Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Legal Issues To Check Before You Sign
- 1. Contracting entity and service description
- 2. Settlement timing, reserves and withheld funds
- 3. Fraud, chargebacks and refund risk
- 4. Suspension and termination rights
- 5. Data protection and customer information
- 6. Regulatory status and sector specific issues
- 7. Liability caps, indemnities and practical remedies
FAQs
- Can a payment provider freeze my business funds?
- Am I still responsible for refunds and chargebacks if I use a third-party payment provider?
- Does using a payment provider deal with my UK GDPR obligations?
- Can I rely on the provider's online terms without legal review?
- What should I do if the provider's terms do not match what was promised?
- Key Takeaways
Using third-party payment providers can speed up checkout, improve cash flow visibility and help you sell across channels, but the contract risk is often hidden in the small print. UK businesses regularly sign standard terms without checking who carries fraud losses, how long funds can be held, or what happens if the provider freezes the account at the busiest point of the month. Another common mistake is assuming the payment provider will handle all compliance issues, including customer chargebacks, anti-money laundering checks, data protection and consumer refunds.
The right provider can be a strong operational tool. The wrong contract can leave you chasing withheld funds, dealing with customer complaints and trying to unwind terms you never properly negotiated. This guide explains what third-party payment providers mean in practice for UK businesses, the legal issues to review before you sign, the mistakes founders make most often, and the contract essentials worth settling before you rely on a provider for day to day trading.
Overview
Third-party payment providers sit between your business, your customers and the banking system, so the contract is not just about fees. It also governs access to your money, risk allocation, compliance responsibility and what happens when something goes wrong.
- who the provider is contracting with, and whether group companies or marketplaces are involved
- how and when settlement payments are made, including reserves, rolling holds and deductions
- which party carries fraud, chargeback, refund and failed transaction risk
- what rights the provider has to suspend, terminate or change the service
- what data is shared, who controls it and what UK GDPR obligations still sit with your business
- whether sector specific rules, card scheme requirements or regulated activity issues apply
- how customer complaints, disputed transactions and reconciliation problems will be handled
- what practical remedies you have if funds are frozen or the provider breaches the agreement
What Third-party Payment Providers Means For UK Businesses
Third-party payment providers are not just software suppliers. They often act as a payment intermediary, merchant acquirer, e-money institution, payment gateway or platform operator, and each model shifts the legal and commercial risk in different ways.
For a UK business, that matters because the provider may touch customer money, process personal data, screen transactions, apply anti-fraud tools and control whether funds are released. Even where the provider is well known, your business still needs to understand what service is actually being supplied and what legal responsibilities stay with you.
What counts as a third-party payment provider?
The term usually covers businesses that let you accept and process payments without using only your own bank's merchant services. In practice, that may include:
- online checkout and card processing providers
- buy now, pay later intermediaries used at checkout
- digital wallet integrations
- marketplace payment platforms that split payments between parties
- subscription billing and recurring payment processors
- point of sale providers that combine hardware, software and payment processing
- international payment platforms handling multi-currency transactions
Some providers are regulated payment institutions or e-money institutions in the UK. Others rely on group structures, partners or outsourcing models. Before you sign a contract, you need to know who is actually delivering each part of the service.
Why businesses use them
The obvious appeal is convenience. You may get faster integration, easier recurring billing, marketplace tools, fraud screening and a smoother customer checkout than with a traditional merchant bank arrangement.
That said, convenience can hide control issues. The provider's standard terms often give it broad discretion to investigate transactions, delay settlements, impose reserves or suspend processing if it thinks your business presents higher risk.
Why the contract matters so much
The main risk is simple: your payment provider can affect revenue collection in real time. A standard software contract usually does not hold your income pipeline in the same way.
This is where founders often get caught. They agree pricing and integration timelines, but do not focus on clauses dealing with withheld funds, suspected fraud, transaction monitoring, acceptable use policies and unilateral term changes. If a dispute arises, those clauses often decide whether your business can keep trading smoothly.
The issue becomes more serious for sectors with higher chargeback rates, regulated products, age restricted goods, subscriptions, marketplaces or cross border sales. In those models, third-party payment providers may treat your account as higher risk from day one, even if no one highlighted that during sales discussions.
Legal Issues To Check Before You Sign
Before you accept the provider's standard terms, identify where money, data and liability actually sit. That is the core legal exercise, and it is far more important than comparing headline transaction fees alone.
1. Contracting entity and service description
Start with the basics. Check the exact legal entity you are contracting with, where it is based, and whether another affiliate is providing regulated services, technology support or settlement functions.
The service description should be clear about:
- what payment methods are supported
- which channels are covered, such as online, in person or invoicing
- whether recurring payments are included
- whether the provider acts for you, for itself, or through another regulated partner
- what onboarding checks and ongoing compliance reviews apply
If the provider's sales team has described features or timings that are important to your decision, get those points reflected in the written terms before you rely on a verbal promise.
2. Settlement timing, reserves and withheld funds
You need a precise picture of when your business gets paid. Many disputes are not about whether a customer paid, but whether the provider is entitled to delay settlement, hold back a reserve or deduct amounts without much warning.
Review clauses covering:
- settlement cycles and payment cut-off times
- rolling reserves, minimum balances and security holds
- rights to delay payout during investigations
- set-off rights against future transactions
- circumstances where funds may be frozen after termination
For a startup or SME, this can be the difference between normal trading and a cash flow crisis. Before you spend money on setup or migration, pressure test how long your business could operate if a provider held funds for several weeks.
3. Fraud, chargebacks and refund risk
Payment provider contracts often push fraud and chargeback exposure back onto the merchant. That can be commercially workable, but only if you understand the allocation and have systems to manage it.
Check who is responsible for:
- authorised push payment fraud issues where relevant
- card not present fraud losses
- friendly fraud and disputed transactions
- chargeback administration fees
- refund processing failures
- evidence gathering and response deadlines
If you sell subscriptions, event tickets, custom products or delayed delivery services, chargeback risk can be higher. Make sure your customer terms, delivery records and refund processes line up with the provider's evidence requirements.
4. Suspension and termination rights
A provider may need broad rights to suspend services for fraud, sanctions, legal breaches or card scheme rules. The issue is whether those rights are drafted so widely that your business can be shut down on limited notice with little practical recourse.
Before you sign, look closely at:
- what triggers suspension
- whether notice must be given
- whether urgent suspension can occur first, with reasons provided later
- what you must do to restore service
- whether termination is immediate or subject to cure periods
- what happens to pending settlements after termination
If the provider can terminate for convenience on short notice, consider the operational risk. A business that depends heavily on one payment flow should have a contingency plan, even if the contract cannot be heavily negotiated.
5. Data protection and customer information
Using a third-party payment provider does not remove your privacy obligations. Your business may still be a controller of customer personal data for parts of the payment journey, and the provider may act as a separate controller or a processor depending on the arrangement.
That means you should review:
- what customer data is shared with the provider
- whether the provider uses the data for its own fraud models, analytics or product improvement
- whether international transfers occur
- security commitments and incident reporting obligations
- who handles data subject requests for payment related records
- how long transaction data is retained
Your privacy notice and internal data mapping should match the actual payment flow. If they do not, your compliance position may be weaker than you think.
6. Regulatory status and sector specific issues
Some business models trigger extra scrutiny. If you operate a marketplace, handle client money style flows, sell regulated goods or support high volume subscriptions, you may need to ask more detailed questions before you sign.
Points worth checking include:
- whether the provider is authorised or registered for the regulated activities it performs
- whether any exclusions or partner arrangements are being used
- whether your sector is listed as restricted or high risk
- whether age verification, know your customer checks or sanctions screening obligations apply
- whether card scheme rules impose extra operational requirements on your business
This is not about turning every merchant into a payments lawyer. It is about making sure the service model matches your trading reality.
7. Liability caps, indemnities and practical remedies
Most providers cap their liability heavily and exclude indirect losses, lost profits and service interruption claims. That is standard, but you still need to understand the practical position if their actions stop money flowing through your business.
Review the clauses on:
- overall liability caps
- carve outs for fraud, wilful default, confidentiality or data breaches
- indemnities you give for customer claims, regulatory issues or misuse of the service
- service credits versus actual loss recovery
- governing law, dispute escalation and complaint routes
In many cases, the real protection comes from clear contract drafting, notice procedures, service commitments and operational backup plans, not from hoping a damages claim will fix a trading problem later.
Common Mistakes With Third-party Payment Providers
Most payment contract problems start long before any dispute. They usually come from treating the provider's onboarding process as an admin task instead of a legal and commercial risk review.
Assuming standard terms cannot be negotiated
Some terms may be non-negotiable for smaller merchants, but that does not mean every issue is fixed. Businesses often secure useful clarifications on settlement timing, support response paths, notice periods, onboarding assumptions or how reserves will be communicated.
Even if the provider will not amend the main agreement, written confirmations on key operational points can still help.
Not checking restricted business categories carefully enough
This is where many founders get caught. A provider may permit your general sector but prohibit a particular product line, fulfilment model or marketing practice.
For example, problems can arise where a business:
- sells subscription products without making recurring billing clear enough
- takes pre-orders or delayed fulfilment payments
- operates a marketplace or takes commission from third-party sellers
- sells age restricted or health related products
- uses affiliate traffic that increases fraud flags
If your business model is not described accurately during onboarding, the provider may later say you breached acceptable use terms.
Relying on verbal sales promises
If a provider representative says reserves will not apply, support is 24 hour, or international settlement is available from day one, get that into the contract or at least clear written onboarding documents. Sales discussions often focus on best case operation. The legal terms usually preserve far more discretion for the provider.
Ignoring the customer side of payment disputes
Your own customer terms still matter. Refund rights, delivery promises, recurring billing disclosures and complaint handling all affect the likelihood of chargebacks and payment disputes.
A payment provider cannot solve weak customer documentation. Before you sign, check that your consumer or business customer contracts match how payments will actually be taken and reversed.
Overlooking account freeze scenarios
Businesses often ask about rates, integrations and dashboard features, but not about freezes. You should ask what happens if the provider detects unusual activity, requests extra verification or suspects policy breaches.
Key practical questions include:
- who can you contact urgently
- what evidence may be requested
- how quickly reviews are normally completed
- whether partial settlements can continue during an investigation
- whether you can migrate away while funds remain under review
If the answers are vague, treat that as a real risk rather than a theoretical one.
Failing to map internal responsibility
Someone in the business needs to own the provider relationship. Problems escalate quickly when finance handles reconciliation, operations handles refunds, marketing controls the checkout flow and nobody monitors contractual triggers for reserve changes or compliance reviews.
Before you rely on the provider, assign responsibility for:
- contract management
- dispute response deadlines
- chargeback evidence collection
- privacy and data queries
- service issue escalation
- termination planning and provider exit
FAQs
Can a payment provider freeze my business funds?
Often yes, if the contract allows it and the provider believes there is fraud, compliance risk, unusual activity or likely chargeback exposure. The real question is when they can do it, how long the hold can last and what notice or explanation they must give.
Am I still responsible for refunds and chargebacks if I use a third-party payment provider?
Usually yes. The provider may process the payment mechanics, but the merchant commonly remains responsible for the underlying customer dispute, refund rights and many chargeback costs.
Does using a payment provider deal with my UK GDPR obligations?
No. A provider may support secure payment processing, but your business still needs appropriate privacy information, lawful handling of customer data and a clear understanding of who controls which data in the payment flow.
Can I rely on the provider's online terms without legal review?
You can, but the risk is that you accept broad suspension rights, reserve powers and liability limitations without spotting them. Before you sign, at least get a contract review of the clauses affecting cash flow, data, dispute handling and termination.
What should I do if the provider's terms do not match what was promised?
Raise the inconsistency before you sign and ask for the promise to be written into the agreement or onboarding documents. If that does not happen, assume the written terms will govern the relationship.
Key Takeaways
- Third-party payment providers can improve checkout and operations, but they also control a critical part of your revenue flow.
- The contract should be reviewed for settlement timing, reserves, chargebacks, fraud allocation, suspension rights, termination and post-termination treatment of funds.
- Your business still needs to manage privacy, customer terms and evidence for disputes, even where the provider handles the payment processing mechanics.
- Founders often miss restricted business rules, rely on verbal promises and underestimate how damaging an account freeze can be.
- Before you sign, make sure the written agreement matches your business model and your internal team knows who owns disputes, compliance and provider escalation.
If you want help with contract terms, settlement and reserve clauses, data protection issues, and suspension and termination risk, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.








