Digital-goods payments for SaaS businesses.
Cardflo offers payment orchestration for SaaS businesses. Optimise your recurring revenue, reduce churn, and expand globally.
Our platform supports the specific needs of subscription-based software providers.
- Industry
- SaaS businesses
- Category
- Digital
- Cardflo support
- Yes
The overview
Software-as-a-Service (SaaS) payment processing needs a specialised approach. It must manage recurring billing cycles.
It also handles a high volume of Merchant Initiated Transactions (MITs). SaaS models rely on continuous validity of stored payment credentials.
This ensures uninterrupted service delivery. This differs from one-off retail purchases.
These businesses operate within a digital goods framework. They often cross borders.
This adds complexity for regional compliance, tax, and local acquiring. The primary technical challenge is managing a subscription's lifecycle.
This goes from initial authorisation via Strong Customer Authentication (SCA) to automated rebilling. SaaS providers use network tokenisation and account updater services.
This maintains high authorisation rates. It also manages card expiries.
Efficient handling of soft declines is essential. This includes automated retries and smart routing.
Routing occurs between multiple acquirers. This minimises involuntary churn.
It stabilises Monthly Recurring Revenue (MRR). This technical infrastructure connects the billing engine and global payment schemes.
It moves funds from the cardholder to the merchant settlement account.
How it works
Initial Authorisation and Tokenisation
The process starts when a customer initiates a subscription. The gateway captures payment data. It performs an initial authorisation. This often needs 3DS verification. This satisfies SCA requirements under PSD2. Following a successful transaction, sensitive data is replaced. It uses a persistent token. This allows for secure storage. It enables subsequent Merchant Initiated Transactions. No re-entering of details is needed.
Automated Billing and Scheduling
At each billing interval, the platform triggers an authorisation request. It uses the stored token. It also uses the original transaction identifier. This identifies the payment to the issuer. It marks it as a recurring sequence. The request is routed through the acquirer to the card schemes. This ensures the transaction adheres to specific recurring payment flags. These flags are required for high acceptance.
Smart Routing and Retries
An authorisation may fail due to a soft decline. This could be temporary insufficient funds. It could also be technical timeouts. The system applies logic to find the best recovery path. This may involve routing the transaction through an alternative acquirer. It may also retry the payment at an optimised time. This is based on historical issuer behaviour patterns.
Credential Management and Updates
The system interacts with card scheme account updaters. This prevents declines from expired or lost cards. This service provides the PSP with the new card number. It also gives the new expiry date. This happens before the next billing cycle. Tokenisation further helps. It maintains a link to the bank account. This happens even if the physical card changes.
Why it matters
Reduction of Involuntary Churn
Involuntary churn happens when a subscription is cancelled. This is due to payment failure. It is not due to customer intent. SaaS businesses can recover many failed transactions. They use automated retry logic. They also use account updaters and network tokens. This directly impacts the customer's lifetime value. It ensures consistent revenue streams. Even small improvements in recovery rates compound. This happens over the subscription lifecycle.
Global Scalability and Localisation
SaaS products are global by nature. Payment preferences differ by region. Supporting local Alternative Payment Methods (APMs) can improve conversion. Local acquiring can also improve conversion. Processing transactions through a local acquirer has benefits. It results in lower interchange fees. It also has higher authorisation rates. This is compared to cross-border processing. Cross-border processing is often flagged as higher risk by issuers. It can also be subject to higher scheme fees.
Regulatory notes
PSD2 and SCA Compliance
SaaS providers in the European Economic Area must follow PSD2 mandates. This means implementing 3DS for initial signup.
This establishes a 'mandate' for future payments. Subsequent transactions must be correctly flagged as Merchant Initiated (MIT).
Failure to do so will cause high decline rates. Issuers will enforce SCA requirements.
The merchant must keep proof of the customer's agreement. This proves agreement to the recurring billing terms.
This defends against potential disputes.
PCI-DSS Data Security
Any SaaS entity handling cardholder data must comply. They must follow Payment Card Industry Data Security Standards.
A vaulted or tokenised approach reduces the compliance burden. This is done through a PSP.
The burden is often reduced to SAQ A or A-EP levels. However, the merchant remains responsible.
They must ensure their front-end environment does not expose sensitive data. Proper implementation of hosted fields is required.
Side-by-side integration is also required. This minimises risk exposure.
Use cases
B2B Enterprise Software
High-value enterprise subscriptions often need support for many payment methods. These go beyond cards. Examples are SEPA or BACS direct debits. Effective payment orchestration allows these merchants to manage complex billing terms. It also handles higher transaction limits. This occurs across multiple regional jurisdictions.
Consumer Content Subscriptions
Streaming or media services have low monthly costs. Transaction speed is vital. Low processing cost is also vital. Automated dunning management helps. Proactive card updates ensure small-ticket recurrences do not fail. This maintains the user base. It requires no manual intervention.
Global Expansion Scenarios
A SaaS provider may move into new territories. They can use a multi-acquirer setup. This routes traffic to local players. This avoids the high cost of cross-border fees. It reduces the likelihood of issuers blocking international payments. This prevents blocks during the initial authorisation phase.
By the numbers
This range reflects typical performance improvements. These are seen when moving from basic payment setups. They show improvements to optimised recurring billing architectures.
These figures are based on scheme-reported averages. They are for digital merchants. These merchants implement Mastercard and Visa token services.
This represents the typical delta. It is between cross-border processing. It is also for domestic routing. This applies to digital subscription services.
Related terms
Book a scoping call to see how Cardflo would set you up.
What's included.
- Dynamic routing of recurring transactions based on acquirer performance and historical authorisation data
- Automated account updater integration to refresh expired or replaced card details before billing
- Network tokenisation to improve authorisation rates and reduce PCI-DSS compliance scope for merchants
- Support for PSD2 compliant Merchant Initiated Transactions through correct 3DS and flagging protocols
- Comprehensive retry logic for soft declines to minimise revenue loss from technical failures
- Multi-acquirer connectivity to reduce dependency on a single PSP and provide redundancy
- Local currency settlement to avoid excessive foreign exchange costs for international customer bases
- Integration with Alternative Payment Methods like wallets and direct debits for global reach
- Granular analytics for tracking churn, success rates, and decline reasons by MCC and BIN
- Secure vaulting of customer payment methods to facilitate smooth upgrades and add-on purchases
Talk to an acquiring specialist about your MID setup.
Common questions.
How does 3-D Secure 2.0 impact recurring SaaS subscriptions?
Under PSD2 regulations, the initial transaction in a subscription series usually requires Strong Customer Authentication (SCA) via 3DS. Once the first payment is authorised and authenticated, subsequent payments in the cycle are typically classified as Merchant Initiated Transactions (MITs).
These subsequent transactions are generally exempt from SCA, provided the initial agreement was correctly flagged.
However, issuers may still request a challenge if they perceive a high risk, making it necessary for SaaS providers to have a robust 3DS infrastructure to handle both the initial friction and potential step-up requests.
What is the difference between a soft decline and a hard decline in SaaS?
A soft decline occurs when the issuer declines the transaction for a temporary reason, such as 'insufficient funds' or a 'system error.' These can often be successfully retried later.
A hard decline is a permanent refusal, such as 'stolen card' or 'account closed,' where retrying will not result in a successful payment and may lead to scheme penalties.
Recognising the specific decline reason code is critical for SaaS businesses to decide whether to trigger dunning emails or attempt a secondary routing strategy.
Can network tokens improve authorisation rates for recurring payments?
Yes, network tokens are issued by the card schemes (Visa, Mastercard) and remain valid even if the underlying physical card is replaced or expires.
Because network tokens are kept current by the schemes and banks, they carry higher trust signals than standard tokens or raw card numbers.
This often results in higher authorisation rates and a reduction in declines related to lifecycle events, which is particularly beneficial for the long-term billing cycles characteristic of SaaS models.
Why is a multi-acquirer strategy beneficial for a digital software provider?
Relying on a single acquirer creates a single point of failure and may lead to lower approval rates in certain regions where that acquirer lacks a local presence.
By using multiple acquirers, a SaaS business can route transactions to the partner most likely to succeed based on the card's BIN and country of origin.
This also provides leverage during fee negotiations and ensures business continuity if one acquirer experiences technical downtime or changes its risk appetite for certain MCCs.
What role does the Merchant Category Code (MCC) play for SaaS?
The MCC, such as 5734 for Computer Software Stores or 4816 for Computer Network/Information Services, tells the issuer the nature of the business. Using the correct MCC is vital for risk profiling and ensuring that the transaction is not incorrectly flagged as high-risk or fraudulent.
Incorrect classification can lead to higher decline rates and may result in fines from the card schemes if the business activity does not match the registered code.
How can I manage cross-border fees for global software sales?
Cross-border fees are applied by schemes when the acquirer and issuer are in different regions. To minimise these costs, SaaS businesses can establish local entities and use local acquirers in their largest markets.
If this is not feasible, using a PSP with a broad global footprint and smart routing capabilities can help ensure that transactions are processed through the most cost-effective rails, potentially reducing the impact of interchange and scheme-fee markups.
Related industries.
Related guides.
Ready for velocity?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.
