
Written by: Kelly Campbell, Vice President of Marketing, Stayntouch
Key Takeaways
-
Hotel payment integration connects a PMS to payment gateways and processors so deposits, pre-authorizations, incremental holds, captures, refunds, voids, and chargebacks post directly to the guest folio.
-
Every payment event must update the PMS folio in real time. Gaps between successful payments and folio postings create manual reconciliation work and missed revenue discovered at night audit.
-
Tokenization and point-to-point encryption (P2PE) keep raw card data out of the PMS, which reduces PCI DSS scope, compliance cost, and security risk.
-
Built-in payment solutions collapse multiple vendor relationships into one provider for simpler support, faster settlement, and automated reconciliation. Third-party gateways and middleware add integration and billing complexity.
-
Stayntouch Pay delivers one provider, one bill, PCI DSS Level 1 security, two-business-day settlement, and 24/7 hospitality support. See how Stayntouch Pay simplifies payment integration.
How A Hotel Payment Flows Through The PMS
Every payment event in a hotel stay has a matching consequence in the guest folio, which tracks all charges, payments, and credits from check-in through checkout. The seven stages are:

-
Deposit – A payment collected before arrival, typically for non-refundable or advance-purchase rates. It creates a deposit folio entry against the reservation in the PMS before the guest arrives on property. A deposit charge is a permanent transaction that transfers funds immediately. If the guest cancels, the hotel issues a refund or retains the deposit per its cancellation policy.
-
Pre-Authorization – At check-in, the PMS places a temporary hold on the guest’s card for the estimated stay cost plus an incidentals buffer. No money moves, and the authorization reference is stored in the PMS against the folio. Under Visa’s Hotel and Lodging Authorization Rules, a hotel’s initial authorization at check-in can cover the estimated total stay amount plus up to 15% for incidentals.
-
Incremental Authorization – As the guest spends during the stay, the held amount must keep pace with the folio balance. An incremental authorization increases the existing hold rather than creating a new, disconnected authorization, so the final capture stays within an authorized amount. This pattern supports open-ended charges such as hotel stays where the guest adds nights or room service. The guest folio and the authorization stay aligned.
-
Capture – At checkout, the PMS converts the authorization into an actual charge. Money moves and the folio closes. Capture is the instruction that money should actually move. Without a capture, an authorization approval eventually expires and nothing is charged to the cardholder.
-
Refund – A credit posts against the reservation and the original transaction, returning funds already captured and settled. A refund is a new money movement, distinct from a void, and appears as a separate line item on the folio.
-
Void – A void cancels an authorization before capture. No money has moved, so nothing is returned. The hold is released, the guest’s available balance is restored, and the folio updates to reflect the reversal.
-
Chargeback – A guest disputes a charge with their card issuer after the fact. Friendly fraud accounts for an estimated 75 to 79% of all hotel chargebacks, driven by frictionless in-app dispute flows for charges guests did not personally see applied, such as resort fees, no-show charges, damage charges, and minibar items. The hotel loses by default unless it can produce documented evidence of the transaction and the guest’s agreement.
Every payment event has a PMS-side consequence. A system can handle the payment but fail to update the folio, or update the folio but fail to complete the payment. Either gap creates two versions of the truth that staff must reconcile by hand.
How A Payment Gateway Connects To A Hotel PMS
Three systems perform distinct roles in hotel payment architecture. The PMS holds the operational record, including reservation, stay, folio, and amount due. The payment gateway carries the payment instruction between the hotel workflow and the payment environment, then returns the transaction result. The acquirer processes the card transaction under the hotel’s merchant arrangement and participates in settlement.
A payment service provider (PSP) such as Stripe, Adyen, Worldpay, or Shift4 sits between the merchant and the acquiring bank, so the hotel never talks to the acquirer directly. PMS platforms such as Oracle OPERA Cloud, Cloudbeds, Mews, and Stayntouch connect to these providers through open APIs (standardized connections two software systems use to exchange data) and webhooks, which push information the moment something happens.
Hotels typically contract with the gateway, processor, and acquirer separately. That structure means several bills, several support numbers, and no single party who owns the problem when a payment fails. A payment can succeed at the acquirer while the corresponding posting in the hotel system fails, so staff must investigate the payment and the posting as separate states.
What Happens In The PMS When A Guest Pays
In a properly integrated system, charges post automatically from every revenue center directly to the guest folio as they happen. Point-of-sale (POS) systems in the restaurant and bar, spa, mobile booking flows, and self-service kiosks all feed the PMS. Occupancy tax and any additional local taxes apply instantly.

Night audit, the end-of-day process that closes out transactions and rolls the system into the next business day, reconciles payments automatically in a connected system. Every exception the operation does not catch at the folio-to-payment boundary resurfaces at the settlement and accounting layers as manual work for someone without the front desk context.
A missed charge is simply lost. Night audit is the point at which a missed charge is usually discovered, and by then the guest has checked out.
Tokenization And Point-To-Point Encryption For PCI Scope Reduction
The PCI Security Standards Council defines two mechanisms that underpin PCI DSS (Payment Card Industry Data Security Standard) Level 1 certification, the strictest tier of the card industry’s security standard.
Tokenization replaces a card number with a meaningless substitute value, or token, so the real card data is never stored in the PMS. Systems that hold only tokens generally fall outside the scope of the full PCI DSS standard, while the token vault operator requires its own PCI DSS validation as a Level 1 service provider.
Point-to-point encryption (P2PE) encrypts card data from the moment it is entered until it reaches the processor, so attackers cannot read it in transit. Only a PCI-listed, validated P2PE solution attracts formal scope reduction. Non-validated encryption may be technically similar but does not provide the same relief, because the relief comes from the solution being assessed and listed.
Together, tokenization and P2PE reduce the number of system components a hotel must prove compliance over. This shrinks the scope of the annual assessment and lowers the cost of maintaining it.
Built-In Payment Solution Vs. Third-Party Gateway Vs. Middleware For Hotels
The architecture decision is not binary. Three approaches exist, and the table below compares them on four factors that shape day-to-day operational burden: how many providers the hotel contracts with, who owns support when a payment fails, how much processor flexibility the hotel retains, and how much reconciliation work lands on staff.
|
Architecture |
Provider Relationship |
Support Ownership |
Flexibility |
Reconciliation |
|---|---|---|---|---|
|
Built-in payment solution |
One provider handles processing, acquiring, and settlement. A PMS with embedded payments folds the merchant account, gateway, and processor into the same system guests and staff already use. |
Single point of contact. One support number owns the problem end to end. |
Less flexibility to keep a preferred processor, because the payment layer is designed to work closely with the PMS. |
Payment data flows directly into the PMS folio. PMS-native payments automate manual tasks by linking each transaction to the right reservation, invoice, guest profile, and booking source. |
|
Third-party gateway |
Hotel contracts separately with gateway, processor, and acquirer. Interchange-plus pricing is transparent and typically cheaper for higher-volume hospitality venues. |
Multiple vendors share responsibility. When a payment fails, no single party clearly owns the problem. Multi-vendor dependencies and blurred accountability are a documented payment failure mode, with warning signals including vendors responding “not our issue” and incidents taking days to diagnose. |
Hotel keeps its choice of processor and can shop on rate. |
Hotel takes on the integration work and the reconciliation. Several bills and several reports must be matched. |
|
Middleware |
An integration layer connects the PMS to the PSP. Middleware or orchestration layers required for PMS, POS, and payment connectivity add cost and operational risk. |
Another vendor enters the chain, so support hand-offs occur between middleware provider, PMS, and PSP. |
Can preserve existing hardware and processors, which is useful during migrations or for legacy estates. |
Adds a translation layer between systems. Reconciliation complexity increases with each additional vendor. |
For most hotels, the real decision is which approach fits their operational model, volume, and staff capacity. A built-in solution reduces complexity at the cost of processor flexibility. A third-party gateway preserves flexibility at the cost of integration work and reconciliation overhead. Middleware preserves existing infrastructure at the cost of another vendor relationship.
The Failure Modes That Drive Daily Friction
Generic payment integration guides often stop at “the PMS talks to the gateway.” Daily operations reveal a messier reality. Four failure modes account for most of the friction staff feel at the front desk and in finance.
Failed pre-authorization at check-in. When a pre-authorization declines, the guest cannot be checked in without a valid hold. If a payment appears to have succeeded but the PMS has not been updated, the hotel should establish the state of the original transaction before attempting another charge, because retaking it risks a duplicate charge. The front desk needs a clear, documented procedure that defines who owns the exception, what the guest is told, and what happens to the folio in the meantime.
Incremental authorization gaps during the stay. A common error occurs when room charges added during a stay exceed the original authorization without a new incremental authorization being sent. If a hotel authorizes $500 at check-in and the guest adds $200 in room charges but the hotel settles at $700 without a new authorization for the difference, that $200 gap may not be covered and can be disputed by the guest’s bank. Not all PMS systems handle incremental authorizations automatically.
Chargebacks lost by default. Most independent hotels answer only about 40% of the chargebacks they receive, and unanswered chargebacks are automatic merchant losses regardless of the underlying merit. The network response deadline is typically 7 to 14 days, and missing it is automatic merchant loss. Useful chargeback evidence includes the booking confirmation, cancellation policy, authorization disclosure, signed registration record, itemized folio, and any guest communications. The friendly-fraud share noted earlier makes consistent responses even more important.
Night audit reconciliation gaps. Hotel payment reconciliation spans five records, including guest folio, payment transaction, acquirer settlement, bank statement, and accounting ledger, with four boundaries between them. A payment-focused night audit should verify that all successful payments appear in the PMS, that no folio postings lack a corresponding payment transaction, and that failed authorizations are identified before the business date rolls.
What To Ask A Vendor Before Signing
Before committing to a payment integration, every hotel IT director, finance controller, and general manager should get clear answers to these questions:
-
Does the payment solution store card data, or tokenize it at the point of capture?
-
Is the solution certified to PCI DSS Level 1?
-
How many days after transaction are funds settled?
-
Who owns the support relationship when a payment fails, the PMS vendor, the gateway, or the processor?
-
Can the hotel keep its preferred processor, or is one dictated?
-
Are there per-transaction fees, and which vendor charges what?
-
Is the integration included in the PMS contract, or listed as a separate line item?
Pricing models vary significantly. Interchange-plus pricing is transparent and benchmarkable. Flat-rate pricing is simpler but can become expensive at hospitality transaction volumes. Blended rates obscure the individual components. A slightly higher processing fee can still be the better commercial choice if the payment system reduces failed payments, manual posting, and finance workload. Evaluate total cost of ownership, including processing fees, gateway fees, chargeback fees, reconciliation labor, and settlement timing, rather than the headline rate alone. Those criteria are exactly where an integrated payment layer changes the math, which is why Stayntouch Pay was built into the PMS rather than bolted alongside it.
Why Stayntouch Is The Best Solution For Hotel Payment Integration With PMS
Stayntouch Pay handles every stage of payment facilitation, including processing, acquiring, and settlement, rather than sitting as one link among several. The result is one transparent bill per month and funds settled two business days after transaction, compared with slower cycles that leave money in transit for up to six days.
Stayntouch Pay is certified to PCI DSS Level 1. Tokenization replaces raw card numbers with meaningless substitute values, and point-to-point encryption scrambles card data from the moment it is entered until it reaches the processor. Raw card numbers are never exposed in the PMS.
When something goes wrong, Stayntouch Pay provides 24/7 priority payment support staffed by hospitality specialists who understand hotel operations. Because the same provider handles processing, acquiring, and settlement, that support team can resolve issues end to end without handing them off to a gateway or processor.
Stayntouch is a cloud-native PMS built on AWS with 100% system uptime as a sustained performance record and 1,400+ integrations with unlimited connections at no additional cost. Users must pay each third-party platform its own platform fee, while Stayntouch charges nothing for the integration itself. This includes the payment and POS systems hotels already run, such as Shift4, Toast, Oracle Micros, and Lightspeed, so the hotel keeps its choice of stack.
Stayntouch builds deep on the PMS and its guest-facing surround, including Booking, Channel Manager, Pay, Kiosk, and Guest Messaging, and integrates with specialist providers for revenue management, CRM, food-and-beverage POS, and central reservation systems. For payments, this architecture keeps control of the payment processor with the hotel rather than a closed suite.
According to Stayntouch customer data, multi-property management runs portfolios 70% more efficiently from a single multi-property dashboard. Automated charge posting from every revenue center delivers up to a 42% improvement in accounting efficiency. Charges post from POS, spa, mobile booking, and the Grab & Go Kiosk directly to the guest folio as they happen, so staff avoid manual intervention and missed charges at night audit.

See what a best-in-class PMS actually feels like. Book a demo of Stayntouch Pay.
Frequently Asked Questions
What Is Hotel Payment Integration With PMS?
Hotel payment integration with a property management system (PMS) is the technical connection that allows the PMS to initiate card payments, hold authorizations, post charges to a guest’s folio, and reconcile transactions. It does this by communicating with a payment gateway or payment service provider (PSP), which routes the transaction through the card network to the guest’s issuing bank and back. Without this connection, payment data must be entered manually, which creates errors, reconciliation gaps, and missed charges.
Does The PMS Store Card Numbers?
In a properly configured system, the PMS does not store card numbers. Tokenization replaces the primary account number (PAN) with a meaningless substitute value at the point of capture, so the real card number never sits in the PMS. The token travels between systems. When a charge needs to run, the PMS passes the token to the payment platform, which retrieves the underlying card data from its vault and processes the transaction. PCI DSS Level 1 certification, combined with point-to-point encryption (P2PE), ensures that raw card data is never exposed in the hotel’s own systems.
What Is The Difference Between A Pre-Authorization And A Capture?
A pre-authorization is a temporary hold placed on a guest’s card at check-in, reserving funds without transferring them. The guest’s available balance decreases, but no money moves. A capture is the instruction that converts the authorization into an actual charge, so money moves from the issuing bank through the card network to the hotel’s merchant account. Without a capture, the authorization eventually expires and nothing is charged. In hotel operations, the pre-authorization is placed at check-in and the capture occurs at checkout, with incremental authorizations keeping the hold aligned with the folio balance during the stay.
What Happens If A Pre-Authorization Fails At Check-In?
A failed pre-authorization means the hotel does not have a valid hold on the guest’s card, and the guest cannot be checked in without one. The front desk needs a documented procedure that establishes whether the failure is a decline from the issuing bank, a communication failure between the PMS and the gateway, or a posting failure where the payment succeeded but the PMS was not updated. Attempting a second charge before confirming the state of the first risks a duplicate. The correct path is to diagnose the failure, communicate clearly with the guest, and resolve it before assigning a room.
How Does Tokenization Reduce PCI Scope?
PCI DSS scope is determined by which systems store, process, or transmit cardholder data. When tokenization replaces card numbers with tokens at the point of capture, the systems downstream of that capture, including the PMS, folio, night audit data, and any connected integrations, hold only tokens rather than card numbers. This removes those systems from the full PCI DSS scope, reduces the number of requirements the hotel must demonstrate compliance with, and shrinks the cost of the annual assessment. The token vault itself remains in scope and must be maintained by a PCI DSS-validated provider.
Can A Hotel Keep Its Existing Payment Processor?
The answer depends on the architecture. A built-in payment solution typically requires using the PMS vendor’s own processing and acquiring infrastructure, which simplifies operations but removes processor choice. A third-party gateway or middleware approach allows the hotel to keep its preferred processor, but adds integration work, reconciliation overhead, and multiple support relationships. Stayntouch Pay handles processing, acquiring, and settlement as a single provider, while the broader Stayntouch PMS integrates with payment and POS systems hotels already run, including Shift4, Toast, Oracle Micros, and Lightspeed.
How Long Does It Take For Funds To Settle?
Settlement timing varies by payment provider and architecture. A single-provider model that handles processing, acquiring, and settlement can deliver funds in two business days after transaction. Multi-vendor arrangements, where the gateway, processor, and acquirer are contracted separately, can leave money in transit for up to six days, depending on each provider’s settlement cycle. Settlement speed affects working capital directly, particularly for properties with seasonal demand or thin operating margins, and deserves the same scrutiny as headline processing rates when evaluating a payments partner.
Conclusion: Simplify The Payment Chain
A hotel payment is not a single transaction. It is a lifecycle of seven distinct events, including deposit, pre-authorization, incremental authorization, capture, refund, void, and chargeback, and each event has a specific consequence in the guest folio. A payment system can handle the transaction but fail to update the folio. It can also update the folio but fail to complete the payment. Either gap creates operational failures that compound across every shift, night audit, and chargeback dispute.
The architecture decision, whether built-in solution, third-party gateway, or middleware, determines how many vendors own the problem when something goes wrong, how many bills arrive at month end, and how quickly funds land in the hotel’s account. For most hotels, collapsing that chain into one provider is the clearest path to operational control.
Stayntouch Pay delivers one provider, one transparent monthly bill, PCI DSS Level 1 security with tokenization and point-to-point encryption, funds settled in two business days, and 24/7 priority support from hospitality specialists. It sits inside a cloud-native PMS with the settlement speed and integration breadth described above.
Ready to simplify hotel payment integration with PMS? Talk to our payments team about simplifying your payment chain.
Read Next
Turn a more connected stack into a better stay.
See how Stayntouch can support the operating moments that matter most to your hotel team.