How WooshPayment works
Checkout architecture, the roles of Shopify, Whop and WooshPayment, and the customer flow from cart to confirmed order.
WooshPayment replaces your store's standard checkout with a branded checkout at {slug}.wooshpayment.com (or checkout.yourstore.com if you map a custom domain), optimized for mobile checkout and Whop embedded payments.
Architecture Overview
Customer โ "Checkout" on your store (Shopify/Woo)
โ (ScriptTag intercepts the click)
WooshPayment checkout (slug.wooshpayment.com or checkout.yourstore.com)
โ (Whop iframe for payment)
Whop โ card / eligible wallet โ authorization
โ (HMAC-SHA256 signed webhook)
WooshPayment marks the session COMPLETED
โ (Shopify/Woo API)
Order created on your store โ standard fulfillment flow
โ
"Order confirmed" customer email sent by WooshPayment with store branding
Merchant notification email sent by us
Roles
| Component | Role |
|---|---|
| Your store (Shopify/WooCommerce) | Catalog, inventory, fulfillment, invoicing and order state |
| WooshPayment | Checkout UX, branding, order sessions, redirect, analytics dashboard, order sync to your store, branded customer order confirmation |
| Whop | Cards, eligible wallets when supported, anti-fraud, payouts to the merchant's account |
| Resend | WooshPayment transactional emails: customer order confirmation, merchant notifications, verify/welcome/password reset, domain and payment-readiness alerts |
The end customer's order confirmation is sent by WooshPayment with the store name and the checkout language when available. Shopify receipt is disabled to avoid duplicates; WooCommerce may still have its own emails/plugins enabled. See Transactional emails.
Customer flow step by step
- Customer opens your store, adds to cart
- Click on "Checkout" โ our ScriptTag intercepts and redirects to
{slug}.wooshpayment.com/checkout/{token} - Sees your brand (logo, color, font) in mobile-first
- Enters email + address + selects shipping + selects payment method
- Pays inside the Whop iframe (3D-Secure when required) โ optionally Cash on Delivery
- Whop โ WooshPayment webhook HMAC signed: marks the session
COMPLETED - WooshPayment โ Shopify/Woo: calls the Orders API, creates the real order with line items +
financial_status: paid - "Order confirmed" email to the customer is sent by WooshPayment, branded with the store name
- Merchant notification email is sent by us via Resend
Where the money goes
Whop deposits directly into the merchant's bank account. WooshPayment never touches the money. From the Whop dashboard you'll find:
- Settlements: payouts to your IBAN (weekly by default, monthly on new accounts until Whop verifies)
- Transaction history with detailed fees
- Anti-fraud tools and dispute management
Whop processing fees are separate from WooshPayment and are shown in your Whop account before traffic. WooshPayment charges the platform plan only. See Plans and pricing.
Domains
- Free subdomain:
{slug}.wooshpayment.com, automatically generated from the store name at signup, automatic Vercel SSL - Custom domain:
checkout.yourstore.com(see guide) โ available to all merchants without plan gating
Security & compliance
- PCI-DSS: handled by Whop (level 1). Cards NEVER pass through our servers: the Whop iframe sends them directly to them.
- 3D-Secure: enforced by Whop on risky transactions.
- Anti-fraud: Whop computes a risk score; high-risk orders are flagged.
- Encryption at rest: Whop API key, Shopify accessToken and Woo consumer secret are encrypted AES-256-GCM in our DB.
- Rate limit: 10 login / 5 register per IP / 15 min. Signed JWT. bcrypt cost-12 passwords with timing-equalize anti-enumeration.
- GDPR: we are data processor, you are data controller. See GDPR.
Who WooshPayment is for
WooshPayment serves dropshippers whose mainstream payment processor (Stripe, Shopify Payments, Airwallex, etc.) disabled or rejected their account. Typical cases:
- Stripe account banned after a chargeback spike on a trending product
- "Your application has been declined" email from Shopify Payments for a high-risk category
- Mollie / Adyen / Airwallex onboarded, processed a few transactions and then closed the account
- Brand new store that wants a high-risk-friendly processor from day 1 to avoid the 60-day ban risk
If you're NOT in those scenarios โ premium DTC brand with Stripe active for years, low-risk products, marketplace or B2B โ mainstream processors work fine for you and WooshPayment is not the right tool.
| WooshPayment | Stripe / Shopify Payments direct | |
|---|---|---|
| Dropshipping high-risk accepted | Yes (via Whop) | No (systematic ban/reject) |
| Restart after ban | 10 min โ connect Whop and you're back | Impossible: a banned account stays banned |
| Onboarding / KYC | Whop review timing depends on merchant profile, documents and risk checks | 1-4 weeks + high-risk categories rejected |
| Custom domain + branded checkout | Yes | No (checkout under Stripe/Shopify domain) |
| WooCommerce supported | Yes | Stripe yes, Shopify Payments no |
| Typical transaction fee | Set by Whop and shown in your Whop account | Stripe standard rate if your account is active |