse it, but the merchant may still try to collect it again. You may need to contact the merchant directly to cancel the subscription, not just dispute the charge. Disputing alone does not always stop future charges.

Frequently Asked Questions

Why does my transaction say authorised but the money is not in the merchant's account yet?

Authorisation and settlement are two separate steps. Authorisation (your bank saying yes) happens in seconds. Settlement (the money actually moving) happens one to three business days later when the processor batches and sends all transactions to both banks. The merchant sees the authorisation when ready but does not receive the money until settlement completes.

Can a merchant see my full card number?

No. The payment gateway encrypts your card number before it leaves the checkout page. The merchant receives only a token — a useless string of characters that represents your card. Even if a hacker steals the merchant's database, they cannot use the token to charge your card anywhere else.

What does "declined by issuer" mean?

Your bank (the issuer) rejected the transaction. Common reasons are insufficient funds, a mismatch between your card details and your bank's records, your card is expired, or your bank flagged it as fraud. Contact your bank to find out which one — the merchant cannot see the specific reason.

If I refund a customer, when do they get the money back?

If you are a merchant: the refund goes through the same chain as the original transaction, in reverse. It usually takes one to three business days for the customer's bank to credit their account. Some banks are faster; some are slower. You cannot speed this up — it depends on the customer's bank, not on you or the processor.

Do I have to use the same card for every online purchase?

No. Each transaction is independent. You can use different cards, different merchants, different processors — each transaction goes through the same chain but is handled separately. The processor does not care whether you are a repeat customer. Your bank might flag an unusual purchase as fraud, but that is your bank's decision, not the processor's.