Processing choices

Mapping the companies behind your store's payments

Ask the company named in the contract or dashboard for that part of the arrangement. Do not choose the company from a plugin name or a nickname. PCI's glossary uses payment processor, payment gateway, and payment service provider for overlapping ideas, and it defines an acquirer separately. WooCommerce lists a payment gateway as a plugin on the store and says gateways communicate with remote servers. Write the legal name, the dashboard label, and the plugin name on different rows. Where they disagree, mark the relationship unconfirmed. You can build that map from your own records. Confirm each party’s role from the relevant agreement; do not infer underwriting authority from a consultation or a plugin name. Describe the work you need. Prism will confirm scope, responsibilities, fees, and terms before work begins.

For: An owner of a research-use-only peptide business who needs to know which company handles each part of the current payment arrangement.

Updated 2026-09-21

The same word can point at more than one company

For PCI DSS, a merchant is an entity that accepts payment cards bearing the logo of a PCI SSC participating payment brand as payment for goods or services. That definition says who the merchant is. It does not name the company that processes the transaction.

PCI's glossary says a payment processor is sometimes referred to as a payment gateway or a payment service provider, and that it is an entity engaged to handle payment card transactions. It then points to acquirers. An acquirer, also called a merchant bank or acquiring bank, is typically a financial institution that processes transactions for merchants and is defined as an acquirer by a payment brand. Because the glossary itself overlaps the labels, the label on a website is not enough. The legal name on the contract is the identifier.

The plugin on the store is not the contract

WooCommerce's system status report lists active plugins, and its example includes a payment gateway plugin separate from the server software. The same report says payment gateways can use cURL to communicate with remote servers to authorize payments. The plugin is software installed on the merchant's site. The company that receives the authorization request is whoever that plugin is configured to call.

Copy the plugin name and version from the report. Then open the plugin's settings or the contract and copy the company name you find there. If the plugin says one name and the contract says another, keep both and mark the relationship unconfirmed. Do not collapse them into the brand you recognize.

Use the document that names the company, and route the question there

A processing question about whether an account can stay open goes to the company that holds the merchant agreement. A question about why a payment method does not appear at checkout goes first to the plugin and the checkout type, because that failure can be an extension incompatibility rather than an account decision. A question about a payout goes to the company named on the payout notice. A question about an invoice for processing fees goes to the company named on that invoice. If you do not have the notice, leave the row blank.

You can decide which document you have and which company it names. That company decides the answer within its role. You cannot decide, from a plugin logo, that a particular bank is the acquirer. Prism's public role is a consultation covering storefront review, preparation for a processing conversation, and help with a provider's website questions. The provider decides eligibility, price, reserves, and account status. A review is not a compliance certification. Scope, fees, and terms are discussed before work.

An unconfirmed row is a result, not a blank to guess

Memory, a salesperson's description, and the name printed on the storefront are not substitutes for the contract, the dashboard, or the invoice. If two sources name different companies for the same part, the map's answer is that the relationship is unconfirmed. The next step is to ask both sources which legal entity holds that part, not to pick the more familiar name.

Do not send account numbers, card data, or a customer list while you are only trying to identify the companies. The consultation form takes a summary of the website, the products, and the question. It does not submit a processing application.

Payment-company map

Use the last column for the legal name you can point to in a contract, dashboard, invoice, or plugin list. Write unconfirmed when the sources disagree or you do not have the document. Worksheet entries are not submitted by this worksheet or saved by this site. Use only non-sensitive summaries; do not enter credentials, government identifiers, card or bank-account numbers, private receipt links, or customer details.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Payment-company map. The last column is for temporary notes.
Part of the arrangementWhat identifies that companyA label that is not enoughLegal name or unconfirmed
Merchant accepting the card paymentThe entity that sells and accepts the payment card. PCI DSS defines a merchant as an entity that accepts payment cards bearing a participating brand's logo.The storefront brand, a supplier's name, or the agency that built the site.
Payment extension on the storeThe plugin name and version in the WooCommerce active-plugin list, or the equivalent list on another platform.The assumption that the plugin publisher is the company that settles funds.
Company the extension connects toThe company named in the plugin settings or the merchant agreement that the extension is configured to use.The plugin's marketing name, when the agreement names a different legal entity.
Acquirer named in the contractThe financial institution the contract calls the acquirer, merchant bank, or acquiring bank. PCI defines that role separately from the loose use of the word processor.A glossary nickname, or a dashboard logo with no legal name beside it.
Company named on a payout noticeThe legal name on the notice that corresponds to money sent to the business's bank.A guess that the payout company and the checkout plugin are the same. They may be. The notice is what shows it.
Company named on a processing invoiceThe legal name on the invoice for the payment service the business pays.The name a salesperson used, if it is not the name on the invoice.
Support contact for a live payments questionThe support address printed on the agreement or inside the dashboard of the company that holds that part.A general contact form for the plugin's marketplace, unless the agreement says that form reaches the contracting company.
PrismPrism's public pages describe a consultation for storefront review, processing preparation, and help with a provider's website questions.Treating Prism as the acquirer, the gateway plugin, or the company that decides the account.

These are temporary notes. Leaving or reloading this page may clear them. The consultation form does not include these entries.

Limits

  • A Prism consultation can help you organize the facts and discuss the website or processing question. The payment provider decides eligibility, pricing, reserves, and whether an account is opened or closed.
  • PCI definitions explain roles. They do not identify the companies in your arrangement, and they are not a Prism eligibility rule.
  • This map does not say that any named provider will accept a research-use-only catalog.
  • Do not send credentials or customer lists through the public form.

Sources checked 2026-09-21

  • PCI DSS merchant definition — checked 2026-09-21. For PCI DSS, a merchant is any entity that accepts payment cards bearing the logo of a PCI SSC participating payment brand as payment for goods or services.
  • PCI glossary: payment processor — checked 2026-09-21. The glossary says a payment processor is sometimes referred to as a payment gateway or payment service provider, and is an entity engaged to handle payment card transactions on a merchant's behalf.
  • PCI glossary: acquirer — checked 2026-09-21. An acquirer, also called a merchant bank or acquiring bank, is typically a financial institution that processes payment card transactions for merchants and is defined by a payment brand as an acquirer.
  • WooCommerce system status report — checked 2026-09-21. Active plugins, including a payment gateway plugin, are listed separately from the server. Payment gateways can use cURL to communicate with remote servers to authorize payments.
  • Prism solutions — checked 2026-09-21. Prism's public support is storefront review, processing preparation, and help with a provider's website questions. The provider decides eligibility and account terms.
  • Prism features — checked 2026-09-21. A website review is informational. It is not a legal opinion or a compliance certification, and it does not guarantee approval.
  • Prism contact — checked 2026-09-21. The form collects the website, products, and question. It does not submit a processing application. Card details, passwords, and customer records are left out.

Request a consultation

Describe the business and this specific question. Prism follows up by email to discuss fit and scope. An inquiry is not a processing application or an approval.