Fintech · Payments
Payment gateway integration services built so no customer is charged twice
We integrate Stripe, Stripe Connect, Paddle, tokenisation providers and app-store billing into web and mobile products, with the retry handling, webhooks and reconciliation that keep money and records in step.

Short answer
Payment gateway integration connects your product to a provider such as Stripe so you can take one-off payments, subscriptions and marketplace payouts. Done properly it includes idempotent charges, verified webhooks, refunds, tax and reconciliation. Innovation Insight has shipped payment integrations on seven client platforms, including Stripe Connect, card tokenisation and separate US and Canadian Stripe accounts. Integrations are priced at $25 to $49 an hour; a single provider usually takes one to three weeks.
Reviewed by Zain Khalid Malik, CTO & Co-founder · Updated
Why payment integrations fail
Taking a test payment is an afternoon's work. The difficulty is everything that happens when the network is unreliable and money is involved. A customer double-clicks. A request times out after the charge succeeded. A webhook arrives twice, or before the page that triggered it has finished. A subscription renews while your server is deploying. An integration that does not plan for these cases produces double charges, paid orders that never appear and customers with access they did not pay for.
What we integrate
| Need | Typical provider | What we build |
|---|---|---|
| One-off payments | Stripe, Adyen, Braintree | Hosted fields or checkout, 3D Secure, saved cards, refunds |
| Subscriptions | Stripe Billing, Paddle, Chargebee | Plans, trials, proration, upgrades, dunning, customer portal |
| Usage-based billing | Stripe Billing | Metering, limits, overage purchases, invoices |
| Marketplace payouts | Stripe Connect | Seller onboarding and verification, split payments, platform fees, payout schedules |
| Card tokenisation across gateways | Spreedly and similar vaults | One token store routed to several processors |
| Mobile in-app purchases | Apple App Store, Google Play | Subscriptions, receipt validation, entitlement sync with your back end |
| Several countries | Separate provider accounts per region | Per-country keys, currencies, tax rules and webhook endpoints |
How we build it
- Card data stays with the provider. Hosted fields or tokenisation keep card numbers off your servers, which keeps PCI DSS scope small.
- Idempotency keys on every charge, so a retry after a timeout returns the original result instead of charging again.
- Webhooks are verified by signature, stored, acknowledged quickly and processed from a queue. Duplicates and out-of-order events are expected.
- Your database holds its own record of plans, payments and entitlements, updated from webhooks, so access decisions never wait on the provider.
- An atomic order transaction: the order, the payment record and the side effects succeed or fail together, with explicit compensation when a later step fails.
- Reconciliation jobs compare your records with the provider's on a schedule and flag differences.
- Every flow is tested in the provider's sandbox, including declines, disputes, refunds and failed renewals.
Payment work we have shipped
- Paint Nite: checkout rebuilt as a six-stage pipeline (quote, tax, tender, persist, emit, effects) with idempotent Stripe payments and an atomic order transaction. The US and Canada use separate Stripe accounts, keys and webhook secrets, with a Canadian tax path and per-state nexus rules.
- Cuts Like A Knife: the full Stripe webhook lifecycle for subscriptions, payment intents, invoices, refunds and charges, with proration and retry tracking, plus one-time track purchases.
- TamTracker: Stripe Connect billing for an agency portal, where agencies manage and bill their own clients.
- Edge OCR: four Stripe plans with scan limits, overage purchases and rollover.
- LogFish: Stripe payments, subscriptions and payouts alongside Apple App Store and Google Play subscriptions.
- Seek My Service: a credit system where vendors buy credits through Stripe, with fixed and percentage discount codes.
- Zeuss: card tokenisation through Spreedly with orders and subscriptions on 29next.
PCI DSS in brief
PCI DSS is the card industry's security standard, and it applies to anyone who accepts cards. How much of it you must evidence depends on how card data flows. If card details are entered only into a provider's hosted page or embedded fields, your obligations fall under the shortest self-assessment questionnaires. If card numbers pass through or are stored on your own servers, the scope grows sharply. We design integrations for the smallest scope and document the data flow for your assessor.
What it costs
| Scope | Typical effort | How it is priced |
|---|---|---|
| One provider, one-off payments or simple subscriptions | 1 to 3 weeks | Time and materials at $25 to $49 an hour |
| Usage billing, proration, customer portal | 3 to 6 weeks | Time and materials at $25 to $49 an hour |
| Marketplace payouts with Stripe Connect | 4 to 8 weeks | Fixed scope after discovery |
| A payments product (wallet, lending, peer-to-peer) | 4 to 6 months | Fintech MVP, $40k to $80k |
| Monitoring and upkeep | Ongoing | Support retainer, $1.5k to $8k per month |
Provider fees are separate and are paid to the provider. We help you compare them before choosing.
Sources and further reading
Next step
Tell us what you're building and get a written estimate.
A senior engineer replies within one business day. NDA on request.
Products we've shipped, and what happened next.
Case studies written from the technical documentation of each project: the stack, the scale and the outcome.
Questions we get asked a lot.
Which payment gateway should we use?
Stripe for most products, because of its APIs, documentation and Connect for marketplaces. Paddle when you want a merchant of record to handle global sales tax. Adyen or Braintree for specific regions or enterprise requirements. We compare fees and features for your case.
How do you prevent double charges?
Idempotency keys on every charge request, webhook events stored and de-duplicated before processing, and scheduled reconciliation against the provider's records.
Do we need to be PCI compliant?
Yes, anyone accepting cards does. Using hosted fields or tokenisation keeps card data off your servers and reduces your obligations to the shortest self-assessment.
Can you add marketplace payouts?
Yes. We use Stripe Connect for seller onboarding, identity verification, split payments, platform fees and payouts.
Can you handle Apple and Google in-app purchases?
Yes. We implement store subscriptions, validate receipts on the server and keep entitlements in step with your web billing.
Can you fix an existing payment integration?
Yes. We audit webhook handling, retries, secrets and reconciliation first, then fix the gaps that put revenue or customers at risk.


