Skip to content

Buyer's guide

Virtual POS or payment institution?

The store rule comes first: what you sell decides the question before POS does. Then the difference between a bank's virtual POS and a payment institution, the application paperwork and the reasons for rejection.

Written for: Companies preparing to take card payments in an app or on a siteLast updated: 9 min read

In short

To take payments in an app, do you need a virtual POS or a payment institution?

The answer depends on what you sell. If you sell digital content or subscriptions inside an app, you must use the store's own payment system; a virtual POS cannot touch that sale. For physical goods and real-world services you can build your own: a bank's virtual POS or a payment institution licensed by the Turkish central bank. In Türkiye that licence rests on Law No. 6493.

The question that comes first: what are you selling?

The payments discussion usually starts in the wrong place. “Which virtual POS is cheaper” skips a prior question: is what you sell consumed inside the app, or delivered in the real world? That distinction decides the whole matter, because in the first case you have no choice to make.

For digital content and subscriptions consumed inside the app, the store's own payment system is mandatory. For physical goods and services delivered in the real world you can build your own stack — and pay no store commission on those sales. Teams that compare POS providers before settling this spend months planning the wrong integration.

Searches this page answers

  • virtual pos or payment gateway which
  • documents needed for virtual pos application
  • why was my payment gateway application rejected
  • in-app purchase store commission rules
  • how to check a licensed payment institution
  • compare payment gateway commission rates
  • storing card data pci dss scope
  • payment institution vs bank pos

What is the difference between a bank POS and a payment institution?

Both let you take card payments, but the relationship sits in a different place. With a bank's virtual POS your counterpart is the bank itself; if your account is already there the money path is short and the commission is part of your commercial relationship. With a payment institution a licensed intermediary steps in: it aggregates several banks' POS behind one integration, takes on instalment and campaign management, and takes its own share in return.

The choice usually falls out like this: with a deep single-bank relationship and low transaction variety, a bank POS stays simple. If you need multi-bank instalments, several payment methods, fast setup and one integration, a payment institution removes a serious amount of work.

A comparison frame — read quotes along these rows
CriterionBank virtual POSPayment institution
CounterpartThe bank directlyA licensed payment institution
IntegrationsOne per bankMany banks behind one
Setup timePaperwork and allocationUsually shorter
InstalmentsTied to the bank's campaignAggregated by the institution
CostCommission + settlement delayCommission + institution's share
SupervisionBanking regulationCentral bank licence (Law 6493)

What paperwork does a virtual POS application need?

The list varies by provider but the core is constant: tax certificate, signature circular, trade registry gazette, certificate of activity and the company's bank details. With those ready, the paperwork is a day's work. The real delay does not come from documents, it comes from your website.

The provider also reviews the page you sell on. It looks for a distance sales contract, a refund and cancellation policy, delivery terms, clearly visible prices, the company's legal name and contact details, and a valid certificate. These read like a compliance checklist, but their function is risk assessment: the provider is looking for a page that can show who sold what when a chargeback arrives.

How do you verify a licensed institution?

Providing payment services in Türkiye requires authorisation, and the authorisation is issued by the central bank under Law No. 6493. The institutions in operation and the scope of their permissions are published on the central bank's own page.

Before signing, check two things: whether the institution is on the list, and whether the scope of its permission covers what you need. The scope distinction is easy to miss — an institution may be authorised for some payment services and not others, and providing an unauthorised service on your behalf makes both of you liable.

How do you compare commission, settlement and instalments?

Looking at the commission rate alone is misleading. The total cost of the same transaction has four parts: the commission rate, the settlement delay before money reaches your account, the rate that climbs with the number of instalments, and the deduction applied on refunds and chargebacks. Put all four in the same table when comparing two quotes.

For cash flow, settlement delay is often more decisive than commission. A one-point difference in commission is easily wiped out by three extra days of settlement — particularly in a business financing its own stock.

Can you hold card data on your own servers?

The moment card data enters your systems your PCI DSS scope grows. The standard covers every environment where cardholder data is processed, transmitted or stored, and brings with it obligations from network segmentation and logging to access management and regular testing.

For most businesses the right architecture is never to receive card data at all: with a hosted payment page or iframe the card details go from the browser straight to the provider and only a token comes back to you. Recurring billing runs on that token too, so a subscription model does not require you to store cards.

Sources

  1. 016493 sayılı Ödeme ve Menkul Kıymet Mutabakat Sistemleri, Ödeme Hizmetleri ve Elektronik Para Kuruluşları Hakkında KanunT.C. Mevzuat Bilgi Sistemi · 2013
  2. 02Ödeme Hizmetleri ve Elektronik Para İhracı MevzuatıTCMB · 2021
  3. 03App Store Review GuidelinesApple · 2025
  4. 04Service feesGoogle Play Console Help · 2026
  5. 05PCI DSS v4.0 — Ödeme kartı veri güvenliği standardıPCI Security Standards Council · 2022

Frequently asked

Questions we get asked

If it is a digital subscription consumed inside the app, no. The stores' rules require their own payment system for that sale, and steering users to your own checkout can be treated as a policy violation. The rule looks at whether what is sold is consumed inside the app; a subscription fee for a service delivered in the real world is a different case. For borderline models, decide from the text of the relevant store policy, not from a guess.

From the central bank's own page. Operating licences for payment and electronic money institutions are issued by the Turkish central bank, and the licensed firms together with the scope of their permissions sit in a public list. That is the only place to check before signing; a “we are licensed” line on the provider's own site is not verification. Scope matters too: not every institution is authorised for every payment service.

Most rejections are about the website, not the technology. Providers assess the page where you sell and look for what should be there: a distance sales contract, a refund and cancellation policy, delivery terms, clearly visible prices, the company's legal name and contact details, and a valid certificate. If one is missing the application comes back without anyone looking at your product. The second reason is sector: some lines of business sit on providers' risk lists, and you find out only when you are rejected.

Technically possible, but the wrong decision for almost every business. The moment card data enters your systems your PCI DSS scope grows, opening a list of obligations that runs from network segmentation and logging to penetration testing and access management. With a hosted payment page or iframe the card data never touches you; that is the cheapest and fastest way to shrink the scope.

Let's walk these steps together

We can stand alongside you while you apply any of this to your own project.