Take card and Direct Debit payments online
How online card and Direct Debit payments work on your storefront, and where the money and data actually go.
This article is for operators — an overview of how your storefront takes payment, and where card and bank data actually goes (short answer: not to us).
Card payments
Card payments are collected through an embedded, PCI-compliant payment form on your checkout. Card numbers are entered directly into that form and go straight to our payment provider — your customer's card details never touch StoreBay's own systems. We only ever store a reference to a saved card, never the card itself. This keeps your storefront out of the highest-risk PCI category without you having to do anything extra.
A customer's first card payment is verified with their bank (sometimes with a one-time confirmation step on their end); future recurring payments then happen automatically without repeating that step, unless their bank specifically asks for it again.
Direct Debit payments
Direct Debit (Bacs) works through a hosted setup page from our Direct Debit provider — again, your customer's bank details go directly there, not to StoreBay. Because Direct Debit isn't instant, every collection follows advance notice and a working-day clearing period; see Understanding your first Direct Debit collection for what your customer experiences.
Choosing what to offer
You can offer card, Direct Debit, or both at checkout. Many operators default new customers toward Direct Debit for ongoing licence fees, since it doesn't need re-authentication for recurring payments — but the choice, and what your customers see, is yours to configure.
Payouts to you
Each operator collects into their own connected account with our payment providers — payments for your sites go to you, not through a shared pool. Payout timing and reconciliation with your accounting package are covered in Connect your accounting package.
Who to contact
If a customer's payment fails in a way that doesn't match the reasons above, or a payout looks wrong, contact support with the reference and we'll look into it.