Skip to content

Fintech · Payments

Payment gateway integration services built so no customer is charged twice

We integrate Stripe, Stripe Connect, Paddle, tokenisation providers and app-store billing into web and mobile products, with the retry handling, webhooks and reconciliation that keep money and records in step.

Book a call
Card payment being processed on a laptop and phone

Short answer

Payment gateway integration connects your product to a provider such as Stripe so you can take one-off payments, subscriptions and marketplace payouts. Done properly it includes idempotent charges, verified webhooks, refunds, tax and reconciliation. Innovation Insight has shipped payment integrations on seven client platforms, including Stripe Connect, card tokenisation and separate US and Canadian Stripe accounts. Integrations are priced at $25 to $49 an hour; a single provider usually takes one to three weeks.

Reviewed by Zain Khalid Malik, CTO & Co-founder · Updated

Why payment integrations fail

Taking a test payment is an afternoon's work. The difficulty is everything that happens when the network is unreliable and money is involved. A customer double-clicks. A request times out after the charge succeeded. A webhook arrives twice, or before the page that triggered it has finished. A subscription renews while your server is deploying. An integration that does not plan for these cases produces double charges, paid orders that never appear and customers with access they did not pay for.

What we integrate

NeedTypical providerWhat we build
One-off paymentsStripe, Adyen, BraintreeHosted fields or checkout, 3D Secure, saved cards, refunds
SubscriptionsStripe Billing, Paddle, ChargebeePlans, trials, proration, upgrades, dunning, customer portal
Usage-based billingStripe BillingMetering, limits, overage purchases, invoices
Marketplace payoutsStripe ConnectSeller onboarding and verification, split payments, platform fees, payout schedules
Card tokenisation across gatewaysSpreedly and similar vaultsOne token store routed to several processors
Mobile in-app purchasesApple App Store, Google PlaySubscriptions, receipt validation, entitlement sync with your back end
Several countriesSeparate provider accounts per regionPer-country keys, currencies, tax rules and webhook endpoints

How we build it

  • Card data stays with the provider. Hosted fields or tokenisation keep card numbers off your servers, which keeps PCI DSS scope small.
  • Idempotency keys on every charge, so a retry after a timeout returns the original result instead of charging again.
  • Webhooks are verified by signature, stored, acknowledged quickly and processed from a queue. Duplicates and out-of-order events are expected.
  • Your database holds its own record of plans, payments and entitlements, updated from webhooks, so access decisions never wait on the provider.
  • An atomic order transaction: the order, the payment record and the side effects succeed or fail together, with explicit compensation when a later step fails.
  • Reconciliation jobs compare your records with the provider's on a schedule and flag differences.
  • Every flow is tested in the provider's sandbox, including declines, disputes, refunds and failed renewals.
Never grant access because the browser says the payment succeeded. Grant it when a verified webhook, or a server-side check with the provider, says so.

Payment work we have shipped

  • Paint Nite: checkout rebuilt as a six-stage pipeline (quote, tax, tender, persist, emit, effects) with idempotent Stripe payments and an atomic order transaction. The US and Canada use separate Stripe accounts, keys and webhook secrets, with a Canadian tax path and per-state nexus rules.
  • Cuts Like A Knife: the full Stripe webhook lifecycle for subscriptions, payment intents, invoices, refunds and charges, with proration and retry tracking, plus one-time track purchases.
  • TamTracker: Stripe Connect billing for an agency portal, where agencies manage and bill their own clients.
  • Edge OCR: four Stripe plans with scan limits, overage purchases and rollover.
  • LogFish: Stripe payments, subscriptions and payouts alongside Apple App Store and Google Play subscriptions.
  • Seek My Service: a credit system where vendors buy credits through Stripe, with fixed and percentage discount codes.
  • Zeuss: card tokenisation through Spreedly with orders and subscriptions on 29next.

PCI DSS in brief

PCI DSS is the card industry's security standard, and it applies to anyone who accepts cards. How much of it you must evidence depends on how card data flows. If card details are entered only into a provider's hosted page or embedded fields, your obligations fall under the shortest self-assessment questionnaires. If card numbers pass through or are stored on your own servers, the scope grows sharply. We design integrations for the smallest scope and document the data flow for your assessor.

What it costs

ScopeTypical effortHow it is priced
One provider, one-off payments or simple subscriptions1 to 3 weeksTime and materials at $25 to $49 an hour
Usage billing, proration, customer portal3 to 6 weeksTime and materials at $25 to $49 an hour
Marketplace payouts with Stripe Connect4 to 8 weeksFixed scope after discovery
A payments product (wallet, lending, peer-to-peer)4 to 6 monthsFintech MVP, $40k to $80k
Monitoring and upkeepOngoingSupport retainer, $1.5k to $8k per month

Provider fees are separate and are paid to the provider. We help you compare them before choosing.

Next step

Tell us what you're building and get a written estimate.

A senior engineer replies within one business day. NDA on request.

FAQ

Questions we get asked a lot.

Which payment gateway should we use?

Stripe for most products, because of its APIs, documentation and Connect for marketplaces. Paddle when you want a merchant of record to handle global sales tax. Adyen or Braintree for specific regions or enterprise requirements. We compare fees and features for your case.

How do you prevent double charges?

Idempotency keys on every charge request, webhook events stored and de-duplicated before processing, and scheduled reconciliation against the provider's records.

Do we need to be PCI compliant?

Yes, anyone accepting cards does. Using hosted fields or tokenisation keeps card data off your servers and reduces your obligations to the shortest self-assessment.

Can you add marketplace payouts?

Yes. We use Stripe Connect for seller onboarding, identity verification, split payments, platform fees and payouts.

Can you handle Apple and Google in-app purchases?

Yes. We implement store subscriptions, validate receipts on the server and keep entitlements in step with your web billing.

Can you fix an existing payment integration?

Yes. We audit webhook handling, retries, secrets and reconciliation first, then fix the gaps that put revenue or customers at risk.