What Does Merchant of Record Mean? Tax, Nexus, and Chargebacks

A Merchant of Record, often shortened to MoR, is the legal entity that a bank authorizes to accept card payments for a given sale and that appears as the seller on the buyer’s statement. Whoever holds that status is the party the card-issuing bank holds accountable for the charge, and along with that accountability comes the tax collection duty, the chargeback exposure, the PCI-DSS compliance burden, and the consumer protection obligations tied to the sale. Understanding what “merchant of record” means matters most when you’re deciding whether to be your own or hand the role to a third party.

What the MoR Is Actually Responsible For

Being the Merchant of Record is not a labeling exercise. The role bundles together a set of legal and financial obligations that attach to whichever entity processes the payment under its own merchant account. Those obligations include collecting and remitting sales tax in every state where the seller has nexus, filing (or receiving) IRS Form 1099-K, absorbing chargebacks and disputes, maintaining PCI-DSS compliance, honoring federal mail and internet order rules, and standing behind implied warranties on the goods sold.

Two entities cannot be the MoR for the same transaction. The status transfers cleanly or not at all, and whichever party holds it inherits the entire package.

MoR vs. Payment Facilitator

The distinction that causes the most confusion is between a Merchant of Record and a Payment Facilitator. They solve different problems, and mixing them up leads to expensive structural mistakes.

A Payment Facilitator (PayFac) provides payment processing infrastructure to sub-merchants under a single master merchant account. The PayFac handles the technical plumbing of moving money, but the original seller remains the legal seller of the goods. The sub-merchant keeps responsibility for its own tax filings, refund policies, and regulatory compliance. Stripe and Square operate largely on this model.

An MoR becomes the legal seller. It takes title to the product at the moment of sale, processes the payment under its own merchant account, and assumes direct liability for tax collection, chargebacks, refunds, and regulatory compliance. Companies like Paddle and FastSpring operate as third-party MoRs for software sellers. The original product creator never touches the payment and never needs its own merchant account. One entity builds the product; another handles the financial and legal machinery of selling it.

Sales Tax and Economic Nexus

Whoever holds MoR status is on the hook for collecting and remitting sales tax. In a country where combined state and local rates range from under 3% to over 10%, that obligation is more complex than it sounds.

The complexity expanded after the Supreme Court’s 2018 decision in South Dakota v. Wayfair, which ruled that states can require remote sellers to collect sales tax even without a physical presence in the state. The threshold South Dakota set, and most states adopted in some form, kicks in once a seller crosses $100,000 in annual sales or 200 separate transactions in that state.1Supreme Court of the United States. South Dakota v. Wayfair, Inc., No. 17-494 Nearly every state with a sales tax now enforces an economic nexus rule along these lines.

For a business acting as its own MoR and selling nationwide, this can mean registering for sales tax permits in dozens of states, calculating the correct rate for each buyer’s location, filing returns on each state’s schedule, and remitting the collected tax. Most states offer free online registration, though a handful charge permit fees up to $100. States can assess back taxes, penalties, and interest on uncollected amounts, and the liability falls squarely on the MoR.

This is one of the strongest reasons businesses use a third-party MoR. When a service like Paddle or FastSpring acts as the legal seller, it assumes the tax nexus obligations. The product creator doesn’t need to register in every state or track rate changes, because the MoR is the entity with the legal obligation to collect.

IRS Form 1099-K Reporting

Federal law requires payment settlement entities to report card and third-party network transactions to the IRS under 26 U.S.C. ยง 6050W.2Office of the Law Revision Counsel. 26 USC 6050W – Returns Relating to Payments Made in Settlement of Payment Card and Third Party Network Transactions Reporting happens through Form 1099-K, and the thresholds depend on the type of entity involved.

For payment card transactions processed through a standard merchant account, there is no minimum threshold. Every dollar settled gets reported. For third-party settlement organizations, including platforms like PayPal or a third-party MoR that aggregates payments for multiple sellers, the reporting threshold was retroactively restored to $20,000 in gross payments and more than 200 transactions in a calendar year. That change, enacted through the One, Big, Beautiful Bill, reversed an earlier law that had dropped the threshold to $600.3Internal Revenue Service. IRS Issues FAQs on Form 1099-K Threshold Under the One, Big, Beautiful Bill

If you act as your own MoR with a direct merchant account, your acquiring bank files the 1099-K reporting your gross payment volume. If you sell through a third-party MoR, that entity receives the 1099-K and handles the reporting relationship. Either way, the IRS sees the money, and businesses that fail to reconcile their 1099-K amounts with their tax returns invite audits.

Chargebacks and Card Network Monitoring

Chargeback liability is where MoR status becomes expensive quickly. When a customer disputes a charge, the card-issuing bank pulls the money back from the MoR’s account immediately and places it in escrow. The MoR then has a limited window to submit evidence proving the transaction was legitimate. Lose the dispute, and the MoR absorbs the sale amount plus a chargeback fee that typically runs $20 to $100 per incident.

Card networks track chargeback ratios closely. Visa’s Acquirer Monitoring Program (VAMP) evaluates merchants processing 1,500 or more card-not-present transactions per month using a combined ratio of fraudulent transactions and disputes divided by total settled transactions. As of April 2026, the threshold for “excessive” status drops to 1.5%. Merchants flagged as excessive pay $8 for every fraudulent or disputed transaction, while those in the “above standard” tier pay $4 per transaction. First-time offenders get a three-month grace period, but repeat violations within 12 months trigger immediate enforcement. At high volumes, those per-transaction fees can dwarf the underlying chargeback losses.

An MoR that lets its chargeback ratio drift risks more than losing individual disputes. Sustained non-compliance can result in termination of the merchant account, cutting off the ability to accept cards at all.

PCI-DSS Compliance and Data Breach Exposure

Any entity that stores, processes, or transmits cardholder data must comply with the Payment Card Industry Data Security Standard, regardless of transaction volume.4PCI Security Standards Council. Merchant Resources – PCI Security Standards Council For an MoR, this means maintaining secure networks, encrypting card data in transit and at rest, restricting access to payment systems, and regularly testing security controls. Small merchants with simple environments face a lighter validation burden than large processors, but the underlying requirement applies to everyone.

Penalties for non-compliance come from the card brands through the acquiring bank, not from the PCI Security Standards Council itself. Fines typically start around $5,000 per month and escalate the longer a merchant remains non-compliant, reaching $100,000 per month or more after six months. A data breach while non-compliant is a different order of magnitude. Card brands can levy fines of $50 to $90 per compromised cardholder record, and a breach affecting tens of thousands of accounts can produce seven-figure liability. Beyond fines, the acquiring bank can terminate the merchant account.

If a breach exposes consumer data, the MoR also faces notification obligations. There is no single comprehensive federal data breach notification law covering all merchants. Instead, all 50 states have their own breach notification statutes, each with different timelines, definitions of covered data, and notification requirements. In a large breach, the MoR must comply with the law in every state where affected consumers reside.

Consumer Protection and Warranty Obligations

Because the MoR is the legal seller, it inherits consumer protection obligations that a product creator working behind a third-party MoR might not expect to see itself. Federal law requires any seller soliciting orders online, by phone, or by mail to ship merchandise within 30 days of receiving a properly completed order, or 50 days if the buyer applied for credit at the time of purchase. If the seller can’t meet that timeline, it must offer the buyer a choice between consenting to the delay or canceling for a full refund.5eCFR. 16 CFR Part 435 – Mail, Internet, or Telephone Order Merchandise Refunds must be sent within seven working days of the cancellation.

The MoR also picks up implied warranty obligations. Under the Uniform Commercial Code, adopted in every state except Louisiana, a merchant who sells goods automatically makes an implied promise that those goods work as expected and have nothing significantly wrong with them.6Federal Trade Commission. Businessperson’s Guide to Federal Warranty Law Selling a product “as is” can disclaim some implied warranties, but it does not shield the seller from product liability claims if the product is defective and injures someone. When a third-party MoR takes legal title to goods, these warranty and liability obligations transfer to it.

Being Your Own MoR vs. Using a Third Party

Every online business eventually faces the same choice: act as its own Merchant of Record, or hand that role to a third-party service.

Acting as your own MoR keeps full control over pricing, customer relationships, refund policies, and branding on card statements. It also carries every obligation described above directly. You register for sales tax across all nexus states, maintain PCI-DSS compliance, manage chargebacks, meet consumer protection rules, and coordinate 1099-K reporting with your acquiring bank. For high-volume businesses with the operational infrastructure to manage compliance, this is often the more cost-effective path, because you avoid the revenue share a third-party MoR charges.

A third-party MoR takes legal title to the product at the instant of sale and resells it to the end customer. That brief transfer of ownership is the legal mechanism that shifts tax nexus, chargeback liability, and regulatory compliance off the product creator’s plate. The third-party MoR calculates and remits sales tax, handles disputes, manages PCI compliance, and deals with consumer protection obligations. The product creator receives a payout minus the MoR’s fee, which typically ranges from 5% to 15% of the transaction depending on volume and services included.

Reserve Funds Tie Up Cash

One cost that catches new merchants off guard is the reserve fund. Acquiring banks routinely withhold a percentage of each day’s transactions in a separate account to cover potential chargebacks and refunds. Reserve rates typically run 5% to 10% of daily settlement volume, held for 30 to 180 days before being released. Businesses in industries with higher chargeback rates, such as travel, subscription services, and digital goods, face reserves at the upper end of that range or higher. A business processing $10,000 per day at a 10% reserve has $1,000 per day locked up, and at a 180-day hold, that’s $180,000 in tied-up capital at any given time. Third-party MoRs absorb this cash flow hit themselves, which is another reason their fees run higher than simple payment processing costs.

Read the Indemnification Clauses

Whether you use a third-party MoR or sign a direct merchant agreement with an acquiring bank, the indemnification clauses deserve careful attention. A standard indemnity provision requires one party to compensate the other for losses from things like contract breaches, regulatory non-compliance, or third-party injury claims. In a third-party MoR arrangement, the MoR typically indemnifies the product creator against payment-related liabilities, but the product creator indemnifies the MoR against claims arising from the product itself, including defects, intellectual property infringement, or misleading marketing. Signing an MoR agreement without reading the indemnification section can mean accepting liability you thought you’d transferred.

Cross-Border Sales Multiply the Burden

Selling internationally multiplies the MoR’s compliance obligations. More than 170 countries impose some form of value-added tax or goods and services tax on digital goods and services, and a growing number require the platform or marketplace facilitating the sale to collect and remit that tax as a “deemed seller.” The European Union’s VAT in the Digital Age proposal will treat digital platforms as the deemed seller for VAT purposes on certain services starting in July 2028. Switzerland already treats any entity facilitating goods sales through an electronic interface as the seller for VAT purposes. Saudi Arabia requires online marketplace operators to charge 15% VAT on transactions involving unregistered sellers.

For a business trying to sell software or digital services globally while acting as its own MoR, managing VAT registration and remittance in dozens of countries is a serious operational burden. A global MoR that already holds VAT registrations in key markets and has systems to calculate the correct rate per jurisdiction removes what would otherwise be a full-time compliance operation from the product creator’s workload. If your business sells across borders at any real scale, this is where the “what does merchant of record mean” question stops being definitional and becomes a decision about how much compliance work you want to own.