Payment Processing

Merchant of Record vs. Payment Facilitator (PayFac): What's the Difference?

9 min read
Comecero Team
By Comecero Team
Merchant of Record vs. Payment Facilitator (PayFac): What's the Difference?
Merchant of Record vs. Payment Facilitator (PayFac) explained — what a payfac is, how it differs from an MoR on tax, liability, and compliance, and which model is right for your business.

Merchant of Record vs. Payment Facilitator (PayFac): What's the Difference?

Quick answer: A payment facilitator (payfac) lets you accept payments fast as a sub-merchant under its master account, but you remain the legal seller — tax, compliance, and most liability stay with you. A merchant of record (MoR) becomes the legal seller itself and takes on global tax remittance, chargebacks, and compliance in full.

If you're setting up payments for a software or digital business, you'll quickly run into these two models that sound similar but carry very different responsibilities. Both help you accept payments. Only one takes the tax and legal liability off your books.

Here's the short version: a payment facilitator gets you accepting payments fast under a shared merchant structure. A merchant of record becomes the legal seller and assumes the full liability that comes with the sale and tax, chargebacks, compliance. The gap between those two is where a lot of businesses get caught out, usually around tax time.

This guide explains what a payfac actually is, how it differs from an MoR, and which model fits your business. For the foundational background, see our guide to what a merchant of record is.

What is a payment facilitator (payfac)?

A payment facilitator is a third-party service that lets businesses accept payments online without setting up their own merchant account. The payfac creates a single master merchant account with a payment processor and onboards many businesses as sub-merchants underneath it.

That structure is the whole appeal. Opening your own merchant account directly with an acquiring bank is costly and can take months of underwriting. A payfac collapses that into a fast, simple signup — which is why payfacs are popular with small businesses, startups, and software platforms that want to get customers paying quickly. Stripe and Square are the names most people know.

A payfac typically handles payment processing, some fraud prevention, chargeback management, and technical PCI compliance for its sub-merchants. What it generally doesn't do is become the legal seller or take on tax liability. (For the full model, see our guide to what a payment facilitator is.)

What is a merchant of record (MoR)?

A merchant of record is the legal entity authorized and held liable for selling goods or services to the end customer. When you sell through a third-party MoR, it becomes the seller of record: its name appears on the customer's statement, and it assumes responsibility for the financial, legal, and compliance side of every transaction.

An MoR covers everything a payfac does and then the parts a payfac leaves to you. Because it's the legal seller, it takes on global sales tax and VAT calculation and remittance, chargeback and fraud liability, full PCI compliance, and the banking and card-network relationships. Common examples of merchants of record include Paddle, the Apple App Store, and the Google Play Store.

The core difference: who handles tax and liability?

Strip it down and the distinction is about how much responsibility transfers off your plate.

A payfac solves acceptance. It gets you taking payments under its master account, fast. But you generally remain responsible for tax, regulatory compliance, and often customer service for billing issues. This is the part that surprises people: payment facilitators don't calculate, file, or remit your sales tax. That stays with you, which is why businesses on a payfac usually have to buy separate sales-tax software to stay compliant across US states and international VAT/GST. (For example, Stripe operates as a payfac; its tax product is a separate purchase.)

A merchant of record solves acceptance plus liability. As the legal seller, it handles the tax calculation and remittance in every jurisdiction, absorbs chargeback and fraud risk, and owns compliance — so you don't bolt on extra tools or carry the exposure yourself.

In short: a payfac takes on some merchant roles; an MoR takes on all of them.

Merchant of record vs. payment facilitator: side-by-side

Responsibility Payment Facilitator (PayFac) Merchant of Record (MoR)
Legal seller of the transaction You (sub-merchant) The MoR
Fast onboarding without your own merchant account Yes Yes
Payment processing Yes Yes
Sales tax / VAT / GST calculation & remittance You (often via separate software) MoR handles it
Chargebacks & disputes Often shared / yours MoR is liable
Fraud prevention Some Comprehensive
PCI compliance Technical layer; ultimate responsibility may stay with you MoR's responsibility
Global expansion You manage tax/compliance per market MoR enables it out of the box
Cost Lower base cost Higher fee (liability + compliance priced in)
Best for Small/local businesses wanting fast acceptance Businesses selling internationally wanting liability offloaded

Is Stripe a payment facilitator or a merchant of record?

This comes up constantly. Standard Stripe operates as a payment facilitator — it gets you accepting payments quickly, but you remain the merchant of record and keep the tax and compliance liability. Stripe's tax automation is a separate product you add on. Square works similarly. So if you're using a payfac and assuming tax is "handled," it's worth double-checking — in most cases it isn't.

(For the closely related comparison with PSPs, see Merchant of Record vs. Payment Service Provider)

Payment facilitator compliance requirements

Compliance is where the two models diverge most sharply, because a payfac and an MoR are complying with completely different things. Understanding what each one is actually on the hook for explains why the fee difference exists.

What a payment facilitator must comply with

A registered payfac carries a substantial regulatory load, all of it centered on payment acceptance rather than the sale itself:

  • Card network registration. Payfacs must register with Visa, Mastercard, and other networks through a sponsoring acquirer, and maintain that registration with periodic renewals and reporting.
  • Sub-merchant underwriting and KYC. Verifying identity, business legitimacy, and beneficial ownership before onboarding anyone, then keeping those records current.
  • AML and sanctions screening. Anti-money-laundering programs, sanctions list checks, and suspicious activity reporting, with the exact obligations varying by jurisdiction.
  • Ongoing transaction monitoring. Watching sub-merchant activity for fraud, laundering, and prohibited categories on a continuous basis rather than at onboarding alone.
  • PCI DSS Level 1. The highest tier of payment card security compliance, with annual audits, because the payfac handles cardholder data across its entire portfolio.
  • Volume thresholds. The card networks set limits on how much a single sub-merchant can process under a master account. Cross the threshold, historically around $1 million in annual card volume, and the sub-merchant is generally required to move to its own merchant account.
  • Settlement and funds handling rules. Requirements around how quickly funds reach sub-merchants and how reserves are held, which can touch money transmission licensing in some jurisdictions.

What the payfac model leaves with you

Here's the part that catches businesses out. Everything above is about payments compliance. None of it is tax compliance.

As a sub-merchant you remain the legal seller, which means you keep:

  • Sales tax, VAT, and GST obligations in every jurisdiction where you have nexus or cross a registration threshold, including calculation, collection, filing, and remittance
  • Economic nexus monitoring across US states, where thresholds differ and change
  • EU VAT obligations on digital services, which apply from your first sale into the bloc with no minimum threshold
  • Product liability and consumer-protection duties in each market you sell into
  • Your own PCI scope, which varies with how you integrate but never disappears entirely

This is why so many businesses on Stripe or Square end up buying separate tax software. The payfac solved payment acceptance and left the compliance that scales with international growth exactly where it was.

How MoR compliance differs

A merchant of record complies with everything a payfac does, then adds the layer the payfac model excludes. Because the MoR is the legal seller, it registers for and remits consumption taxes in the jurisdictions it sells into, absorbs chargeback liability rather than passing it back, and carries the consumer-protection obligations attached to the sale.

The practical test when comparing providers: ask who is contractually liable for remitting VAT in the EU on your sales. A payfac will tell you that's your responsibility. An MoR will tell you it's theirs. That single answer is the whole difference, and it's worth getting in writing. (For the full model, see our guide to what a payment facilitator is.)

Where payfac and MoR sit among payment models

These aren't the only two models — and the surrounding vocabulary trips people up, so here's the quick map:

  • Payment processor — moves the money between banks; a component, not a full solution. A payfac sits on top of a processor, aggregating many sub-merchants; the processor itself just executes transactions. (Full breakdown of every layer: PayFac vs. Payment Processor vs. Gateway.)
  • Payment gateway — the technology layer that securely transmits payment data from your checkout to the processor. Neither a payfac nor an MoR is "just" a gateway; both use gateways under the hood. (Full comparison: Merchant of Record vs. Payment Gateway.)
  • ISO (Independent Sales Organization) — a reseller of traditional merchant accounts. Unlike a payfac, an ISO doesn't hold the master merchant account or own the sub-merchant relationship; it brokers you a direct account with an acquirer. PayFacs onboard you in minutes under their own account; ISOs place you into your own account with longer underwriting.
  • Payment aggregator — in practice, another name for the payfac model: many merchants aggregated under one master account. (For who the major providers are, see payfac companies.)
  • Merchant acquirer: the bank that actually holds merchant accounts and carries ultimate financial risk. A payfac sits underneath an acquirer, holding one master account with it and onboarding sub-merchants beneath that, which absorbs underwriting the acquirer would otherwise do itself. Acquirers work with merchants directly, while payfacs aggregate merchants the acquirer never assesses individually.
  • Marketplace: a platform where independent sellers transact with buyers. The structures overlap, since many marketplaces operate as payfacs to process payments for their sellers. The difference is the commercial relationship, because a marketplace owns the buyer experience and the seller relationship while a payfac is purely payment infrastructure. Under marketplace facilitator laws in the US and equivalent rules elsewhere, marketplaces increasingly must collect and remit sales tax on seller transactions, an obligation payfacs generally do not carry.
  • Merchant account — your own direct account with an acquiring bank; full control, slow and costly to set up.
  • Seller of record (SoR) — the entity legally responsible for the commercial sale (a full MoR plays this role). See Seller of Record vs. Merchant of Record for the full distinction.

The payfac and MoR models are simply two points on a spectrum from "just help me accept payments" to "take the entire sale and its liability off my hands."

Which model is right for your business?

There's no universally correct answer — it depends on stage, geography, and how much compliance you want to own.

A payfac tends to fit when you:

  • Are small, early-stage, or locally focused
  • Want to start accepting payments fast without your own merchant account
  • Sell mainly in one market with simpler tax rules
  • Have the capacity (or tax software) to manage compliance yourself

A merchant of record tends to fit when you:

  • Sell internationally and face VAT, GST, and multi-state sales tax
  • Run subscriptions or usage-based billing with cross-border complexity
  • Want chargeback, fraud, and compliance liability off your books
  • Would rather not buy and maintain separate tax tooling
  • Are scaling faster than your finance and compliance capacity

A simple rule of thumb: if managing tax and compliance yourself is starting to cost more, in money, time, or risk — than an MoR's fees, it's time to move up the spectrum.

Where this matters most

The payfac-vs-MoR decision gets sharpest for:

FAQ

Frequently asked questions

Everything else you might be wondering about.

The bottom line

A payment facilitator gets you accepting payments quickly but leaves tax and liability with you. A merchant of record becomes the legal seller and takes the whole compliance burden tax, chargebacks, PCI off your books. For small or local businesses, a payfac's speed and lower cost often make sense. As you sell internationally or your billing gets complex, the MoR model turns a growing pile of obligations into one relationship.

If you're weighing which model recovers the most revenue while keeping you compliant, talk to the team at Comecero. We build merchant-of-record and billing infrastructure for SaaS, AI, and high-ticket sellers — without the complex setup.

Ready to Simplify Your Payment Operations?

Discover how Comecero's Merchant of Record platform can help you expand globally with ease.