How Do Online Payments Work? Steps, Delays, and Protections

Online payments work in two stages: authorization, where your bank confirms in a few seconds that you can pay and places a hold on the funds, and settlement, where the money actually moves to the merchant a day or two later. Between those two stages, your card details pass through a payment gateway, a processor, a card network, and your issuing bank, with fraud checks running at every step. Federal law then decides what happens if something goes wrong, and the rules are meaningfully different depending on whether you paid with a credit card or a debit card.

Who Handles Your Payment

A single online card purchase involves at least six parties, each with a specific job:

  • You, the cardholder.
  • The merchant selling the product.
  • The payment gateway, which encrypts your card details at checkout and forwards them into the processing network. Most online stores have this built into their e-commerce platform.
  • The payment processor, which routes transaction data between the merchant’s side and the card networks. Some processors also act as payment facilitators, letting small businesses accept cards under a shared master merchant account instead of setting up their own. Stripe and Square work this way.
  • The card network — Visa, Mastercard, American Express, or Discover — which sets the rules and routes messages between the banks.
  • The issuing bank, which issued your card and decides whether to approve or decline.
  • The acquiring bank, which holds the merchant’s account and receives the settled funds.

All of them touch the transaction in real time during authorization, and most are involved again during settlement. If a dispute comes up later, working out which party made the error usually points to how it gets resolved.

What You Send at Checkout

Typing your card details into a checkout form gives the system four pieces of data: the card number (usually 16 digits), the expiration date, the three- or four-digit security code printed on the card, and your billing address. The card number tells the network which issuing bank to contact. The security code helps confirm you have the physical card, since that code isn’t stored on the magnetic stripe or embedded in the chip, and it shouldn’t sit in any merchant’s database.

Your billing address gets checked through an Address Verification System that compares what you entered against the address your bank has on file. A mismatch doesn’t always kill the transaction, but it can push the purchase into manual review or trigger a decline.

The 3D Secure Check

Many online transactions now pass through 3D Secure, a protocol that adds a layer of identity verification between you and your card issuer. The current version runs mostly in the background, analyzing your device, location, and transaction history. If everything looks normal, the purchase goes through with no extra steps. If the system flags the transaction as higher risk, you’ll be prompted to verify your identity with a one-time code sent by your bank or a biometric check like a fingerprint. When a transaction passes this authentication, fraud liability shifts from the merchant to the issuer, which is why more merchants have adopted it.

What Happens the Moment You Click Place Order

The gateway encrypts your card data and sends it to the processor. The processor forwards the request through the card network to your issuing bank. Your bank then runs a series of checks: Is the account open and in good standing? Are there enough funds or available credit? Does the purchase match your usual spending, or does it look like fraud?

If everything checks out, the bank sends an authorization code back through the same chain. That code is a promise to hold the purchase amount, not an actual transfer of money. The merchant sees an approval, fulfills the order, and the hold on your account shows up as a “pending” charge on your statement. The whole round trip usually finishes within a few seconds.

The Electronic Fund Transfer Act sets the legal framework for these electronic transfers, defining consumer, bank, and intermediary rights.1Office of the Law Revision Counsel. 15 USC 1693 – Congressional Findings and Declaration of Purpose

Why a Transaction Gets Declined

Insufficient funds get the most attention, but they’re only one of many reasons a purchase can fail. The merchant usually sees a generic error code, not the full explanation. Beyond insufficient funds, the common reasons include:

  • A new card that was mailed but never activated through the bank’s phone or app.
  • An expired card, even if the replacement is sitting in your wallet with dates you haven’t entered.
  • A security code mismatch, which happens more often than you’d expect with manual entry.
  • Fraud filters catching a purchase that falls outside your normal pattern: an unusually large amount, a country you’ve never bought from, or several transactions in quick succession.
  • Transaction limits set by your bank or card program that the purchase would exceed.
  • A lost or stolen flag on the account, which freezes the card.

If your card is declined and you know the account is funded, calling the number on the back of the card is almost always faster than re-entering information or trying another browser. The bank can tell you exactly why the transaction was blocked and often release the hold while you’re on the phone.

Why the Money Doesn’t Move Instantly

Authorization reserves the money. Settlement is what actually moves it, and the gap between them is where most confusion lives.

Throughout the day, the merchant collects authorization codes for every approved sale. At a scheduled cutoff, the merchant submits these authorizations as a batch to its acquiring bank. The acquiring bank sends the batch through the card networks, which route each transaction to the appropriate issuing bank for actual fund transfer. The issuing banks release the held funds, and the money flows to the merchant’s acquiring bank, minus fees. Most domestic transactions settle within one to three business days after the batch is submitted.

That’s also why the amount that reaches the merchant is less than what you paid. Fees come out of every settled transaction, including an interchange fee to the issuing bank, an assessment fee to the card network, and a markup to the processor. For debit cards subject to the Federal Reserve’s interchange cap, the average interchange fee across all networks was about 0.73% of transaction value in 2024.2Federal Reserve. Average Debit Card Interchange Fee by Payment Card Network

What You’re Protected Against If Something Goes Wrong

The federal protections you get when a charge is unauthorized or disputed depend heavily on whether you paid with a credit card or a debit card. This is the single biggest reason financial advisors tend to recommend credit over debit for online purchases.

Credit Card Charges

Credit card disputes fall under the Fair Credit Billing Act, which caps your liability for unauthorized charges at $50. In practice, every major card issuer waives even that amount as a matter of policy.3Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card There is no tiered system based on how fast you report. As long as the unauthorized use happened before you notified the issuer, your maximum exposure is $50 by law. You have 60 days from the date the first bill containing the error was sent to submit a written dispute to preserve your rights under the statute.4Federal Trade Commission (FTC). Using Credit Cards and Disputing Charges

Because a credit card charge is the issuer’s money until you pay your statement, a disputed charge doesn’t drain your bank account while the investigation plays out.

Debit Card Charges

Debit cards pull directly from your checking account, and the federal protections are weaker and time-sensitive. Under the Electronic Fund Transfer Act, your liability depends on how quickly you report:5Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability

  • Report within 2 business days of learning about the loss or theft, and your liability caps at $50.
  • Report after 2 business days but within 60 days of your statement, and your liability jumps to $500.
  • Report after 60 days from your statement, and you could be on the hook for the full amount of unauthorized transfers that occur after that 60-day window.

Regulation E requires the bank to investigate a reported error within ten business days of receiving your notice. If the bank can’t finish inside that window, it can take up to 45 days, but it has to give you provisional credit within those first ten business days while the investigation continues.6eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors Provisional credit doesn’t change the fact that unauthorized debit transactions pull real money out of your account first. If your rent check bounces because a fraudster drained your account three days before you noticed, the credit won’t undo the overdraft fees.

How Your Card Data Is Kept Safe

Any business that accepts, processes, or stores card data has to comply with the Payment Card Industry Data Security Standard, known as PCI DSS. The current version (4.0) requires merchants to encrypt cardholder data, restrict internal access to payment information, keep security software up to date, test their networks for vulnerabilities, and train staff on data handling. Smaller merchants usually satisfy these requirements through annual self-assessment questionnaires; larger ones undergo formal audits. Most online merchants reduce their compliance burden by using a gateway or facilitator that handles card data on their behalf, so the actual card numbers never touch the merchant’s own servers.

Tokenization adds another layer. When you save a card on a merchant’s website or app, the system replaces your real card number with a randomly generated token. The token works only for that specific merchant and has no value if stolen. Your actual card number stays locked in the processor’s secure vault, and the merchant never stores it. This is why a data breach at an online retailer doesn’t automatically mean your card number was exposed. If the merchant used tokenization, what the attackers took was a string of meaningless characters.