A gateway with a narrow book, on purpose.


BazPay is the EU, UK and Commonwealth payment gateway for merchants that fit a defined acceptance list. We board e-commerce sellers, subscription software firms and professional-services businesses. We turn the rest away. That choice shapes everything below.

Card acquiring, open banking, payouts and fraud checks run behind one API contract. Pricing is published. Compliance sits on our side of the line.

Six things we decided early

These are operating rules, not values on a wall. Each one has a page that shows the detail behind it.

  • 01Underwriting

    A defined list of sellers

    We board e-commerce, subscription software and professional-services sellers. That is the whole book. A narrow book keeps scheme standing clean and approval rates steady for everyone on it.

    See pricing and terms
  • 02Compliance

    We carry the card scope

    Card data is vaulted on our side under PCI DSS Level 1. Your yearly return stays at SAQ A.

    Hosted fields and checkout
  • 03Pricing

    Published, not quoted

    Interchange++ sits next to blended rates. You can read both before you talk to anyone. No demo gate.

    Pricing breakdown
  • 04Engineering

    Boring on purpose

    Endpoints are versioned. Writes are idempotent. We hold an uptime target of 99.9% and publish changes before they ship.

    API reference
  • 05Data

    Regional processing, regional rails

    Merchant and shopper data is processed in-region under GDPR. Funds move on instant rails, including SEPA Instant.

    Open banking rails
  • 06Ownership

    Your integration, your data

    We are a gateway, not a platform checkout. You keep the merchant record, the customer data and the freedom to leave.

    Developer docs

What we hold and where we hold it

Certification is not a badge for us. It is the reason a merchant can stay at the smallest card scope there is. We re-attest every year.

Data is processed in-region. Payouts and open banking settle on instant rails. Read the privacy notice for how long we keep records.

Company standing and certification summary
What we are EU, UK and Commonwealth payment gateway not a wallet
Who we board A defined MCC list by policy
Card certification PCI DSS Level 1 audited yearly
Authentication 3-D Secure 2 certified PSD2 SCA
Data handling GDPR-compliant Regional processing
Instant rail SEPA Instant participant seconds to settle

Where we draw the line

Saying what we will not do is faster than a sales call. If one of these is a blocker, we are the wrong gateway.

  • We do not serve restricted or adult-content sellers.
  • We do not store card data on merchant infrastructure. Vaulting is gateway-side only.
  • We do not hide cost behind blended-only pricing.
  • We are not a platform-native checkout. You own your integration.
  • We are not a consumer wallet or a marketplace of other providers.

How the platform got here

Four build decisions shaped the gateway merchants use today.

  1. One API contract first

    Card acquiring, open banking, payouts, subscriptions and fraud checks were built behind a single contract. Adding a product does not mean a second integration.

  2. Scope moved to the gateway

    Hosted fields render inside our PCI boundary. Merchants dropped to SAQ A and stopped carrying card-data audit work.

  3. Plugins for regional platforms

    Pre-built plugins cover the major regional shop systems. Most sellers go live in days rather than months.

  4. Decline reasons in the open

    Raw decline codes reach the dashboard as they happen. You fix the flow instead of guessing at it.

Want the platform coverage list? See integrations, or browse the resources hub for guides.

Talk to the people who run it

Ask about underwriting, rails or scope before you write a line of code. Or skip ahead and open a sandbox account now. Test keys arrive at once.