

Square Payments
By Block, Inc.
Typical implementation process for Square Payments:
Sign up for a Square account and complete basic identity verification online; this typically takes just a few minutes, and you can start taking payments immediately after activation.
Link a bank account or choose Square Banking for deposits; bank-account verification for transfers usually takes one to three business days, but does not block you from accepting payments.
Download the Square Point of Sale app and, if needed, purchase or connect Square hardware (reader, stand, terminal, register); hardware setup and pairing generally takes under an hour.
Configure items, taxes, and basic settings in the Square Dashboard (catalog, locations, users), which, for a small catalog, can be completed in a few hours and expanded over time.
Square Payments is highly customizable and can be tailored to many different business models, from retail and restaurants to services, e‑commerce, and invoicing. You can customize items, modifiers, options, variations, categories, taxes, discounts, and unit types so that your catalog reflects your exact products, services, and pricing structures. The Point of Sale checkout screen is configurable, letting you choose which payment types to show, reorder them, and even add custom payment types so your records match how you actually get paid (e.g., house accounts, third‑party gift cards, “other” methods). Payment links and online checkouts can be branded with your logo, colors, and customized payment options such as tips, service charges, coupons, taxes, fulfillment rules, and what customer information you collect. In contrast, digital receipts and invoices can be branded with your logo, policies, and custom messages. For developers, Square’s Web Payments SDK and APIs enable deep customization of the card entry form (style, layout, dark mode) and bespoke workflows that integrate payments with your own apps, CRMs, or industry systems. Beyond payments, the wider Square ecosystem offers configurable user roles, permissions, team management, and integrations via the App Marketplace and APIs, meaning you can shape Square into a lightweight solution for a microbusiness or a more complex, integrated system for multi‑location operations.
Square Payments offers a mix of self-service education, structured courses, and live support to help new users get up and running quickly. The Square Support Center provides an extensive, searchable knowledge base with step-by-step articles on setup, payments, hardware, invoicing, online sales, and troubleshooting, which many sellers use as their primary “manual.” Square Academy adds more structured learning with free courses and webinars covering product basics, onboarding, and optimization—for example, multi-hour curricula for Square for Retail or POS that walk through dashboard use, inventory, reports, and hardware choices. For day-to-day questions, new users can access in-product help tips, contextual onboarding checklists, and community forums where other sellers and Square moderators answer questions, plus official support channels including chat and phone support during business hours. Square also publishes blog content and dedicated “how to use Square” guides with practical training tips for owners and employees, such as practicing different payment types during quiet times, troubleshooting connectivity, and using Square’s YouTube tutorials for visual walk-throughs.
Square Payments uses a layered security model that combines encryption, PCI compliance, fraud detection, and strict privacy controls to protect both merchants and their customers. All sensitive payment data is encrypted end to end: card details are encrypted within the Square reader or client app at the moment of swipe, dip, or tap and transmitted over encrypted connections to Square’s servers, regardless of whether you use public or private Wi‑Fi or mobile data. Square’s card-processing systems are certified to Level 1 PCI Data Security Standards, which is the highest level for the payments industry, meaning merchants who use Square for storing, processing, and transmitting card data do not need to handle their own PCI validation for those transactions.
Square also runs continuous monitoring and fraud prevention. Its systems and servers are monitored around the clock by dedicated security staff, and Square employs industry‑leading machine-learning models that analyze transactions in real time to detect suspicious behavior and stop fraudulent activity before it completes. EMV chip support, built directly into Square hardware, further reduces in‑person card-present fraud. If disputes or chargebacks occur, Square provides integrated dispute management and works with card networks on the merchant’s behalf, helping protect their revenue while keeping cardholder data secure.
On the organizational side, Square enforces strict internal security policies: software is built following security best practices, employees operate under security and privacy policies designed to keep data safe, and Square’s privacy notices explicitly state that it will not sell customer information to third-party vendors. All customer information sent to Square’s servers is encrypted, and card data is tokenized so merchants never see or store raw card numbers. Together, these measures—encryption at capture and in transit, PCI Level 1 compliance, 24/7 monitored infrastructure, machine‑learning fraud detection, EMV hardware, robust dispute support, and strong privacy commitments—form the backbone of Square Payments’ data protection strategy.
Square Payments is updated frequently, and most updates are delivered automatically with minimal user intervention.
Square’s dedicated payment hardware (Square Terminal, Square Register, and Square Handheld) typically receives software updates every 2 to 4 weeks, with official support articles stating a regular cadence of “every 2 weeks” and community threads noting updates in roughly the 2–8 week range depending on device and region. These updates can include both firmware changes and new versions of the Square Point of Sale app running on the device, and usually take about 15–20 minutes, but can sometimes run up to an hour, depending on network speed and the size of the release. By default, they are scheduled to run automatically overnight around 3 a.m. local time, as long as the device is plugged in, powered on, and connected to the internet, to avoid disrupting business hours; users can change the scheduled reboot/update time, or choose to defer recommended updates until the nightly window.
On the software side, Square publishes ongoing product updates and new features across payments, POS, inventory, orders, menus, and sign‑in via its public release notes, which show new releases roughly every two weeks as well. These updates are managed centrally by Square and applied either automatically in the cloud (for backend and dashboard changes) or through app updates on iOS, Android, and hardware devices; merchants usually see them appear as new options or settings without needing to run a manual upgrade. For transparency, Square now also maintains a public product roadmap and biannual release events, and says it updates that roadmap quarterly to reflect planned enhancements and gather customer feedback. Legacy hardware like first‑generation Square Terminal and Square Register eventually age out of this cycle; official notices specify that as of September 1, 2025, those older devices no longer receive software updates, even though they can still take payments.
Square’s policies distinguish between who owns what data, how it can be used, and how easily you can export it, but they do not position Square as a pure “data custodian” that simply holds data you fully control.
From an ownership and usage standpoint, Square’s privacy notices and information-collection policies state that it collects various categories of personal and business data (e.g., transaction details, customer information, device and network data) to provide secure payment processing and related business services. Square emphasizes that it does not sell customer information to third‑party vendors, and uses the data primarily to operate and improve its services, comply with legal obligations, and help protect merchants from fraud, all under the terms of its Seller Privacy Notice and Data Processing Agreement. In legal terms, Square acts as a data controller for some data and as a processor for others, depending on jurisdiction and use case, but either way its contracts and privacy documents govern how it may process, retain, and share that data.
For portability, Square provides several export mechanisms that effectively give merchants practical control over their business data. The Square Dashboard lets you export transaction histories, payout reports, item sales, customer lists, and other reports as CSV files, which you can then import into accounting systems or new providers. Integrations with tools like QuickBooks, Xero, and other accounting or analytics platforms also synchronize data out of Square automatically, providing another form of portability. However, like most PSPs, Square does not advertise “card-on-file token portability” as a standard feature: stored card credentials and tokens live inside Square’s PCI‑compliant environment and generally cannot just be bulk‑migrated to another processor; if you switch PSPs, customers usually have to re-enter their card details with the new provider.
Square’s Data Processing Agreement and privacy notices also describe data subject rights (such as access, correction, and deletion) under applicable privacy laws, and provide contact channels for merchants or buyers to request copies of their personal data or ask for it to be deleted, subject to legal and contractual retention requirements. In practice, this means you can download most operational data (transactions, customers, reports) whenever you want, but Square retains certain records for compliance, fraud prevention, and regulatory reasons even if you close your account.
If you’re building a comparison matrix, the concise takeaway is: merchants have broad practical access and export options for their business data through reports and integrations, but Square maintains legal control over payment tokens and some underlying personal data, and it does not position itself as offering full, standards-based.
Square Payments is designed to scale up or down flexibly, with terms that avoid locking businesses into long commitments so they can adapt as their needs change. Its standard processing plans use simple, pay‑as‑you‑go pricing with no long-term contracts, minimums, or early termination fees, so very small or seasonal merchants can start or stop using Square at any time without penalty. As organizations grow, they can move from the free baseline tools to paid plans (e.g., Square Plus or industry-specific subscriptions) that add more advanced features, while still retaining the ability to change plans or cancel at any time via the dashboard. For higher-volume sellers, Square offers custom pricing and more sophisticated tools, and explicitly frames its model as “we grow when you grow,” indicating that larger merchants pay primarily via a take‑rate on gross payment volume rather than fixed long-term commitments. This combination of contract‑light, usage-based fees, upgradeable software tiers, and negotiable enterprise terms allows businesses to scale their use of Square Payments up or down—adding locations, staff, and channels or shrinking back—without major renegotiations or reimplementation.
Square Payments is designed so most small and mid-sized merchants are not locked into fixed-term processing contracts, which makes renewal and cancellation relatively flexible compared with traditional acquirers.
Square’s General Terms of Service state that by using its services you agree to ongoing, open-ended terms rather than a fixed contract period; there is no standard multi‑year merchant processing agreement that auto‑renews. For core payment processing, Square emphasizes that there are no long‑term commitments, no early termination fees, and no minimum volume requirements—merchants can effectively “cancel” by stopping use and closing their account at any time through the Dashboard. Closing an account ends access to Square’s services going forward, though Square retains certain records for legal, compliance, and fraud-prevention purposes as described in its privacy and information-collection policies.
Where explicit renewal and cancellation terms do apply is in Square’s subscription services (for example, industry-specific POS plans, Square Plus tiers, or add-on software). Support documentation for subscriptions notes that these are billed monthly or annually, renew automatically by default, and can be canceled at any time from the Dashboard; once you cancel, future renewals are stopped, but fees already paid for the current billing period are generally non‑refundable, and service continues until the end of that period. Some products (such as Square Payroll) highlight that account closure is irreversible: once closed, you cannot use that specific service again without a new setup, so Square encourages exporting records prior to cancellation.
Square’s Payment Terms and other product-specific terms reserve the right for Square to suspend or terminate service unilaterally for risk, fraud, or terms-of-service violations, and they can modify terms with notice, usually by updating online legal pages and notifying users via email or in-product messages. For buyers and customers, separate “buyer features” and Square Pay terms describe how their stored information and profiles behave across merchants, but those are distinct from merchant contracts.
Square Payments meets several key industry and regulatory compliance standards focused on payment data security and regulated online payments.
Square is fully compliant with the Payment Card Industry Data Security Standard (PCI DSS) and states that it adheres to “industry‑leading PCI standards” to manage its network, secure web and client applications, and set security policies across the organization. Its card-processing environment is certified to the required PCI level (internal materials describe this as PCI compliance for all systems handling card data), and Square emphasizes that merchants who use Square for storing, processing, and transmitting payment card data do not need to separately validate PCI compliance for those transactions because Square’s infrastructure already meets those requirements.
For European online payments, Square is PSD2-compliant and supports Strong Customer Authentication (SCA) for transactions involving EEA cardholders. Square updated its Payment Form and APIs so that when needed, they trigger 3D Secure 2.0 challenges and apply PSD2 SCA exemptions (for low-value or low-risk transactions) automatically, which satisfies PSD2’s requirements for multi-factor authentication. This means merchants using Square in PSD2 jurisdictions can stay compliant with SCA without building their own verification flows.
Square also operates within broader payments and financial‑compliance regimes, including anti‑money‑laundering (AML) and know‑your‑customer (KYC) obligations, particularly in contexts like its Lightning/Bitcoin integrations and banking products, where it must comply with U.S. money‑transmitter and related regulations. Across its services, Square’s legal and privacy documents commit to complying with applicable privacy and data‑protection laws, and its “Security at Square” and PCI content emphasize continuous monitoring, encryption, and adherence to PCI DSS as the foundation for its compliance posture.
If you’re building a checklist, the headline compliance items for Square Payments are PCI DSS compliance (Square’s environment is PCI-compliant so merchants don’t need their own full PCI certification for Square-only flows) and PSD2/SCA compliance for European online payments, with AML/KYC requirements met on the financial‑services side.