A gateway with a narrow book, on purpose.
BazPay is the EU payment gateway built for low-risk merchants. We board e-commerce sellers, subscription software firms and professional-services businesses. We turn the rest away. That choice shapes everything below.
Card acquiring, open banking, payouts and fraud checks run behind one API contract. Pricing is published. Compliance sits on our side of the line.
Six things we decided early
These are operating rules, not values on a wall. Each one has a page that shows the detail behind it.
-
01Underwriting
Low-risk sellers only
We board e-commerce, subscription software and professional-services sellers. That is the whole book. A narrow book keeps scheme standing clean and approval rates steady for everyone on it.
See pricing and terms -
02Compliance
We carry the card scope
Card data is vaulted on our side under PCI DSS Level 1. Your yearly return stays at SAQ A.
Hosted fields and checkout -
03Pricing
Published, not quoted
Interchange++ sits next to blended rates. You can read both before you talk to anyone. No demo gate.
Pricing breakdown -
04Engineering
Boring on purpose
Endpoints are versioned. Writes are idempotent. We hold an uptime target of 99.9% and publish changes before they ship.
API reference -
05Data
EU processing, EU rails
Merchant and shopper data is processed in the EU under GDPR. Funds move on SEPA rails, including SEPA Instant.
Open banking rails -
06Ownership
Your integration, your data
We are a gateway, not a platform checkout. You keep the merchant record, the customer data and the freedom to leave.
Developer docs
What we hold and where we hold it
Certification is not a badge for us. It is the reason a merchant can stay at the smallest card scope there is. We re-attest every year.
Data is processed in the EU. Payouts and open banking settle on SEPA rails. Read the privacy notice for how long we keep records.
| What we are | EU payment gateway | not a wallet |
|---|---|---|
| Who we board | Low-risk merchants | by policy |
| Card certification | PCI DSS Level 1 | audited yearly |
| Authentication | 3-D Secure 2 certified | PSD2 |
| Data handling | GDPR-compliant | EU processing |
| Instant rail | SEPA Instant participant | seconds to settle |
Where we draw the line
Saying what we will not do is faster than a sales call. If one of these is a blocker, we are the wrong gateway.
- We do not serve high-risk, restricted or adult-content sellers.
- We do not store card data on merchant infrastructure. Vaulting is gateway-side only.
- We do not hide cost behind blended-only pricing.
- We are not a platform-native checkout. You own your integration.
- We are not a consumer wallet or a marketplace of other providers.
How the platform got here
Four build decisions shaped the gateway merchants use today.
-
One API contract first
Card acquiring, open banking, payouts, subscriptions and fraud checks were built behind a single contract. Adding a product does not mean a second integration.
-
Scope moved to the gateway
Hosted fields render inside our PCI boundary. Merchants dropped to SAQ A and stopped carrying card-data audit work.
-
Plugins for EU platforms
Pre-built plugins cover the major EU shop systems. Most sellers go live in days rather than months.
-
Decline reasons in the open
Raw decline codes reach the dashboard as they happen. You fix the flow instead of guessing at it.
Want the platform coverage list? See integrations, or browse the resources hub for guides.
Talk to the people who run it
Ask about underwriting, rails or scope before you write a line of code. Or skip ahead and open a sandbox account now. Test keys arrive at once.