Skip to main content

Choosing Payment Methods

TL;DR
  • US e-commerce baseline: Cards + Apple/Google Pay + PayPal. Add BNPL if AOV >$50.
  • B2B/SaaS: Cards + ACH. Wires for $50K+. SEPA DD for EU recurring.
  • Global: Cards + major wallets + 1-2 local APMs per priority market.
  • Payouts: ACH (cheap, slow) vs RTP/FedNow (instant) vs push-to-card (instant to any debit card).
  • Pay-ins and payouts have different fraud profiles. Pay-in is chargebacks and friendly fraud. Payout is ATO and misdirected payments.

You're balancing four things: customer preference, cost, fraud exposure, and operational complexity. Here's how to decide.


The Decision Framework

1. Customer Preference

What do your customers want to use? Refuse it and you'll lose sales. Survey data and benchmarks help, but your own abandonment rates help more.

2. Economics

Work out the true cost per method:

  • Direct fees (interchange, processing)
  • Fraud losses and chargebacks
  • Settlement timing, which is a cash flow cost
  • Operational overhead

3. Fraud Profile

Every method has its own fraud profile. Your risk tolerance shapes what you accept, and so does what your tools can catch.

4. Integration Complexity

Some methods take real engineering time, so weigh that cost against the expected benefit.

5. Settlement Needs

Cash flow tight? Favor the faster-settling methods, or pay for accelerated settlement.

6. Pay-ins vs Payouts

Think about pay-ins and payouts separately. Pay-ins are how customers pay you, and payouts are how you send money out. The best rails differ:

Pay-ins (receiving money):

  • Cards + wallets + BNPL for consumer checkout
  • ACH / SEPA Direct Debit for recurring and B2B
  • Local APMs for international markets

Payouts (sending money):

  • ACH for standard payouts, cheap and 1-2 days
  • RTP / FedNow for urgent or instant payouts
  • Push-to-card (Visa Direct / Mastercard Send) for instant-to-debit-card UX
  • Wires for large, urgent, or international

Different fraud profiles. Pay-in fraud is stolen credentials and chargebacks, while payout fraud is ATO and misdirected payments. A marketplace needs strong controls on both sides.


The Cannibalization Problem

Adding payment methods doesn't automatically mean more sales. A lot of the adoption is existing customers switching, not new customers converting.

Why This Matters

You add BNPL and see 1,000 BNPL transactions in month one. That's not 1,000 new sales. It might be:

  • 300 genuinely new conversions, customers who wouldn't have bought
  • 700 existing customers who'd have paid with a card anyway

BNPL costs you 5% and cards cost 2.5%. On those 700 transactions you've just paid an extra 2.5% for nothing.

How to Measure Cannibalization

Before launching a new method:

  • Baseline your conversion rate, AOV, and payment method mix
  • Track cart abandonment by stage

After launching:

  • Compare total conversion rate, not just new method adoption
  • Watch for drops in other payment method usage
  • Calculate true incremental revenue: New method revenue × (1 - cannibalization rate)

Warning signs of pure cannibalization:

  • Total conversion rate unchanged despite new method adoption
  • Card transaction count drops in step with new method growth
  • Same customers switching methods month over month

Quick Example

Before BNPL launch:

  • 10,000 orders/month
  • 95% cards, 5% PayPal
  • 2.8% blended payment cost

After BNPL launch:

  • 10,200 orders/month, up 2%
  • 80% cards, 5% PayPal, 15% BNPL
  • 3.2% blended payment cost

The math:

  • 200 incremental orders × $80 AOV = $16,000 new revenue
  • 1,500 orders switched to BNPL × $80 AOV × 2.5% cost increase = $3,000 extra cost
  • Net benefit: $16,000 - $3,000 = $13,000, assuming ~30% margin on new orders

In this case, BNPL is worth it. But if you only got 50 incremental orders? The math flips negative.

Hidden Costs of More Methods

It doesn't have to cost more per transaction to cost you:

Reconciliation complexity

Each payment method you add is one more data source to reconcile. Five methods means five reconciliation streams, five sets of edge cases, five vendor relationships.

Subscription/recurring limitations

Methods don't all handle recurring equally:

  • Cards: excellent (card-on-file, account updater)
  • ACH: good (mandates persist)
  • PayPal: good (billing agreements)
  • BNPL: poor (built for one-time, not recurring)
  • Crypto: very poor (no recurring mechanism)

Running a subscription business? A method that handles recurring badly means customers can't easily subscribe. Or you're handling payment method changes at every renewal.

Refund complexity

Refunds don't work the same way everywhere:

  • Cards: straightforward, same rails
  • ACH: ACH credit back, or a check if the account closed
  • BNPL: coordinate with the provider, unwind the installments
  • Crypto: which currency? At what rate? To which wallet?
  • Vouchers and cash methods: usually manual, or store credit

One-click / conversion optimization

You've tuned your card checkout for one-click. A new method that needs a redirect, a login, or verification may:

  • Cut overall conversion. More choices means more friction.
  • Train customers onto slower methods
  • Break A/B tests and conversion work already done

When Cannibalization Is Acceptable

Sometimes it's fine, and here's when.

Cost reduction

Customers switch from cards at 2.5% to ACH at 0.3%, and you've saved money with zero new sales. Calculate: Transactions × cost difference = savings.

Fraud reduction

High-fraud customers switch from raw card entry to Apple Pay, and your fraud losses drop.

Customer preference

Customers who strongly prefer a method you don't offer may still buy, but they won't be happy about it. Offering it lifts NPS even with no conversion lift.

Competitive necessity

Every competitor offers BNPL and you don't, so you may lose the customer entirely. The math is "cannibalize yourself or lose them."

The Right Approach

  1. Don't add methods speculatively. Have a hypothesis about who'll use it and why.
  2. Measure incrementality. Track total conversion, not just new method adoption.
  3. Count the total cost. Ops overhead, not just transaction fees.
  4. Sunset underperformers. If a method adds complexity and no incrementality, it's gone.
  5. A/B test when you can. Show the new method to a subset and compare total conversion.

Payment Method Matrix

MethodCostSpeedFraud RiskChargeback RiskBest For
Credit CardHighT+2-3Medium-HighHighRetail, e-commerce
Debit CardMediumT+1-2LowerMediumRetail, everyday purchases
ACHLowT+1-2DifferentReturns (60 days)Recurring, B2B
RTP/FedNowLowInstantEmergingNoneUrgent disbursements
Digital WalletsMediumT+2-3LowerHigh (via card)Mobile, e-commerce
BNPLHighT+1-2LowerProvider handlesFashion, discretionary
WireFlat feeSame dayHigh (social engineering)NoneLarge B2B

Fraud, Risk, and Conversion Matrix

MethodTypical CostFraud PatternDispute MechanismConversion Impact
Credit Card (CNP)1.89-2.60% + $0.10 interchangeStolen cards, synthetic ID, card testingNetwork chargeback (120 days)Baseline for e-commerce
Credit Card (CP)1.51-2.30% + $0.10 interchangeLost/stolen, counterfeit (reduced by EMV)Network chargeback (120 days)Baseline for retail
Debit Card0.05% + $0.21 regulated, 0.70-0.80% + $0.15 exemptATO, lost/stolenNetwork chargeback + Reg E (60 days)Slightly lower than credit
PrepaidSimilar to exempt debitLow for merchants (mule risk in specific verticals)Network chargeback availableNeutral to slightly lower
Card-Token WalletsSame as card (often CP rates)Very low (tokenization + biometrics)Standard card chargebackStrong uplift on mobile
Online Account Wallets3.49% + $0.49ATO at wallet levelWallet provider dispute (buyer-friendly)Strong (saved credentials)
P2P Wallets2.75-3.49%ATO, social engineeringComplex (wallet + underlying funding)Strong with young US demos
ACH Debit$0.20-1.00Unauthorized debits, ATOACH returns (R10/R29), 60 daysLower (bank login friction)
ACH Credit$0.20-1.00BEC, misdirected paymentsVery limited (push payment)N/A (push, not checkout)
Pay by Bank (US)0.5-1.5%ATO, social engineeringACH returns (if ACH-based)Lower (friction), improving
Open Banking (UK/EU)0.1-0.5%ATO (mitigated by SCA)Very limited (push)Lower than cards, improving
RTP/FedNow$0.01-0.05Social engineering, BECNone (irrevocable)N/A (mostly disbursements)
Push-to-Card0.5-1.5%ATO, misdirected payoutsNone (irrevocable)N/A (payouts only)
Wire$25-40 flatBEC, vendor impersonationNone (irrevocable)N/A (B2B only)
BNPL2-8%First-party "never pay," return abuseProvider handlesStrong uplift
Crypto via PSP1-2%Compromised wallets, AML exposureNone (complaints only)Niche
Mobile Money1-3%SIM swap, social engineeringProvider-specificEssential in market
Carrier Billing15-30%SIM swap, unauthorized chargesCarrier dispute processExcellent for digital content
eCash/Vouchers2-5%Low (cash payment)None/merchant policyLower (must pay at store)
SEPA Direct Debit€0.20-0.50Unauthorized mandates8-week no-questions refundGood for EU recurring

Don't read straight down that cost column. The card rows are interchange, the network's cost before your processor's markup. The wallet, BNPL and carrier rows are the provider's all-in merchant rate, markup included. They aren't the same measurement. Card interchange comes from Visa's US schedule of 18 April 2026 and Mastercard's of 17 April 2026. Blended across a normal card mix, that's about 0.89% + $0.158 in person and 1.36% + $0.152 online. The derivation is published.


Fraud Pattern Details by Method

Card-Not-Present (CNP) Credit

  • Primary attack: stolen credentials from breaches and dark web purchases
  • Secondary: synthetic identity, built from mixed real and fake data
  • Pattern: high-velocity testing, then larger purchases reshipped to mules
  • Mitigation: 3DS, AVS, CVV, velocity limits, device fingerprinting

Card-Token Wallets (Apple Pay, Google Pay)

  • Fraud rates run 50%+ lower than raw CNP
  • Tokenization kills stored credential theft
  • Biometric authentication blocks unauthorized use
  • Main risk: social engineering to add a stolen card to the wallet, called provisioning fraud
  • Mitigation: network and issuer controls at provisioning, device binding

Online Account Wallets (PayPal, Skrill)

  • Primary attack: account takeover via credential stuffing and phishing
  • Secondary: first-party "item not received" claims
  • Pattern: ATO, change the shipping address, buy high-value items
  • Disputes: the wallet provider decides, and usually leans buyer-friendly
  • Mitigation: wallet-level 2FA, shipping to confirmed addresses

ACH

  • Primary attack: unauthorized debits, a fraudster pulling from a victim's account
  • Secondary: ATO leading to debits that look authorized
  • Return codes: R10 (unauthorized), R29 (corporate unauthorized)
  • Pattern: fraudster gets routing and account numbers, then starts pulling
  • Mitigation: account verification (Plaid and similar), micro-deposits, behavioral analysis

Real-Time Payments (RTP/FedNow/Faster Payments)

  • Primary attack: social engineering, or "authorized push payment" fraud
  • Pattern: the victim is tricked into sending money. Romance scams, invoice fraud.
  • The fraudster targets the sender, not the recipient. Merchants receiving RTP see low fraud.
  • Mitigation: Confirmation of Payee, friction on first-time recipients

BNPL

  • Primary attack: first-party "never pay." The customer never intends to finish the installments
  • Secondary: return abuse. Buy, return, stop payments, keep the refund.
  • Pattern: apply at several providers at once, max out the credit
  • Mitigation: cross-provider data sharing (still emerging), identity verification

Mobile Money (M-Pesa, etc.)

  • Primary attack: SIM swap, where the fraudster takes over the phone number
  • Secondary: social engineering. "Send money to unlock prize."
  • Pattern: SIM swap, drain the wallet, transfer to a cash-out agent
  • Mitigation: carrier security, transaction limits, agent monitoring

Conversion Characteristics

Highest Conversion (vs Baseline Cards)

  • Apple Pay / Google Pay on mobile: 30-50% lift (one-tap, biometric)
  • PayPal, for PayPal users: 30-50% lift (saved credentials)
  • BNPL: 20-40% lift (financing removes the price objection)
  • Stored card / card-on-file: 10-30% lift (no re-entry)

Baseline

  • Credit card with manual entry
  • Debit card with manual entry

Lower Conversion (vs Baseline)

  • Pay by Bank / Open Banking: 10-30% lower (bank login friction, redirect)
  • ACH: 20-40% lower (bank credentials, verification steps)
  • eCash / Vouchers: 30-50% lower (leave the site, go to a store, come back)
  • Crypto: highly variable. Niche audience, heavy friction for everyone else.

You're trading conversion against cost. Lower-cost methods like ACH and Pay by Bank carry a conversion penalty. Higher-converting methods like wallets and BNPL carry a cost premium. Pick for your customer base and your margin.


Rails vs. Products: An Important Distinction

Separate rails from products. Rails are the infrastructure, and products are what your customer actually sees.

Rails (Underlying Infrastructure)

  • Card networks: Visa, Mastercard, Amex, Discover
  • ACH: the Nacha network for US bank transfers
  • RTP: The Clearing House's real-time rail
  • FedNow: the Federal Reserve's real-time rail
  • SEPA: European bank transfer infrastructure
  • Faster Payments: the UK real-time rail
  • PIX: Brazil's instant rail, run by the central bank
  • UPI: India's Unified Payments Interface, run by NPCI
  • SWIFT: messaging for international wires, and not a settlement rail itself
  • Blockchain networks: Bitcoin, Ethereum, Solana

Products (Customer-Facing)

  • Credit, debit and prepaid cards, built on card network rails
  • Apple Pay and Google Pay: a tokenization layer on card rails
  • PayPal and Venmo: account wallets that pull from cards or ACH
  • Zelle: a product built on RTP or bank networks
  • Cash App: cards, ACH, or internal transfers
  • Klarna and Affirm: BNPL products, often funded by cards or ACH
  • "Pay by Bank" products: built on ACH, Open Banking APIs, or local rails
  • Instant card payouts (Visa Direct, Mastercard Send): same card rails, pushed instead of pulled

Why this matters:

  • Fraud and dispute rules come from the rail, not the product
  • A Venmo payment funded by a card falls under card chargeback rules
  • A Venmo payment funded by bank balance follows Venmo's policies
  • When you evaluate a payment method, find out which rail it runs on

Industry-Specific Recommendations

E-commerce / DTC (US Focus)

  • Cards. You don't get a choice
  • Digital wallets: Apple Pay, Google Pay, PayPal
  • BNPL for AOV $50+
  • Local payment methods if you sell internationally

Subscription/SaaS

  • Cards, primary
  • ACH for B2B customers who prefer it
  • Backup payment methods for failed cards

B2B

  • ACH for most transactions, for the cost savings
  • Cards for small transactions and customers who insist
  • Wire for large, urgent payments
  • Level 2/3 data on card transactions

Marketplace

  • Cards and PayPal for buyers
  • ACH for seller payouts
  • Real-time payments if sellers want instant payouts

Healthcare

  • Cards for patient payments
  • ACH for insurance reimbursements
  • Financing or payment plans for large balances

What Should Merchants Actually Use?

Treat this as a default starting stack, then adjust for your business.

US E-commerce / DTC

Must have:

  • Credit and debit cards (Visa, Mastercard, Amex, Discover)
  • Apple Pay and Google Pay
  • PayPal

Add if relevant:

  • BNPL (Klarna, Affirm, Afterpay) if AOV > $50 and the products are discretionary
  • Venmo or Cash App Pay if your demographic skews young US
  • Shop Pay if you're on Shopify. Saved credentials convert well.

Optional / situational:

  • Crypto, only for a crypto-native audience or real demand
  • Pay by Bank. It's cheaper, but it costs conversion. Worth a look on high-ticket items.

Don't bother (usually):

  • Wire transfers. They're not for consumer checkout.
  • ACH direct debit for one-time purchases. Too much friction.

B2B / SaaS / Invoice-Based

Must have:

  • Cards, for smaller invoices and expense-card customers
  • ACH, for larger invoices and recurring payments. The cost savings aren't small.

Add if relevant:

  • Pay by Bank or instant bank verification, which makes ACH setup faster
  • SEPA Direct Debit for EU customers
  • Wire for large one-time payments, over $50K where ACH limits or timing matter

Optional / situational:

  • BNPL or financing, for SMB customers who want to spread payments
  • Crypto, only on meaningful demand. It's rarely worth the complexity.

Operational note: for recurring SaaS, turn on card account updater and dunning. Expired cards are the biggest source of involuntary churn.

Global E-commerce / Marketplaces

Must have:

  • Cards, for global acceptance
  • Major wallets: PayPal, Apple Pay, Google Pay

Add by region:

  • EU: SEPA Direct Debit (recurring), iDEAL (Netherlands), Bancontact (Belgium), PayPal/Klarna (Germany)
  • UK: Open Banking / Pay by Bank, Direct Debit
  • Brazil: PIX (essential), Boleto (declining but still used)
  • Mexico: OXXO (essential for unbanked)
  • India: UPI (essential), Paytm
  • China: Alipay, WeChat Pay (essential for Chinese customers)
  • Southeast Asia: GrabPay, GoPay, local wallets
  • Africa: M-Pesa, MTN MoMo (essential in covered markets)
  • Japan: Konbini, PayPay, JCB

For marketplaces specifically:

  • Real-time payouts. RTP/FedNow for US sellers, Faster Payments for the UK.
  • Local payout rails in each market
  • Payout providers (Stripe Connect, Adyen for Platforms, Payoneer) absorb the complexity

Gaming / Digital Content

Must have:

  • Cards
  • PayPal

Add if relevant:

  • Paysafecard, which matters in gaming, especially the EU
  • Carrier billing (Boku and similar) for mobile games and apps
  • Crypto, if the audience is crypto-native, Web3, or NFT

Watch out for:

  • Gaming runs high chargeback rates, so you'll need strong fraud prevention
  • Carrier billing has high fees and excellent conversion

High-Risk / Regulated Verticals

For gambling, adult content, cannabis (where legal), forex, and the like:

Common patterns:

  • Fewer processor options. Expect to pay higher rates.
  • Wallets like Skrill and Neteller matter in gambling and forex
  • Cash and voucher methods (Paysafecard) cut chargeback exposure
  • ACH and bank transfers often beat cards on economics

Key considerations:

  • Build relationships with processors who know your vertical
  • Watch your chargeback ratios obsessively. Network thresholds don't bend.
  • Plan for processor redundancy. Getting cut off isn't rare.

Decision Framework Summary

  1. Start with cards plus major wallets. Apple Pay, Google Pay, PayPal.
  2. Add BNPL for discretionary products with AOV > $50.
  3. Add local APMs for each significant international market.
  4. Consider ACH or Pay by Bank where the savings beat the conversion hit.
  5. Add niche methods (crypto, carrier billing, vouchers) only on clear demand.
  6. Monitor and adjust on your actual conversion, fraud, and cost data.

The goal is covering what your customers want, without drowning in complexity. Start simple, add the methods that move the needle, and cut the ones that don't earn their operational cost.


Push vs Pull and Reversibility

This is the framework that matters most for payment risk:

MethodPush/PullReversible?Who Can ReverseReversal Window
Credit CardPullYesCardholder/Issuer120 days
Debit CardPullYesCardholder/Issuer (Reg E)60 days
ACH CreditPushLimitedODFI in special cases5 days (most)
ACH DebitPullYesRDFI/Customer60 days (unauthorized)
RTP/FedNowPushNoOnly voluntary refundN/A
WirePushNoOnly bank cooperationN/A
PIX/UPI/etc.PushVery limitedScheme-specificVaries
SEPA CreditPushLimitedVery limited recall10 days
SEPA Direct DebitPullYesCustomer8 weeks (no questions)

Why this matters:

  • Pull methods like cards and direct debit put the merchant at risk. You ship, the customer disputes, the money comes back.
  • Push methods like RTP and wire put the sender at risk. Once it's sent, it's gone. Fraudsters love push payments.
  • Reversibility sets your dispute exposure. Irrevocable methods have zero chargebacks, and they leave you zero recourse if you're defrauded.

Regional Regulation Snapshot

Regulation changes payment economics a lot by region.

United States:

  • The Durbin Amendment caps regulated debit interchange at 0.05% + $0.21
  • No cap on credit. Consumer credit runs 1.51-2.30% + $0.10 in person and 1.89-2.60% + $0.10 online (Visa 18 April 2026, Mastercard 17 April 2026).
  • There isn't much regulation on payment methods overall

European Union:

  • Interchange Fee Regulation caps: 0.2% consumer debit, 0.3% consumer credit, intra-EEA
  • PSD2 requires Strong Customer Authentication on most e-commerce
  • SEPA standardizes payments across Europe

United Kingdom:

  • Interchange caps close to the EU, retained post-Brexit
  • Open Banking mandates. Banks have to provide API access.
  • Heavy adoption of Faster Payments and Direct Debit

India:

  • UPI merchant discount rate is zero or near-zero for many categories
  • The government subsidizes digital payments to drive adoption
  • Result: UPI processes 20+ billion transactions monthly

Brazil:

  • PIX is run by the central bank at near-zero cost
  • Boleto, the bank slip, still matters for the unbanked
  • Card interchange is high by global standards

China:

  • Alipay and WeChat Pay dominate, roughly 90% of mobile payments combined
  • QR code payments are the standard
  • Cross-border restrictions limit foreign card acceptance

Why this matters. Evaluating payment economics across borders? Local regulation changes the math completely. A 2.5% credit card rate in the US becomes 0.3% in the EU. UPI in India is basically free. Your strategy has to be region-specific.


The Issuer's Perspective

How issuers see each method shapes what you should do.

What Issuers Care About

Interchange revenue. Credit cards generate the most interchange. Debit generates less, and ACH generates none. Issuers want customers on credit cards.

Fraud losses. Issuers eat fraud losses on unauthorized transactions. They prefer secure methods (chip, tokenization, biometrics) over manual entry.

Dispute costs. Processing chargebacks costs issuers real money in staff time, systems, and investigation.

Float. On credit cards, issuers front the money before collecting from cardholders. On debit, it comes out of existing deposits.

Customer experience. Declines frustrate cardholders. Issuers want high approval rates, but not at the price of fraud.

Why This Matters for You

Issuers influence:

  • Approval rates on your transactions
  • Which fraud signals get transactions declined
  • Chargeback outcomes. Issuers often side with the cardholder.
  • Card reissuance, which'll break your stored credentials

High fraud rates, excessive chargebacks, or odd transaction patterns get you flagged. Issuers start declining more of your transactions, and some block your MID entirely.

From the issuer side, we track merchant reputation. A merchant at a 3% chargeback rate sees more declines than one at 0.3%. Even when the individual transaction looks identical.

Building Issuer Trust

  • Keep chargeback rates well below network thresholds
  • Use modern security features: 3DS, tokenization
  • Give cardholders a descriptor they'll recognize
  • Respond promptly to fraud alerts and retrieval requests
  • Don't retry declined transactions over and over

Operational Considerations

Reconciliation Across Methods

Each payment method reconciles differently.

Cards. Match batch totals to processor reports to bank deposits. Account for fees deducted from settlement.

ACH. Track origination files against returns, and monitor return rates by customer and type.

Real-time payments. Individual confirmation for each transaction. Simpler to reconcile, but higher volume.

Mixed methods. More methods means messier reconciliation, so build systems that handle multiple sources.

Reporting and Analytics

Track key metrics by payment method:

  • Volume and value
  • Acceptance and approval rate
  • Decline reasons
  • Fraud rate
  • Chargeback and return rate
  • Settlement timing
  • Effective cost

These numbers point at real money. ACH returning 3% while cards charge back 1%? Push customers toward cards. Wallet transactions running half the fraud rate? Prioritize wallet checkout.

Disaster Recovery

What happens when a payment method fails?

Card processor outage. You'll want a backup processor, or the ability to fail over. ACH delays. That's what same-day ACH is for. Wire for anything urgent. Bank issues. Keep relationships with more than one bank. Network outages. They're rare, but carrying Visa, Mastercard and Amex gives you redundancy.

Write the contingency plans down, because a payment outage hits revenue directly.


Next Steps

Building your initial payment stack?

  1. Card Payments - Start with card fundamentals
  2. Digital Wallets - Add Apple Pay, Google Pay, PayPal
  3. Cheat Sheet - Quick reference for all methods

Optimizing payment costs?

  1. Bank Transfers - ACH for lower-cost recurring payments
  2. Real-Time Payments - RTP/FedNow for instant, low-cost payouts
  3. Interchange Optimization - Reduce card processing costs

Expanding payment options?

  1. Alternative Methods - BNPL, local APMs, crypto
  2. International Payments - Cross-border method selection
  3. Going Global - Market-specific recommendations

See Also