You can accept payment several ways - cash, checks, bank transfers, and cards through a processor or point-of-sale system - and most small businesses end up using more than one. The right mix depends on how you sell (in person, online, or both), how fast you need the money, and how much risk and paperwork you're willing to take on. This guide walks through the main options, what a payment processor actually does, and the security and money-handling responsibilities that come with taking cards.
Your options for getting paid
Cash. No processing fee, no chargeback risk, money in hand immediately - but you carry the burden of physical security, making change, and accurate recordkeeping, and some customers simply don't carry cash anymore.
Checks. Cheap to accept but slow to clear, and a check can bounce after you've already delivered goods or services. Business checks are more common in B2B transactions than in retail.
ACH / bank transfer. Money moves directly from the customer's bank account to yours. ACH transfers typically cost less than card transactions and work well for recurring payments (like invoices or subscriptions), but they usually take a day or more to settle and carry their own return risk if the customer's account has insufficient funds.
Cards via a payment processor or point-of-sale (POS) system. A processor authorizes the transaction with the customer's card network and bank, then moves the funds into your account, usually within one to a few business days. A POS system is often the hardware and software layer (the terminal, the checkout screen, the receipt printer) sitting on top of a processor.
Online checkout. If you sell online, you need a way to securely collect card or bank details on your website or app and route them to a processor. This can be a hosted checkout page (the customer is briefly sent to the processor's own secure page) or an embedded checkout built into your site.
Getting paid on time is its own recurring challenge separate from choosing a payment method - late-paying customers and collecting on unpaid invoices is covered in the getting paid guide.
How processing fees actually work
Card processing isn't free. A processor's fee generally reflects a few layered costs: an interchange fee set by the card network and paid to the customer's issuing bank, a smaller assessment fee paid to the card network itself, and the processor's own markup for the service. On top of that, many processors charge a flat per-transaction fee, and some add monthly account fees, statement fees, PCI compliance fees, or equipment costs for a terminal.
Rates vary a great deal by provider, by card type (a rewards or corporate card often costs more to process than a basic debit card), by how the card is entered (a card that's tapped or inserted in person is generally cheaper to process than a number typed in online, because in-person transactions carry less fraud risk), and by your industry's overall risk profile. Because of that variation, this guide won't quote specific rates - any number you see quoted elsewhere is provider- and contract-specific, and processors are not required to price things the same way. What you can do is ask any processor you're considering for a full written breakdown of every fee, in plain language, including what happens if your monthly volume is unusually low or unusually high, before you sign a contract.
What to do when comparing processors
Ask for the complete fee schedule in writing, not just a headline rate - including monthly fees, per-transaction fees, chargeback fees, and any early-termination or equipment costs.
Ask how quickly funds settle into your bank account, and whether that timeline changes for new accounts or high-risk categories.
Ask directly about reserve and hold policies (below) before you sign, not after your funds get held.
Confirm what level of PCI DSS support the processor provides - a hosted checkout or PCI-validated terminal generally reduces your own security burden.
Read the contract term and cancellation terms, since some processor agreements auto-renew or charge an early-termination fee.
PCI DSS: your security responsibility for card data
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements created by the major card networks' council, not a federal statute - but it functions like a mandatory rulebook because card networks and processors contractually require any business that accepts, processes, stores, or transmits cardholder data to comply with it. That obligation applies to your business directly, even though the processor also has its own compliance duties. Depending on how many transactions you process, you may be able to complete a shorter self-assessment questionnaire rather than a full outside audit, but the underlying security duties - protecting stored data, restricting who can access it, using secure networks, and keeping systems updated - apply regardless of your size.
In practice, most small businesses reduce their PCI burden by never touching raw card numbers at all: using a processor's own point-of-sale terminal, a hosted checkout page, or a tokenized payment form means the sensitive data goes straight to the processor rather than through your own systems. If you ever do handle, email, write down, or store card numbers yourself, you take on a much larger share of the security obligation - and a data breach can expose you to card-network fines, breach-notification duties, and reputational harm on top of the underlying loss. If your business handles any stored payment data, it's worth having a knowledgeable IT professional or your processor's support team confirm your setup meets current PCI DSS requirements, since the standard is periodically updated.
Chargebacks
A chargeback happens when a cardholder disputes a charge directly with their card-issuing bank, and the bank reverses the payment - pulling the money back out of your account - rather than the customer simply asking you for a refund. Common reasons include a customer not recognizing the charge, believing goods or services weren't delivered as promised, or claiming the card was used without their authorization.
You generally have the right to contest a chargeback by submitting evidence - receipts, delivery confirmation, signed agreements, correspondence with the customer - but each processor sets its own deadline and documentation requirements, and there's usually also a chargeback fee regardless of the outcome. A pattern of frequent chargebacks can also affect your standing with a processor, sometimes triggering a reserve requirement or even account termination. Keeping clear transaction records, accurate item descriptions, and easy-to-reach customer service reduces both the number of disputes you get and your odds of winning the ones that happen.
Reserves and holds on your money
Many processor agreements give the processor the right to hold back a portion of your funds, or pause payouts entirely, as protection against future chargebacks or fraud - often called a reserve. This is a business risk-management practice built into your contract with the processor, not a government requirement. It tends to come up more for new accounts without a payment history, businesses in higher-risk industries, sudden spikes in sales volume, or accounts with an elevated dispute rate. Reserve terms - how much may be held, for how long, and under what conditions funds get released - are set out in the processor's merchant agreement, so read that section closely before you sign, and ask directly what would trigger a hold in your specific situation.
Sales tax still applies, no matter how you get paid
Whichever payment method a customer uses, it doesn't change your underlying duty to collect sales tax on taxable sales where your state and local rules require it. A payment processor moves money; it generally does not calculate, collect, or remit sales tax for you unless you've specifically configured your point-of-sale or e-commerce platform to do that as a separate feature. Which sales are taxable, what rate applies, when you need to register, and how often you must file all vary by state - and sometimes by city or county - so confirm the current rules with your state's tax agency rather than assuming your last state's rules (or a competitor's practice) applies to you. The sales tax guide covers registration and collection in more depth.
Putting it together
There's no single right combination of payment methods - a lot of small businesses accept cash and cards in person, add ACH for larger invoices, and layer in online checkout if they sell remotely. The more important habits are the same regardless of which processor you pick: get fee terms in writing, understand your PCI security responsibilities before you ever touch card data, know how disputes and reserves work under your specific contract, and remember that collecting the money and collecting sales tax on that money are two separate obligations you still have to handle. For anything significant - a contract you don't understand, a large hold on your funds, or a sales-tax question specific to your state - a qualified attorney or CPA, or free help from your local Small Business Development Center or SCORE, is worth the call.
This is general business information, not legal, tax, or financial advice.
Frequently asked questions
Do I have to accept credit cards?
No federal law requires a business to accept cards. Some states and cities go the other direction and restrict businesses from refusing cash, and those laws are changing, so check your current state and local rules before going cashless. Whatever you accept, post your policy clearly at checkout.
Is a payment processor the same thing as a merchant account?
Not always. A traditional merchant account is a dedicated account with an acquiring bank set up just for your business. Many small businesses instead use an aggregator-style processor that runs many merchants through one shared account. Both can move card money into your bank account; they differ in setup, underwriting, and how disputes and holds are handled.
Who is responsible if customer card data gets stolen from my business?
You are, at least in part. PCI DSS puts security obligations on any business that accepts, stores, or transmits card data, even when a processor handles the actual transaction. Using a reputable processor's hosted checkout or terminal reduces what you have to secure yourself, but it doesn't erase your responsibility to handle receipts, records, and access to any stored data carefully.
Can a processor hold onto my money?
Yes. Many processors reserve the right to hold a portion of your funds for a period of time, or pause payouts, if they see high dispute rates, a sudden volume spike, or other red flags in your account. Reserve and hold terms are set out in your processor agreement - read that section before you sign up, not after funds get held.
Does the payment processor handle my sales tax for me?
Generally no. Unless you specifically set up sales tax collection through your point-of-sale or e-commerce platform, the processor just moves the payment - it doesn't calculate, collect, or remit sales tax on your behalf. You're still responsible for registering, collecting the right amount, and filing under your state's rules.
This article is general legal information, not legal advice, and may not reflect the most current law or the law in your jurisdiction. Laws vary by state and change over time. For advice about your specific situation, consult a licensed attorney.
Knowing your rights is the first step
Join thousands committing to calmly and consistently exercise their constitutional rights.