whats-best.ai
Search Sign in

Payment

SlimPay

Provenance unknown Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 2 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by SlimPay SAS · slimpay.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Skeptic

Weighted verdict

Knows the headline rate covers the cheapest card in the cheapest country. Reads for the currency conversion markup, the chargeback fee, the payout delay and the clause that lets the provider freeze funds without a reason — and treats a missing licence number as an answer.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Skeptic

Payment methods & local coverage

How this is scored

Which methods a European customer can actually pay with — cards and wallets, SEPA Direct Debit, and the local methods that decide conversion per country — judged on the named list per market rather than on a method count.

0 — Cards only, or a method list with no statement of which countries and currencies each one covers.

3 — Major cards and wallets plus one or two European methods, with local coverage stated vaguely ("many local methods") and no SEPA Direct Debit.

5 — Cards, Apple Pay and Google Pay, SEPA Direct Debit, and the main local methods for DACH and Benelux (iDEAL or Wero, Bancontact, Klarna or invoice) listed by name with the countries they serve.

8 — Broad EU coverage named per country — including methods such as BLIK, TWINT, Przelewy24, EPS and Wero — multi-currency acceptance with settlement currencies stated, and which methods support refunds and recurring charges documented per method.

10 — Coverage is documented as a matrix a merchant can plan against: every method with its countries, currencies, refund, partial-capture and recurring support, and the provider's own acquiring versus third-party routing stated per method.

Report an error

The Skeptic

The named list is SEPA Direct Debit, SEPA Credit Transfer and open banking, in euros only, across the euro zone — I found no public information on cards, wallets, or country-specific local methods such as iDEAL, Bancontact or BLIK, so any customer who pays by card is out of scope. Coverage is stated precisely (euro zone, thirty-four-country SEPA, EUR only), which I credit, but the breadth is one scheme family deep and single-currency. 1 3 4

Report an error

Checkout, SCA & fraud

How this is scored

The path from basket to authorised payment under PSD2: hosted and embedded checkout options, 3-D Secure and SCA exemption handling, fraud screening, and what the provider documents about keeping legitimate payments from failing.

0 — A single redirect page with no statement on 3-D Secure, SCA or fraud screening.

3 — Hosted checkout with 3-D Secure 2 mentioned, fraud screening as an unexplained add-on, and no word on exemptions or declined-payment handling.

5 — Hosted and embedded checkout options, 3-D Secure 2 with SCA handled by the provider, configurable fraud rules, and the resulting PCI DSS scope for each integration type stated.

8 — SCA exemptions (low value, transaction risk analysis, merchant-initiated) applied and documented, fraud tooling with rules and risk scores exposed to the merchant, network tokens or account updater, and liability shift explained per flow.

10 — Authorisation is engineered and shown: exemption strategy documented, soft-decline retry handled, authorisation-rate reporting by method and issuer country, and a checkout the merchant can run in their own domain while staying at the lowest PCI scope.

Report an error

The Skeptic

Four documented checkout modes — pop-in, iframe, redirect with white-label option, and full API control — plus mandate-with-document signing scenarios and a verified IBAN collected from the bank is more than a bare redirect page. But I found no public information on 3-D Secure, SCA exemption handling, merchant-configurable fraud rules or PCI DSS scope, and the only fraud statement in the captures is transaction monitoring owed under French anti-money-laundering law — a duty SlimPay owes its supervisor, not conversion protection for the merchant. 2 5 6

Report an error

Subscriptions & recurring payments

How this is scored

Charging the same customer again: card-on-file and merchant-initiated transactions, SEPA mandates, subscription logic and dunning — and whether the stored payment credentials can leave with the merchant.

0 — No stored payment methods; every charge needs the customer to pay again.

3 — Card-on-file tokens for repeat charges, but no SEPA mandate handling, no subscription logic, and failed-payment handling left entirely to the merchant.

5 — Stored cards and SEPA Direct Debit mandates, merchant-initiated transactions documented, and basic subscription plans with scheduled charges and failed-payment notifications.

8 — Subscription billing with trials, proration and plan changes, smart retries and dunning, card account updater, mandate management with pre-notification, and a documented process for exporting payment tokens to another provider.

10 — Recurring revenue is a first-class product: usage-based and invoice-based billing, dunning with measurable recovery, token migration in and out documented with a stated timeline and format, and recurring support stated for every local method that allows it.

Report an error

The Skeptic

Mandates are the core product and it shows: electronic signature combined with contract signing, one-off and recurring direct debits, payment plans, import of existing mandates with compliance validation, bulk import, export carrying the mandate reference and IBAN, revocation and IBAN change with history, plus a named automatic retry. I found no public information on pre-notification, dunning detail, or subscription logic such as trials and proration, and no card-on-file capability is evidenced — coherent for an account-to-account specialist, but plan management beyond a passing mention of payment plans is not shown. 1 5 8

Report an error

Settlement, reconciliation & API

How this is scored

Getting the money and knowing what it was: payout cadence and currencies, fee itemisation per transaction, reports that match a bank statement, and an API and webhooks a team can build finance processes on.

0 — Payouts on an unstated schedule, one net amount per payout, and no API or report beyond an on-screen list.

3 — A stated payout schedule and CSV exports, but fees netted invisibly into payouts and an API with thin documentation.

5 — Payout frequency and delay stated, per-transaction fee breakdown in reports, a documented REST API with webhooks and a test mode, and exports that link each payout to its transactions.

8 — Configurable payout schedules and settlement currencies, reconciliation reports that match bank lines, accounting integrations or exports named, a versioned API with idempotency and published rate limits, and a public status page with incident history.

10 — Finance can close the month from the provider's data: interchange and scheme fees itemised per transaction, automated reconciliation to the ledger, a deprecation policy for the API, and full historical data exportable after the contract ends.

Report an error

The Skeptic

Payout is stated as a 24-hour average, fees are itemised by named code — direct debits, rejects, returns, refunds, fund transfers — and appear as separate lines in a CSV account statement the provider itself describes as built for reconciliation, with balance, available funds and reserve laid out and report automation available on request. I found no public information on webhooks, a test mode, API versioning or a status page, and settlement is euro-only on a fixed 24-hour average rather than configurable schedules. 1 9 10

Report an error

Licence, risk & account terms

How this is scored

Who holds the merchant's money under which licence, and what the contract lets the provider do on a bad day: freezes, reserves, termination, chargebacks. Scored on what the terms and the imprint state, not on reputation.

0 — No regulated entity named; terms allow freezing funds and terminating the account at any time with no notice, reason or timeline.

3 — A licence mentioned without the entity, supervisor or register number, and terms that permit reserves and holds with no stated limits.

5 — The regulated entity named with its supervisor and licence type, safeguarding of merchant funds stated, chargeback fees and dispute process published, and a notice period for ordinary termination.

8 — Entity, supervisor, register number and passporting stated per country; reserve and rolling-hold conditions defined with limits and release timelines; freeze and termination terms with reasons and a route to appeal; PCI DSS level and attestation published.

10 — The bad day is written down: every regulated entity in the chain named with register links, reserve calculation disclosed, funds release timelines after termination committed, a documented complaint route to the supervisor, and exit terms that include handing back payment tokens and transaction history.

Report an error

The Skeptic

The regulated entity is named and real — SlimPay, a French payment institution authorised and supervised by ACPR, registered in Paris under number 518 991 336, acting as both processor and acquirer since 2012 — and the reserve is actually defined: a €300 minimum balance of fixed plus variable coverage held against rejected payments, with no fixed reserve for B2B direct debit. What I did not find is the bad-day paperwork: no safeguarding statement, no ACPR register number, and no published freeze, termination, notice-period or dispute terms at all. 1 2 10

Report an error

European sovereignty

How this is scored

Who the contracting and regulated entity is, and where transaction and cardholder data are processed and stored. Independently sourced by the sovereignty pipeline. The card schemes are US-based for every provider, so the scheme layer is not held against any one vendor; the part the vendor controls is.

0 — Non-EU contracting entity, no statement on where payment data is processed, and subprocessors unnamed.

3 — An EU licensed entity contracts, but payment and customer data is processed outside the EU by default without an explained safeguard, or the subprocessor list is absent.

5 — EU contracting and regulated entity, EU processing stated for core payment data, but the group parent or significant parts of the chain (fraud scoring, support, analytics) are non-EU without a stated safeguard.

8 — EU entity and EU licence, payment and cardholder data processed and stored in the EU on named infrastructure, subprocessor list published with locations, and a DPA covering the processing the provider does as processor versus as controller.

10 — Sovereign end to end and evidenced: European ownership, EU entity and licence, every processing location and subprocessor European, European rails (SEPA, Wero or national schemes) offered alongside cards, and certifications published.

Report an error

The Skeptic

An EU entity under an ACPR licence contracts, servers are stated to be located entirely within the European Union on named infrastructure (Amazon Web Services), and any transfer outside the EU/EEA is covered by adequacy decisions or standard contractual clauses. But the privacy policy itself permits processing in non-EU countries via SlimPay processors and Trustly Group affiliates, the host is US-headquartered with the CLOUD Act exposure that carries, and the data processor list is referenced but no named processors or locations are evidenced — the parent group's ownership is not documented here either. 1 2

Report an error

Pricing transparency not rated — the vendor publishes no price

How this is scored

Whether a merchant can compute the effective fee for their own mix of cards, countries and methods — including cross-border and currency conversion markups, chargebacks, refunds, payouts and monthly fees — from public pages alone.

0 — No public prices at all; every rate is a sales conversation.

3 — A headline percentage exists, but it is unclear which cards and countries it covers, and cross-border, currency conversion or chargeback fees are unstated — the effective fee is unknowable.

5 — Rates published per main method with domestic and international cards distinguished, but at least one commonly incurred cost (currency conversion markup, chargeback fee, payout or monthly fee) is missing or "on request".

8 — Every method priced publicly, cross-border and currency conversion markups stated, chargeback, refund and payout fees listed, minimum monthly fees and contract term given, and whether the model is blended or interchange++ said plainly.

10 — Complete fee computability: the effective rate derivable for a given volume, card mix and country mix — interchange++ with the markup published or a blended rate with every exception listed — plus volume tiers, reserves and every ancillary fee on a public page.

Report an error

The Skeptic

Not one rate appears anywhere I can see: I found no public information on the direct debit fee, the reject fee, the return fee, the refund fee or the fund transfer fee — only their existence as five named fee codes charged to the payment account on a monthly email invoice. The sole figure published is a €300 minimum balance coverage; for a mid-market and enterprise sales motion the effective cost of a merchant's own mix is a sales conversation, not a computable number. 9 10

Report an error

European sovereignty — proven facts

2 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency EU only ⚠ unverified 3/3 pts 2 Report an error
Subprocessors US CLOUD Act reach ⚠ unverified 0/2 pts 2 Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (10)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor page slimpay.com Checked 29 Sep 2026 Details →
  2. 2 Privacy policy — found from the homepage www.slimpay.com Checked 30 Sep 2026 Details →
  3. 3 Payment methods & local coverage — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →
  4. 4 Payment methods & local coverage — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →
  5. 5 Checkout, SCA & fraud — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →
  6. 6 Checkout, SCA & fraud — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →
  7. 7 Subscriptions & recurring payments — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →
  8. 8 Subscriptions & recurring payments — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →
  9. 9 Settlement, reconciliation & API — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →
  10. 10 Settlement, reconciliation & API — found from sitemap support.slimpay.com Checked 1 Oct 2026 Details →