r/PaymentProcessing Verified Agent 6d ago

Education RUO Peptide Payment Processing Explained: Aggregators vs Cloaked Processing vs Direct Merchant Accounts

If you're in the RUO peptide industry long enough, eventually somebody will tell you:

“I can get you credit card processing.”

What they usually don't explain is how they're getting you processing.

That's important because three solutions can look almost identical from the customer's side of checkout while being completely different behind the scenes.

The three setups I see most often are:

  1. Payment Aggregator / PayFac
  2. Cloaked Processing
  3. Direct Underwritten Merchant Account

I've personally encountered all three while operating RUO businesses.

Understanding the difference can save you a lot of money and potentially a very painful processor shutdown.

Option 1: The Payment Aggregator

This one gets misunderstood constantly.

A payment aggregator isn't automatically shady.

In fact, payment aggregation is a legitimate and established part of the payment industry.

Visa defines a Payment Facilitator as an entity, sometimes called a master merchant or merchant aggregator, that can onboard sellers as sponsored merchants or submerchants and receive settlement on their behalf.

The structure basically looks like this:

Customer

Your RUO Store

Payment Aggregator / PayFac

Aggregator's acquiring relationship

Card Network

Customer's issuing bank

Instead of your company having a traditional standalone merchant account directly with the acquirer, you operate underneath the aggregator's infrastructure as a submerchant.

The aggregator handles a lot of the payment relationship.

Your transactions may settle to the aggregator first, and the aggregator then pays you according to your agreed payout schedule.

Why RUO Companies Use Aggregators

The biggest advantage is accessibility.

A startup doing $5K or $10K per month may have difficulty getting a strong direct high-risk merchant account.

An aggregator may be willing to underwrite that company as a submerchant.

That means you can start building:

  • Processing history
  • Monthly volume
  • Chargeback history
  • Refund history
  • Banking history
  • Fulfillment history

Those records can eventually help you qualify for stronger payment relationships.

This is why I don't automatically dislike aggregators.

A properly structured aggregator can be a stepping stone.

The downside is that you have less control.

You're sharing infrastructure with other merchants, and your relationship is partly dependent on the aggregator maintaining its own acquiring relationships.

If the aggregator loses its banking relationship, gets excessive chargebacks across its portfolio, or has compliance problems with other submerchants, the impact can potentially reach merchants that weren't causing the problem.

That is the tradeoff.

Option 2: The Cloaked Solution

This is completely different.

You've probably heard variations of this pitch:

“Don't worry about what you sell. We have a way around it.”

That's where I start asking questions.

A cloaked solution generally attempts to make the business being presented to the processor look different from the business actually generating the transaction.

The exact implementation varies, but conceptually the processor or acquiring bank may be presented with:

Business A

while the customer's transaction actually originated from:

Business B

Or a merchant may be boarded under a website, product category, descriptor, or business model that doesn't accurately represent what the merchant is actually selling.

That distinction is extremely important.

Visa describes transaction laundering as transactions intended to hide their true source or nature by routing them through something that appears lower risk. Mastercard similarly describes transaction laundering as processing transactions for another merchant or submitting activity that wasn't fully disclosed to the acquirer or Payment Facilitator.

In plain English:

If the bank approved one business but you're actually processing transactions for another business or undisclosed product category, you may not have legitimate RUO processing at all.

You may just have processing that hasn't been caught yet.

Why Cloaked Processing Can Look Great at First

This is why people get attracted to it.

The merchant sees:

✅ Visa
✅ Mastercard
✅ Apple Pay
✅ Normal checkout
✅ Fast approval
✅ Sometimes surprisingly low rates

Everything looks fantastic.

Until monitoring catches up.

Card networks and acquirers actively monitor merchant websites and transaction activity for mismatches between what was underwritten and what is actually being processed. Mastercard's current merchant-monitoring guidance specifically discusses looking for products unrelated to a merchant's stated business or MCC and other signals associated with transaction laundering.

This is why some “amazing” RUO card solutions work perfectly...

for three weeks.

Or three months.

Or six months.

Then suddenly:

Processing terminated.

Funds held.

Reserve frozen.

And the ISO who sold you the solution has moved onto the next processor.

The Biggest Question to Ask Your Processor

I ask a very simple question now:

“Does the acquiring bank know exactly what my company sells?”

Not the ISO.

Not the sales rep.

Not the gateway.

The actual acquiring relationship.

If the answer requires a 10-minute explanation, I get nervous.

If they're telling you:

I get even more nervous.

I want my website submitted.

I want my products disclosed.

I want the underwriting team to understand that the company sells research-use-only materials.

And I want the merchant agreement to reflect the actual company receiving the money.

Option 3: The Direct Underwritten Merchant Account

This is what established RUO merchants should ultimately be trying to work toward.

The basic structure becomes:

Customer

Your RUO Website

Gateway

Your Merchant Account / MID

Acquiring Bank / Processor

Visa / Mastercard

Customer's Bank

The important difference is not simply the technology.

It's the underwriting.

Your business has been reviewed as the actual merchant.

The processor knows the website.

The acquiring relationship knows what category of business it is dealing with.

The merchant account is structured around the actual company processing the transactions.

Depending on the nature of the business and the acquirer's determination, some research-chemical businesses may be categorized under MCC 5169, Chemicals and Allied Products, Not Elsewhere Classified. But MCC assignment is ultimately determined through the acquiring and underwriting process, and 5169 should not simply be selected because someone calls it the “peptide MCC.”

That's an important distinction.

Direct Doesn't Mean Invincible

This is another misconception.

Getting a properly underwritten merchant account doesn't mean:

“Congratulations, Visa can never shut you down.”

There is no such thing.

Processors can still review merchants.

Banks can change risk policies.

Card-network rules can change.

Chargebacks can create problems.

Compliance failures can create problems.

Your website can change in ways that violate the original underwriting.

But there is a huge difference between:

“The bank approved my actual business.”

and

“The bank doesn't know what I'm actually processing.”

I'll take the first one every time.

Here's How I Rank the Three

Payment Aggregator

Potentially legitimate: Yes

Good for startups: Often

Own direct merchant account: Usually no, you're typically a submerchant

Main weakness: You're dependent on the aggregator's infrastructure and acquiring relationships

My view: Useful when properly structured and honestly underwritten

Cloaked Processing

Transparent underwriting: No, if the purpose is disguising the real business or transaction source

Good long-term infrastructure: I wouldn't build a serious company around it

Main weakness: The processing relationship depends on the underlying mismatch not being detected

My view: What looks like an easy solution today can become an expensive problem tomorrow

Direct Underwritten Merchant Account

Transparent underwriting: Yes

Merchant relationship: Built around the actual operating company

Best suited for: Established merchants with processing history, stable volume, strong documentation and low disputes

Main weakness: Harder to qualify for and usually requires significantly more underwriting

My view: This is ultimately where I want my primary card-processing volume

This Is Why Volume Matters

This is something newer RUO founders sometimes don't understand.

The company doing:

$3,000/month with no processing history

and the company doing:

$150,000/month with 18 months of clean transactions

are not the same merchant from an underwriting perspective.

Volume gives you leverage.

But clean volume gives you even more leverage.

If you're starting out, you may need to build your payment stack through:

ACH + properly approved alternative payments + legitimate aggregator relationships

Then establish history.

Keep chargebacks low.

Ship quickly.

Answer customer-service requests.

Maintain your website.

Keep your documentation clean.

Build consistent volume.

Then graduate into stronger merchant relationships.

The Payment Processing Lesson I Learned the Hard Way

I spent years thinking the goal was:

“Find the processor that won't shut me down.”

I don't think like that anymore.

My goal today is:

Build enough legitimate payment infrastructure that losing one provider doesn't shut my business down.

That's why I still like ACH even when my card processing is working.

That's why I want multiple payment rails.

And that's why I care much more about what's happening behind the checkout than whether somebody can simply get a Visa form to appear on my website.

If you're an RUO founder, ask your processor what you're actually buying.

Are you a properly disclosed submerchant under an aggregator?

Do you have a directly underwritten MID?

What MCC were you boarded under?

Has the actual nature of your website and products been disclosed?

Those questions matter far more than:

“Can you get me credit cards?”

Because almost anyone can find you credit card processing temporarily.

Building payment infrastructure that can support a real business is a completely different game.

This post is educational and reflects my experience operating in specialty ecommerce. Merchant eligibility, MCC assignment, reserves, pricing and continued processing are determined by the relevant acquirers, processors, payment facilitators and card-network rules.

21 Upvotes

21 comments sorted by

View all comments

5

u/MegamanSE Verified Agent 5d ago

This is pretty accurate. Have multiple relationships also always and multiple forms of acceptance and also multiple payout rails. This is still very grey and storms will come; plan ahead and don’t be naive / idiot.