A payment gateway is the software layer that captures a customer's card details at checkout, encrypts them, and transmits them to the payment processor for authorisation. Think of it as the online equivalent of the card terminal in a shop: it moves payment data securely, but it does not itself move money or hold your funds. Every card sale needs both a gateway to carry the data and a processor to settle it.
A customer enters their card at checkout. The gateway encrypts that data and sends it to the processor, which asks the customer's issuing bank whether funds are available. The bank approves or declines, the answer travels back through the processor to the gateway, and the buyer sees "approved". Security bodies note that gateways typically layer encryption, tokenisation and fraud checks so raw card numbers are never exposed. Stripe's own explainer frames the gateway as the technology that securely transmits card data to the processor for authorisation.
These get confused because you rarely see one without the other. The distinction is simple: the gateway carries the data, the processor moves the money. The gateway collects and secures the card details at the point of sale; the processor authorises the transaction and settles funds between the issuing and acquiring banks. As NerdWallet's breakdown puts it, the two are interdependent - you need both for a single online transaction to complete.
Gateway, processor, acquirer and merchant account are four separate roles. Traditionally you would source and stitch them together yourself, then wait on underwriting for the account. A payment facilitator collapses all of that: it already holds the acquirer relationship and the master merchant account, and it fronts the gateway and processing for every sub-merchant it onboards. That is why "do I need a gateway?" is usually the wrong question for a modern builder - you need a provider that brings all four.
If you are shipping a product, you do not want to license a gateway, contract a processor and open a merchant account as three projects. paas.build is a productised PayFac built on UniPaaS (an FCA-authorised Payment Institution, No. 929994): the gateway, processing, your own sub-merchant account and payouts arrive as one flat 3.9%. One prompt, an embedded checkout, live the same day via progressive KYB - and you stay the merchant of record, so the money settles to you.
The gateway captures and encrypts the card data at checkout and passes it on; the processor authorises the transaction and moves the funds between the issuing and acquiring banks. Every online card payment needs both, and they work together on each transaction.
No. paas.build bundles the gateway, processing, sub-merchant account and payouts into one flat 3.9%. You embed a hosted checkout or drop-in component and the gateway is handled for you - nothing to license or integrate separately.
A reputable gateway is built to the PCI DSS standard and uses encryption and tokenisation so raw card numbers never touch your servers. On paas.build the checkout is hosted, so the card data stays within the PCI-compliant, FCA-authorised UniPaaS environment.
No. A pure gateway only transmits data. Funds settle through the processor and acquirer to a merchant account. With paas.build you are the merchant, so the money settles to you and pays out to your bank on schedule.