★★★★★ Trustpilot 4.4|Hosted, tokenised card security

PCI compliant payment gateway with hosted card security

A PCI compliant payment gateway from eCom Pay keeps card data out of your systems entirely, through hosted payment pages and tokenised card storage. Your transactions run through payment infrastructure assessed against PCI DSS, as every payment provider must be, and your own compliance workload shrinks to match what you actually handle, which is almost nothing.

In brief Hosted payment pagesTokenised card storageCard data off your systemsSmaller PCI DSS scope

See if you're pre-approved

Answer a few quick questions for an instant pre-approval indication. No obligation, under 60 seconds.

Pre-approval progress 14%
How do you take payments?
Do you currently take card payments?
What is your industry?
How long have you been trading?
How is your business set up?
Estimated monthly card volume?
Strong match

Based on your answers you are a strong pre-approval match. Confirm a few details and we will finalise your application.

A real person reviews every application, and we never share your data.

24 hrs

approval, once documents are in

150+

currencies processed

4.4

Trustpilot rating

2010

processing payments since

Recently approved: Vape retailerRecently approved: Online pharmacyRecently approved: Dessert and food brandRecently approved: Automotive parts sellerRecently approved: Takeaway and ordering siteRecently approved: Travel agencyRecently approved: CBD storeRecently approved: Forex platformRecently approved: Crypto merchantRecently approved: Subscription boxRecently approved: Salon and bookingsRecently approved: Adult and datingRecently approved: Vape retailerRecently approved: Online pharmacyRecently approved: Dessert and food brandRecently approved: Automotive parts sellerRecently approved: Takeaway and ordering siteRecently approved: Travel agencyRecently approved: CBD storeRecently approved: Forex platformRecently approved: Crypto merchantRecently approved: Subscription boxRecently approved: Salon and bookingsRecently approved: Adult and dating

On this page Why it matters · What is included · How it works · In depth · FAQs

Why it matters

Why PCI DSS matters to every card-taking business

PCI DSS is the security standard every business taking card payments must meet, and most merchants meet it the hard way. The smarter route is a PCI compliant payment gateway designed so card data never enters your world in the first place.

Check your approval odds

The standard applies to you already

The Payment Card Industry Data Security Standard applies to every business that takes card payments, however small. What varies is the burden, and the burden follows the card data. The less of it your systems touch, the lighter your obligations become.

Breaches cost more than fines

Falling short of PCI DSS risks penalties, but a breach of stored card data costs far more, in remediation, in scheme consequences and in the customer trust that does not come back. The easiest card data to secure is the card data you never hold.

Compliance eats time you do not have

Self-assessment questionnaires, evidence gathering and annual reviews scale with your scope. Shrink the scope and the paperwork shrinks with it, which turns an annual dread into a manageable exercise.

What to check in any provider’s PCI answer The eCom Pay answer
Where card data is captured On hosted payment pages, never on your servers
Where card data is stored In a secure token vault, with your systems holding only harmless tokens
Your resulting scope Shrunk to match what you actually handle, typically the lightest route available
Authentication 3D Secure 2 built in, keeping you aligned with strong customer authentication rules
Guidance Plain-terms help with your self-assessment from a team that does this daily
Support A UK team on 0345 548 0072, around the clock
What is included

Security architecture that does your paperwork a favour

Every part of the setup is designed around one principle. Card data that never reaches your systems is card data you never have to secure, store, audit or explain.

Hosted payment pages

The payment form is hosted by the gateway, not your website, so card details are typed straight into secure infrastructure and never pass through your servers. Your checkout keeps your branding, your systems keep their innocence.

Tokenised card storage

Saved cards live in a secure token vault, with your systems holding only tokens that are useless to anyone who steals them. Returning customers get one-tap checkout, and you get nothing sensitive to protect.

3D Secure 2 as standard

Strong customer authentication runs through the checkout and Pay by Link, keeping your payments aligned with UK and EU authentication rules and shifting fraud liability on authenticated transactions away from you.

A smaller questionnaire

Because card data stays off your systems, your PCI DSS self-assessment typically falls into the lightest categories, with far less evidence to gather and far fewer controls to demonstrate each year.

Help with the form

Your account manager and our team talk you through the self-assessment in plain terms, so an annual formality stays a formality instead of becoming a project.

The same shield everywhere

Hosted, tokenised card security runs across the gateway, Pay by Link, the virtual terminal and recurring billing, so every channel you add inherits the same architecture automatically.

How it works

Getting compliant-by-design in four steps

  • Apply once, properlyexperienced underwriters process your application and guide you step by step, approved in 24 hours once your documents are in
  • Checkout goes hostedthe payment form runs on secure hosted infrastructure with your branding, and card data stops touching your servers
  • Storage goes tokenisedsaved cards move into the token vault, leaving your systems holding nothing a thief would want
  • Your assessment shrinksyour PCI DSS self-assessment now reflects a business that barely touches card data, with our team helping you complete it
Start your application
Card data audit
Card numbers on your servers 0
Capture hosted payment page
Storage token vault
3D Secure 2 active ✓
Status light touch
Hosted pagesToken vault3DS2SAQ guidance
Rated 4.4 on Trustpilot

What our merchants say

Fair. So here is what UK merchants say after switching to eCom Pay, in their own words.

★★★★★

No hidden fees, best so far

It was such a pleasure working with eCom Pay for my company, very straightforward to set up and the team were so helpful. No hidden fees, cost efficient, and from using other platforms before I can say this has been the best so far.

Verified merchantvia Trustpilot

★★★★★

Simpler than the big names

We found eCom Pay to be a simple, efficient payment system to integrate, with a lot of support behind it. Would recommend them over competitors who charge far too much.

Verified merchantvia Trustpilot

★★★★★

Set up fast, better rates

Great customer service from eCom Pay. Needed a card reader for my business, they had me set up fast and gave me better rates than the last company. Highly recommend.

Verified merchantvia Trustpilot

★★★★★

Sales noticeably improved

Super impressed with eCom Pay. The transaction fees are competitive, and I love that my customers have multiple payment options, which has noticeably improved my sales.

Verified merchantvia Trustpilot

★★★★★

Transparent, reliable, efficient

Good service from eCom Pay. The card machines are reliable and easy to use. I like that there are no hidden fees and everything is explained upfront.

Verified merchantvia Trustpilot

★★★★★

Always answers when I need help

Would highly recommend. Easy, simple, and always answers when I need help. The best payment gateway I have come across, with a wide variety of packages available.

Verified merchantvia Trustpilot

Especially valuable for

Small teams without security staffFast growing checkoutsSubscription businessesMulti-channel sellersSpecialist sectorsAnyone who dreads the annual form
In depth

How the architecture shrinks your scope

PCI DSS burden follows card data. This is how the setup moves that data, and the burden with it, away from your business step by step.

01

Capture moves off your site

Hosted payment pages mean the card number is typed into secure gateway infrastructure, not your website. Your servers never see it, so the systems you run day to day fall outside the hardest requirements.

02

Storage moves into the vault

Tokenisation replaces stored card numbers with tokens. What sits in your database is a meaningless string, which is precisely what you want a thief to find.

03

Transactions stay authenticated

3D Secure 2 verifies the customer with their bank during checkout, aligning you with strong customer authentication rules without adding friction for genuine customers.

04

The paperwork follows the data

With capture hosted and storage tokenised, your self-assessment typically lands in the lightest categories. Our team helps you complete it, and the same answers hold year after year because the architecture does not change.

Tokenisation has a full page of its own at payment tokenisation, and the wider security picture is covered in online fraud prevention.

FAQs

PCI compliance, straight answers

What is PCI DSS?

The Payment Card Industry Data Security Standard, a set of security requirements that applies to every business taking card payments. It governs how card data must be captured, transmitted and stored, and the depth of your obligations depends on how much card data your systems actually touch.

Is eCom Pay a PCI compliant payment gateway?

Yes. Your transactions run through payment infrastructure assessed against PCI DSS, as every payment provider must be, and the whole setup is designed so card data is captured on hosted pages and stored as tokens, keeping it out of your systems entirely.

Do I still need to be PCI compliant if I use a gateway?

Yes, every card-taking business has PCI DSS obligations. What a well designed gateway changes is the size of them. With hosted payment pages and tokenised storage your scope shrinks to match what you actually handle, and your self-assessment typically falls into the lightest categories.

What is a PCI self-assessment questionnaire?

The form most merchants complete annually to demonstrate PCI DSS compliance, known as an SAQ. Which version you complete depends on how card data flows through your business. The less your systems touch, the shorter the form, which is exactly what hosted, tokenised card security is designed to achieve.

How do hosted payment pages help with PCI DSS?

They move the point of capture off your website. The customer types their card number into the secure hosted form, styled with your branding, and your servers never receive it. Systems that never touch card data are systems you largely do not have to evidence.

How does tokenisation reduce PCI burden?

It removes stored card data from your side entirely. Saved cards live in a secure vault, your database holds only tokens, and a breach of your systems would expose nothing usable. Less sensitive data means fewer requirements, less evidence and less risk, all at once.

What happens if a business is not PCI compliant?

Non-compliance can bring penalties, higher costs and, after a breach, serious scheme consequences on top of the damage itself. The practical answer is to make compliance easy by design, which is what an architecture that keeps card data away from you does.

Will you help me with my PCI paperwork?

Yes. Your account manager and our team walk you through the self-assessment in plain terms, help you understand which questionnaire applies and how the hosted, tokenised setup answers most of it. There is no setup fee to apply, and approval takes 24 hours once your documents are in.

Written by the eCom Pay team. Reviewed August 2026. Last updated August 2026.

Security that protects your customers and your calendar

Card data captured on hosted pages, stored as tokens and kept off your systems, approved in 24 hours once your documents are in.

See every capability on the features hub, or read about payment tokenisation.

Call us Get approved