WWooshPayment docs
Get started

How WooshPayment works

Checkout architecture, the roles of Shopify, Whop and WooshPayment, and the customer flow from cart to confirmed order.

4 min read

WooshPayment replaces your store's standard checkout with a branded checkout at {slug}.wooshpayment.com (or checkout.yourstore.com if you map a custom domain), optimized for mobile checkout and Whop embedded payments.

Architecture Overview

Customer โ†’ "Checkout" on your store (Shopify/Woo)
              โ†“ (ScriptTag intercepts the click)
WooshPayment checkout (slug.wooshpayment.com or checkout.yourstore.com)
              โ†“ (Whop iframe for payment)
Whop โ†’ card / eligible wallet โ†’ authorization
              โ†“ (HMAC-SHA256 signed webhook)
WooshPayment marks the session COMPLETED
              โ†“ (Shopify/Woo API)
Order created on your store โ†’ standard fulfillment flow
              โ†“
"Order confirmed" customer email sent by WooshPayment with store branding
Merchant notification email sent by us

Roles

ComponentRole
Your store (Shopify/WooCommerce)Catalog, inventory, fulfillment, invoicing and order state
WooshPaymentCheckout UX, branding, order sessions, redirect, analytics dashboard, order sync to your store, branded customer order confirmation
WhopCards, eligible wallets when supported, anti-fraud, payouts to the merchant's account
ResendWooshPayment transactional emails: customer order confirmation, merchant notifications, verify/welcome/password reset, domain and payment-readiness alerts

The end customer's order confirmation is sent by WooshPayment with the store name and the checkout language when available. Shopify receipt is disabled to avoid duplicates; WooCommerce may still have its own emails/plugins enabled. See Transactional emails.

Customer flow step by step

  1. Customer opens your store, adds to cart
  2. Click on "Checkout" โ†’ our ScriptTag intercepts and redirects to {slug}.wooshpayment.com/checkout/{token}
  3. Sees your brand (logo, color, font) in mobile-first
  4. Enters email + address + selects shipping + selects payment method
  5. Pays inside the Whop iframe (3D-Secure when required) โ€” optionally Cash on Delivery
  6. Whop โ†’ WooshPayment webhook HMAC signed: marks the session COMPLETED
  7. WooshPayment โ†’ Shopify/Woo: calls the Orders API, creates the real order with line items + financial_status: paid
  8. "Order confirmed" email to the customer is sent by WooshPayment, branded with the store name
  9. Merchant notification email is sent by us via Resend

Where the money goes

Whop deposits directly into the merchant's bank account. WooshPayment never touches the money. From the Whop dashboard you'll find:

  • Settlements: payouts to your IBAN (weekly by default, monthly on new accounts until Whop verifies)
  • Transaction history with detailed fees
  • Anti-fraud tools and dispute management

Whop processing fees are separate from WooshPayment and are shown in your Whop account before traffic. WooshPayment charges the platform plan only. See Plans and pricing.

Domains

  • Free subdomain: {slug}.wooshpayment.com, automatically generated from the store name at signup, automatic Vercel SSL
  • Custom domain: checkout.yourstore.com (see guide) โ€” available to all merchants without plan gating

Security & compliance

  • PCI-DSS: handled by Whop (level 1). Cards NEVER pass through our servers: the Whop iframe sends them directly to them.
  • 3D-Secure: enforced by Whop on risky transactions.
  • Anti-fraud: Whop computes a risk score; high-risk orders are flagged.
  • Encryption at rest: Whop API key, Shopify accessToken and Woo consumer secret are encrypted AES-256-GCM in our DB.
  • Rate limit: 10 login / 5 register per IP / 15 min. Signed JWT. bcrypt cost-12 passwords with timing-equalize anti-enumeration.
  • GDPR: we are data processor, you are data controller. See GDPR.

Who WooshPayment is for

WooshPayment serves dropshippers whose mainstream payment processor (Stripe, Shopify Payments, Airwallex, etc.) disabled or rejected their account. Typical cases:

  • Stripe account banned after a chargeback spike on a trending product
  • "Your application has been declined" email from Shopify Payments for a high-risk category
  • Mollie / Adyen / Airwallex onboarded, processed a few transactions and then closed the account
  • Brand new store that wants a high-risk-friendly processor from day 1 to avoid the 60-day ban risk

If you're NOT in those scenarios โ€” premium DTC brand with Stripe active for years, low-risk products, marketplace or B2B โ€” mainstream processors work fine for you and WooshPayment is not the right tool.

WooshPaymentStripe / Shopify Payments direct
Dropshipping high-risk acceptedYes (via Whop)No (systematic ban/reject)
Restart after ban10 min โ€” connect Whop and you're backImpossible: a banned account stays banned
Onboarding / KYCWhop review timing depends on merchant profile, documents and risk checks1-4 weeks + high-risk categories rejected
Custom domain + branded checkoutYesNo (checkout under Stripe/Shopify domain)
WooCommerce supportedYesStripe yes, Shopify Payments no
Typical transaction feeSet by Whop and shown in your Whop accountStripe standard rate if your account is active