Online card payments
Accept cards and digital wallets on your site or app, without card data ever touching your server.
Your customer pays on a page that looks like part of your site but is served from a PCI DSS Level 1 certified environment. You get confirmation over a webhook and the funds in your account within 48 business hours.
If you already have a checkout you want to keep, you can capture the details through our PCI Proxy and still stay out of PCI certification scope.
What you get
Hosted checkout
A ready payment page in your language, with your logo and colours.
Or your own design
Full control of the look through the REST API and PCI Proxy.
3-D Secure 2
Strong customer authentication under PSD2 with minimal friction.
40+ methods
Cards, Apple Pay, Google Pay, PayPal, Klarna and local methods.
Refunds
Full and partial, straight from the merchant panel or the API.
Real-time reporting
Every transaction with its fees broken into components.
How it works
Approval
You send the documents and get sandbox access within hours.
Integration
Install a plugin or wire up the API, usually a day's work.
Testing
Run test payments with sandbox cards and verify the webhook.
Go live
Swap in production keys and take your first real payment.
What actually happens when a customer hits Pay
Between the button press and the success message, about two seconds pass and five separate things happen. The card details leave the customer's browser over an encrypted connection to our gateway. The gateway checks whether the card supports 3-D Secure and, if it does, hands the customer to their bank for confirmation. After confirmation the request goes to the card scheme, Visa or Mastercard, and on to the issuing bank. The issuer decides whether the funds are there and whether the transaction looks normal for that cardholder. The answer travels back the same way.
For you as a merchant this is one API call or one click in the plugin. Everything else, including scheme rules, message formats and PSD2 requirements, sits on our side. You see two things: approved or declined, and the reason when it is declined.
What matters for your money comes after. An approved transaction is not money received, only an amount held on the customer's card. The actual transfer happens at settlement, when we collect the day's takings and send them to your company account. With BulPays that is within 48 business hours, and for certain risk profiles the same business day is possible.
Why declines are not all the same
The most expensive mistake in online payments is treating every decline as a lost customer. Declines come in two kinds and they need different handling. Hard declines mean the card will never go through: closed account, invalid number, blocked card. Retrying those only stacks up fees. Soft declines are temporary: no funds right now, the bank wants an extra check, the daily limit is spent. A large share of those succeed on a second attempt a day or two later.
In the panel you see the decline code exactly as the bank returned it, not a generic payment failed. If you sell on subscription, that is the difference between a churned customer and one who pays two days later.
The second common cause of lost sales is an over-strict fraud filter. A rule that blocks every transaction from a foreign IP sounds sensible until you realise you have declined every Bulgarian shopping from a phone while roaming. That is why rules are tuned to the actual business rather than applied from a template.
Integration: plugin, hosted checkout or your own API
The plugin is the fastest route. For WooCommerce, PrestaShop and OpenCart you install the module, paste the keys from the panel and take your first transaction the same day. The plugin also handles the 3-D Secure redirect and the return to your shop.
Hosted checkout is for when you do not want card details to touch your site at all. The customer is redirected to a page on our domain, pays there and comes back to you. That drops your PCI obligations to the lightest questionnaire, SAQ A.
The REST API is for bespoke applications and non-standard flows. It speaks JSON, authentication is by key and signature, and every request carries an idempotency key, so a request sent twice over a weak connection cannot create two payments. There is a test environment with cards for every scenario, including decline, expired card and failed 3-D Secure.
Who gets paid what: one transaction taken apart
On a 100 euro sale with a Bulgarian consumer debit card, the fee is assembled from three parts. Interchange goes to the customer's bank and for that card is around 0.20%. The scheme fee goes to Visa or Mastercard and is around 0.03%. The BulPays margin is 0.79%. Plus the fixed 0.05 euro per transaction. Around 1.07 euro in total.
The same sale on a commercial credit card issued outside the EEA costs more, because interchange on those cards is several times higher. On a blended rate that difference is invisible: you pay one percentage for everything and never learn that you subsidised the expensive cards with the margin from the cheap ones. On IC++ you see every component separately.
Questions about this
Do I need PCI DSS certification to take cards online?
It depends on how you integrate. With hosted checkout or our PCI Proxy, card data never touches your server and you fall under SAQ A, the shortest questionnaire, which takes about an hour to complete. If you want to accept card numbers directly in your own form on your own server, the requirements are far heavier and you go through SAQ D. In practice almost no merchant needs the second option.
How long does it take to go live?
Account approval takes 1 to 24 hours with a complete document set. Technical integration with a plugin is an hour's work, with your own API usually one business day. So with decent organisation you are taking real payments on day two.
What happens with a chargeback?
You get a notice with the reason and the deadline to respond. You upload the evidence in the panel: order confirmation, shipping document, correspondence with the customer, delivery logs for a digital product. We format it to the scheme's requirements and file it. The amount is held while the dispute runs and returns if the decision goes your way.
Can I accept payments in euro and in another currency?
Yes. We accept the main European currencies and settle in euro to your company account. If you sell mostly to customers outside the eurozone, say so and we will look at whether multi-currency settlement makes sense.
What is 3-D Secure 2 and is it mandatory?
It is the strong customer authentication protocol under PSD2. For most consumer payments in the EEA it is mandatory. Version 2 passes more data to the issuing bank, which is why many transactions go through without the customer seeing anything at all. There are also legal exemptions, for example for small amounts or a trusted merchant, applied automatically when the profile allows it.
Ready to start accepting payments?
Send us an enquiry and you will get a concrete quote with calculated fees for your business, usually within one business day.