Ecommerce payment processing demystified: how it actually works
One minute a customer is staring at their cart wondering if they really need a second candle; the next minute their bank account is a little lighter, and yours is a little heavier, and somehow it all happened without either of you lifting more than a finger to a screen. So what actually happens?
Every time a sale is made, a lot goes on behind the scenes in the space of a second or two. Card details get checked, funds get moved between banks, and your online store gets the green light to say "order confirmed", all in the blink of an eye (or sometimes two blinks).
If you're setting up an online store, or you're simply curious about what happens to your money each time you pay, then this is the blog for you. Here's a plain-English breakdown of how ecommerce payment processing works, who is involved, and if you’re a business owner: what to look for when choosing a provider.
The basic flow of an online payment
Interestingly enough, every card payment made online, whether it's a €20 face cream or a $2,000 sofa, requires roughly the same sequence of events.
-
The customer enters their payment details on your checkout page.
-
A payment gateway encrypts that information and securely passes it along for authorisation.
-
A payment processor sends the request to the relevant card network (Visa, Mastercard, American Express, and so on).
-
The card network routes the request to the customer's bank (the "issuing bank") to check that the card is valid and that the funds are available.
-
The issuing bank approves or declines the transaction, and that response travels back through the same chain.
-
If approved, the funds are moved from the customer's bank to your business's bank (the "acquiring bank"), usually arriving in your account within one to a few business days.
All of this typically takes a whopping two to three seconds. While the customer simply sees a loading symbol, four or five different systems are having a conversation, all at the same time.
Who’s involved?
The terminology in this space can be jargony, to say the least. So before moving forward, let’s get clear on what each term actually means.
-
Payment gateway: This is the technology that captures and encrypts the customer's payment details at checkout and passes them along the chain. Think of it as the digital equivalent of a card terminal .
-
Payment processor: The company that handles the behind-the-scenes communication between the gateway, the card networks, and the banks, and manages the authorisation process.
-
Acquiring bank: The bank that holds your business's merchant account and receives the funds on your behalf.
-
Issuing bank: This refers to the customer's own bank, which actually approves or declines the transaction based on their account.
-
Card network: Visa, Mastercard, American Express, and similar networks that set the rules and route transactions between issuing and acquiring banks.
Having a good understanding of what these terms mean will help you with your decision-making, so when you’re researching a provider, you know exactly what you’re talking about.
Common online payment methods
Once a customer reaches your checkout screen, they'll usually see a few different ways to pay: cards, digital wallets, maybe a "pay later" option. Which ones you offer can genuinely affect whether they finish the purchase or drop off.
Here are the main ones customers expect to see, though what's most popular can shift a bit depending on where you're selling:
-
Credit and debit cards remain the most widely used method across the US, UK, Ireland, and Germany, though card scheme preferences differ — American Express usage, for instance, tends to be higher in the US than in continental Europe.
-
Digital wallets like Apple Pay and Google Pay have become a standard expectation at checkout, offering customers a faster and easier payment experience than ever.
-
Bank transfer and direct debit methods are especially popular in some European markets; in Germany, for example, direct bank transfers and services like SEPA-based payments are a common alternative to cards.
-
Buy now, pay later options have grown quickly worldwide, letting customers pay over time, rather than all at once.
-
Pay-by-link options let you send a secure payment request via email or text, which is useful for remote or phone-based sales.
We recommend offering a mix of these, rather than cards alone, as it tends to reduce checkout drop-off. If customers see their preferred payment method, they are typically far more likely to complete a purchase.
Security: what keeps us safe
Every time a customer types in their card details, they're trusting you with information. So, how can you be sure that you’ll keep it safe? Fortunately, each card payment is backed by a set of standards working quietly in the background, so neither you nor the customer has to wing it and just hope for the best. Here’s what’s keeping both you and your customers safe:
-
PCI DSS compliance: The Payment Card Industry Data Security Standard is the baseline requirement for any business handling card data. A good payment provider will be fully PCI compliant, so the burden isn't sitting entirely on you.
-
Encryption and tokenization: Card details are scrambled in transit and often replaced with a "token" for storage, so the actual card number is never sitting exposed on your systems.
-
3D Secure / Strong Customer Authentication (SCA): An extra verification step (like a one-time code or banking app confirmation) that's now a regulatory requirement for many online card payments across the UK and EU, including Ireland and Germany. It adds a small extra step at checkout in exchange for meaningfully reducing fraud and chargebacks.
The good news is you don’t have to worry about any of this; none of this needs to be something you manage manually. These are all largely handled by your payment gateway and processor. Regardless, it’s nice to know what processes are keeping your money secure.
Understanding the fees
While often imperceptible, every time someone pays online, a small percentage of that sale gets taken as a fee before the rest reaches your account. This is how payment providers make their money, and how the banks and card networks involved get paid too. But where are they taking this money from, and how much do they take?
-
Interchange fees: Set by the card networks and paid to the customer's issuing bank. These are largely fixed and outside your processor's control.
-
Scheme fees: Smaller fees charged by the card network itself (Visa, Mastercard, etc.).
-
Processor markup: The fee your payment processor adds on top, which is usually the only part you can actually negotiate or shop around on.
Some providers charge more for online sales than in-person ones. This is worth looking into with your provider, as it can add up quickly if most of your sales occur online.
Understanding chargebacks
In some cases, a customer decides to skip the refund conversation altogether and goes straight to their bank to negate the charge. This is what’s known as a chargeback, and it tends to happen more often online than in person.
A good payment processor will help manage the dispute for you and flag suspicious transactions before they turn into a bigger problem. In practice, that means things like a card being used from an unusual location, an order placed with mismatched billing and delivery details, unusually large or repeated purchases in a short space of time, or a card that's already been reported lost or stolen.
Here’s our top tip: check exactly what fraud protection and dispute support is included before you sign up with a provider.
What to look for in a payment processor
Picking an ecommerce payment provider for your business is a big decision, as it will touch every online transaction your business makes. There are a lot of providers, some with many flashy features, so it can be hard to know what you actually need. Here’s what you should prioritise:
-
One flat rate: No confusing price tiers that shift depending on the card or the size of the sale.
-
No extra 'online' charge: Some providers quietly bump up the price for card-not-present transactions compared to in-person ones.
-
Built-in PCI compliance: Worth checking so it’s not left for you to figure out separately.
-
A proper connection to your ecommerce platform: Shopify, WooCommerce, BigCommerce, so sales, stock, and payments update automatically without needing manual syncing.
-
One system: If you sell both online and in-person, it's all one system, so you're not pulling two separate sets of reports together every month.
Epos Now ticks most of these boxes: one flat rate, no card-not-present markup, PCI compliance handled for you, and a setup that keeps online orders, in-store sales, and stock in the same place rather than three different ones. There's also Pay by Link for taking payments remotely, without charging more just because the sale wasn't in person.
Ecommerce payment processing explained: what to remember
Ecommerce payment processing looks complicated from the outside, but what it really is is a handful of key players: a gateway, a processor, the card networks, and two banks, all working together. By cooperating in the background, your customer's card gets checked, your money lands where it should, and the sale is done- simple as that.
As a business owner, the part you’re responsible for is who you choose to run it. Get that right, and the rest (like those candle sales from the very start of this) just quietly takes care of itself.
Frequently Asked Questions
- How long does it take to receive funds from an online sale?
-
Once a payment is approved, funds typically move from the customer's bank to your business's bank within one to a few business days, depending on your provider and how your account is set up.
- Do I need a different payment processor for my online store and my physical till?
-
Not necessarily, some providers, including Epos Now, let you run both online and in-person sales through the same system, so your payments, stock, and reporting all stay in sync rather than living in two separate places.
- What is 3D Secure, and why does my checkout ask for it?
-
3D Secure is an extra verification step (like a one-time code sent to the customer's phone) designed to confirm the person paying is really the cardholder. It's a legal requirement for most online card payments in the UK, Ireland, and the EU. In the US, there's no equivalent legal mandate, though it's still widely used, since card networks encourage adoption by shifting fraud liability away from merchants who use it.
- Why was my customer's payment declined?
-
A decline usually comes from the issuing bank (the customer's own bank), not your payment provider. Common reasons include insufficient funds, a card expiring, incorrect details being entered, or the bank's own fraud checks flagging the transaction as suspicious.