Pay50 for WooCommerce
Pay50 for WooCommerce lets your store accept credit and debit card payments through the Pay50 payment gateway. Card details are entered directly on your checkout page (server-to-server integration) — there is no hosted payment page — and are transmitted securely to the Pay50 API for authorization. When a 3-D Secure challenge is required, it can be shown as a full-page redirect (default) or, once your domain is whitelisted with Pay50 support, inside an iframe that keeps the customer on your site.
Features
- Frictionless (2DS) card payments captured instantly.
- 3-D Secure (3DS) challenge flow with automatic bank-OTP redirect and return handling.
- SHA-512 request/response signing for every API call.
- Client- and server-side card validation (Luhn checksum, expiry, CVV) and live card-brand detection.
- Card-on-file: optionally save the card at checkout and receive a token for merchant-initiated charges.
- Post-purchase upsell funnels: rule-based offers on the order-received page, charged to the saved card token.
- Status enquiry and automatic pending-order reconciliation via WP-Cron (or an external system cron).
- High-Performance Order Storage (HPOS) compatible.
- Sensitive data (card number, CVV, expiry) is never written to logs.
Requires WooCommerce. This plugin adds a payment method to WooCommerce and does not function on its own.
External services
This plugin connects to the Pay50 payment gateway API to authorize and settle card payments. This connection is required for the plugin to work as a payment method — without it, no payment can be processed.
What is sent, and when: when a customer places an order using Pay50 (and during any related status check, 3DS capture, or saved-card upsell charge), the plugin sends the following to the Pay50 gateway endpoint you configure in the settings, over HTTPS:
- Card data entered at checkout — card number, expiry date and CVV — used solely to authorize that payment.
- Billing details, and shipping details when provided — name, address, email and phone number.
- Order reference, amount and currency.
- Browser fingerprint values (user agent, language, screen size, timezone, accept header) required for 3-D Secure risk checks.
- When “Save Card for Upsells” is enabled: a request to store the card on file so post-purchase upsells can be charged to the returned token (no card number/CVV is re-sent for those charges).
What is received: the plugin receives payment results via the return URL (after a 3DS challenge) and via asynchronous webhook callbacks, and it can query transaction status on demand.
Data is transmitted only to the Pay50 gateway base URL configured in the plugin settings (your Pay50 live or sandbox endpoint). The plugin does not send data to the plugin developer and does not “phone home.”
Because raw card data is transmitted from your server, your store falls under PCI-DSS SAQ D scope. Ensure your hosting and site meet the relevant PCI-DSS requirements before going live.
- Service provider: Pay50
- Terms of Service: https://pay50.com/terms
- Privacy Policy: https://pay50.com/privacy
Legal disclosure — Pay50 Remit Ltd. (last updated May 14, 2026)
- FINTRAC MSB Registration Number: N300000269
- Incorporation: BC1578975 (British Columbia)
- Business Number: 736578238BC0001
- Registered Office: 555 Burrard St, Vancouver, BC, V7X 1M8, Canada
Pay50 is a registered Money Services Business (MSB) in Canada under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). FINTRAC registration does not constitute an endorsement, license, or approval of its services. Services provided include foreign exchange, money transferring, issuing/redeeming money orders, virtual currency dealing, and payment service provider (PSP) activities.
All suspicious transactions are reported to FINTRAC. Large cash and virtual currency transactions (CAD $10,000 or more) are reported as required by law. Pay50 is PCI DSS compliant, and customer funds and records are handled in accordance with Canadian AML/ATF regulations.
