Merchant of Record vs. Payment Gateway: What's the Difference?


Merchant of record vs. payment gateway explained — what a payment gateway actually does, how it differs from an MoR on tax, liability, and compliance, how the full payment stack fits together, and which one your business needs.
Merchant of Record vs. Payment Gateway: What's the Difference?
Quick answer: A payment gateway is technology — it securely transmits payment data from your checkout to the payment processor. A merchant of record (MoR) is a legal role — the entity responsible for the sale itself: the tax, the chargebacks, the compliance, and the liability. They aren't competing options; an MoR uses a gateway under the hood. The real question is who carries the legal and tax burden of your sales — and a gateway never does.
The confusion is understandable, because both sit between your customer's card and your bank account, and payment vendors market across the boundary. But comparing a gateway to an MoR is like comparing a cash register to a store owner: one is equipment, the other is responsibility.
This guide explains what each actually does, how the full payment stack fits together, and how to work out which one your business needs. For the foundational background, see our complete guide to what a merchant of record is.
What is a payment gateway?
A payment gateway is the technology layer that captures payment details at checkout, encrypts them, and passes them to the payment processor for authorization — then relays the approve/decline response back. It's the digital equivalent of a card terminal.
What a gateway handles:
- Secure transmission of card and wallet data from checkout to processor
- Encryption and tokenization so raw card data never touches your servers
- Authorization requests and responses in real time
- Basic fraud screening (velocity checks, AVS/CVV verification), depending on the provider
What a gateway does not handle: it doesn't calculate or remit your sales tax or VAT, doesn't take liability for chargebacks, doesn't make you compliant with tax law in any jurisdiction, and doesn't change who the legal seller is. All of that stays with you. Well-known gateways include Authorize.net, Braintree's gateway layer, and the gateway components inside Stripe and PayPal.
What is a merchant of record (MoR)?
A merchant of record is the legal entity authorized — and held liable — for selling to the end customer. When you sell through a third-party MoR, it becomes the seller on each transaction: its name is on the customer's card statement, and it owns the financial, legal, and compliance side of the sale.
That means the MoR handles:
- Global sales tax, VAT, and GST — registration, calculation, collection, and remittance in every jurisdiction it sells into
- Chargeback and fraud liability — disputes hit the MoR, not you
- PCI compliance — the MoR maintains the security posture
- Payment processing end to end — including, yes, the gateway layer
- Banking and card-network relationships — merchant accounts, acquirers, underwriting
The through-line is liability. A gateway moves data; an MoR takes responsibility for the sale.
The core difference: technology vs. legal responsibility
Strip everything away and the distinction is one sentence: a payment gateway is a tool you use; a merchant of record is a role someone plays.
If you sell with your own gateway and processor, you are the merchant of record — with everything that implies. You must register for and remit sales tax and VAT wherever you have obligations, absorb chargebacks, maintain PCI compliance, and answer to banks and tax authorities. The gateway made the payment possible; it made none of the obligations go away.
That's the trap in "we have payments handled — we integrated a gateway." You've handled the plumbing. The liability is all still yours.
Merchant of record vs. payment gateway: side-by-side
| Responsibility | Payment Gateway | Merchant of Record (MoR) |
|---|---|---|
| What it is | Technology layer | Legal seller of the transaction |
| Transmits payment data securely | Yes | Yes (uses gateways internally) |
| Legal seller on the transaction | You | The MoR |
| Sales tax / VAT / GST calculation & remittance | You | MoR handles it |
| Chargeback & dispute liability | You | MoR is liable |
| PCI compliance | Shared; ultimate responsibility yours | MoR's responsibility |
| Fraud prevention | Basic screening | Comprehensive, with liability |
| Name on customer's card statement | Yours | The MoR's (configurable descriptor) |
| Global expansion | You handle tax/compliance per market | Built in |
| Cost | Low per-transaction fee | Higher blended fee (liability priced in) |
Do you need a gateway if you use a merchant of record?
No — and this is the point most comparisons miss. A full-service MoR includes the gateway function. When you sell through an MoR, checkout, secure transmission, processing, tax, and liability all come as one integrated service. You don't shop for a gateway separately; it's inside.
The reverse isn't true: a gateway alone gives you none of what an MoR provides. If you build on a gateway, you'll separately need a payment processor relationship (often bundled), a tax compliance solution, chargeback management, and PCI scope management — and you'll still be the legal seller everywhere you sell.
How the full payment stack fits together
Where each piece sits, from checkout button to money in the bank:
- Checkout — where the customer enters payment details.
- Payment gateway — encrypts and transmits those details for authorization.
- Payment processor — executes the transaction between the card networks and banks.
- Acquiring bank — holds the merchant account that receives the funds.
- Merchant of record — the legal seller wrapped around all of the above: owns the merchant account, the tax obligations, and the liability.
With a payfac or PSP (like standard Stripe), layers 2–4 are bundled for you, but you remain the merchant of record — the liability layer stays yours. With a third-party MoR, all five layers, including the legal role, transfer to the provider. We compare those models in detail in Merchant of Record vs. Payment Facilitator and Merchant of Record vs. Payment Service Provider.
Which does your business need?
A gateway (with you as your own MoR) tends to fit when you:
- Sell mainly in one country with simple tax obligations
- Have finance and engineering resources to own tax, compliance, and PCI
- Want the lowest per-transaction cost and maximum control over the stack
- Sell physical goods locally, where cross-border digital tax rules don't bite
A merchant of record tends to fit when you:
- Sell software, SaaS, or digital products internationally — where VAT and GST obligations arrive with your very first foreign sale
- Run subscriptions or usage-based billing across borders
- Want chargeback, fraud, and compliance liability off your books
- Would rather not assemble and maintain a gateway + processor + tax engine + compliance stack yourself
A simple test: list what you'd need beyond the gateway — tax registrations, filings, chargeback handling, PCI audits — and price it in money, time, and risk. If that bill exceeds an MoR's fee, the gateway wasn't actually the cheap option.
Frequently Asked Questions
Everything else you might be wondering about.
The bottom line
A payment gateway and a merchant of record answer different questions. The gateway answers "how does the card data get from my checkout to the bank?" The MoR answers "who is legally on the hook for this sale — its taxes, its chargebacks, its compliance?" Every business needs the first solved; the strategic decision is the second.
If you're selling digital products internationally and the liability side is starting to cost real money, time, or sleep, talk to the team at Comecero. We're a merchant of record built for SaaS, AI, and high-ticket sellers — gateway, processing, global tax, and revenue recovery in one relationship, without the complex setup.

