Skip to content
Thursday, October 1, 2026 · Global Edition
NUV Media
PAYMENTS · FINTECH · BANKING
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
NUV Media

How Online Payment Processing Actually Works Behind the Scenes

A single card payment crosses at least four companies between checkout click and settled funds. Here is the route, and where the fees sit along it.

How Online Payment Processing Actually Works Behind the Scenes
How Online Payment Processing Actually Works Behind the Scenes

When a customer clicks “pay,” the money does not move. Not yet. What moves first is a message — an authorization request — that bounces through a gateway, a processor, a card network and two banks before anyone's balance changes. The whole round trip usually takes a second or two, and the funds themselves arrive days later.

Understanding that route matters because every party on it charges for its part, and the merchant eats most of the stack. This explainer follows one online payment from click to settlement, names each player, and shows where the delays and the fees actually sit. Merriam-Webster defines “online” as done while connected to a computer or telecommunications system — which is accurate but tells you nothing about who touches the online payment next. That list is below.

Who touches a payment between the click and the bank?

Four parties handle a typical payment, plus the merchant and the customer. The gateway is the checkout software that captures card details and passes them along securely. The processor is the plumbing company: it formats the transaction and routes it to the right network. The card network — Visa, Mastercard or the like — sits in the middle and connects the two . The issuing bank issued the customer's card. The acquiring bank holds the merchant's account.

In practice, some of these roles merge. A large provider may be gateway, processor and acquirer at once. But the functions exist whether they sit under one roof or five, and each function is a place where a fee or a failure can appear.

What happens in the two seconds after checkout?

The sequence is short and always the same:

  1. The customer submits card details. The gateway encrypts them and sends an authorization request to the processor.
  2. The processor routes the request through the card network to the issuing .
  3. The issuer checks the account: funds available, card not reported stolen, no fraud flag. It approves or declines and sends the answer back down the same chain.
  4. The merchant sees the approval and ships the goods. An authorization hold now sits on the customer's card.

That hold is a promise, not a payment. It reserves the amount against the customer's limit but moves no money. Gas stations use the same mechanism with larger amounts, which is why a fill-up can leave a bigger temporary hold than the price on the pump — see how preauthorization holds work at the gas pump.

What is settlement, and why does it take days?

Authorization and settlement are different events. At the end of a business day, the merchant's processor batches the day's approved transactions and submits them for clearing. The card network routes each item to the issuing bank, which posts the charge to the cardholder's account and sends funds — minus fees — toward the acquirer. The acquirer then deposits the money into the merchant's account, typically a couple of business days after the sale.

Bank transfers on automated rails work on a similar lag for the same structural reason: the banks settle with each other in batches, not one transaction at a time. The mechanics differ, but the patience required does not — see how ACH transfers move money between banks and why settlement waits. This connects to our earlier piece, How ACH Transfers Move Money Between Banks and Why Settlement Waits.

Where does the fee actually sit?

The merchant's processing fee is not one fee. It is a stack. The largest layer is interchange, set by the card networks and paid to the issuing bank on every transaction. Its size varies with card type, transaction method and merchant category — the mechanics are unpacked in what interchange fees actually are and who ends up paying them. On debit cards, a regulatory cap applies to large issuers; Regulation II caps debit interchange fees at 21 cents plus a percentage for covered banks.

On top of interchange sit the network's own assessment fees and the processor's markup. That last layer is where pricing gets opaque: flat-rate plans bundle everything into one percentage, while interchange-plus plans show the pass-through costs separately. Either way, the merchant pays the whole stack, and the customer pays it indirectly through prices.

What makes an online payment fail?

Most failures are declines, and every decline carries a code that says why — insufficient funds, expired card, suspected fraud. What those codes reveal determines whether a retry is worth attempting; card decline codes tell merchants about failed payments in enough detail to act on. Fraud screening adds its own friction: card-not-present transactions carry more risk than swiped ones, so issuers and merchants layer extra checks. One common check is 3-D Secure, which shifts fraud liability toward the issuer when the customer completes an extra verification step.

Then there is the failure that happens after the money arrives: the chargeback. A cardholder disputes a charge, the issuer pulls the funds back pending review, and the merchant must argue its case or lose the sale plus a fee. Recurring merchants fight a quieter version of this — cards that expire or fail silently — which is why subscription businesses run recovery flows; dunning keeps subscriptions alive when cards fail.

What this means for merchants choosing a setup

Our analysis of the route points to three practical checks. First, ask a prospective processor to show the fee stack line by line — interchange, assessments, markup — because a single blended rate hides which layer is expensive. Second, ask what happens at settlement: when funds land, what happens on a refund, and what a chargeback costs end to end. Third, ask about failure handling, since every declined transaction is a lost sale until proven otherwise.

Merchants running many providers through a single routing layer get more control over exactly these questions; payment orchestration layers let merchants route transactions across providers and compare outcomes. And for payments that cross borders, the same chain adds currency conversion and correspondent banks — with a markup tucked into the exchange rate; the FX markup hides in the rate itself.

Where the rails go next

The card chain described here is not the only rail anymore. Account-to-account transfers are moving faster as instant-payment systems come online, and regulators keep pressing on interchange and routing rules — the policy fight around card routing is tracked in coverage of the Credit Card Competition Act. None of that changes the core structure a merchant should understand first: authorization is instant, settlement is not, and every hop in between is a business charging for its part of the path.

The evidence for how fast the alternatives are growing comes from the providers themselves — for instance, Zelle's reported volumes reflect the operator's own disclosures, not an independent audit. Treat provider-reported figures accordingly.

Frequently Asked Questions

Is the payment gateway the same thing as the processor?
No. The gateway captures and secures card details at checkout; the processor routes the transaction between banks and networks. Many providers sell both under one contract, but the functions are separate and each can fail or charge independently.
Why does the customer see a charge before the merchant has the money?
Authorization places a hold on the cardholder's available credit or balance immediately, while settlement moves actual funds to the merchant days later. The cardholder's statement shows the pending amount first and the posted charge after the banks settle.
Who pays the interchange fee?
The merchant's side of the transaction pays it as part of the processing fee, and the issuing bank receives it. Merchants typically recover the cost through their prices, so customers pay it indirectly.
Can a payment be approved and still not get paid?
Yes. Approval only guarantees funds are reserved at that moment. A chargeback, a settlement failure, or an issuer reversing the transaction after the fact can still take the money back from the merchant.

Sources

  1. New games - CrazyGames
  2. Free Games
  3. ONLINE Definition & Meaning - Merriam-Webster
  4. Popular Games - Play Online for Free! - Poki

More from our brands

Part of the VUGA Network

Covers payments.