The checkout is the sequence of steps on an online shop where a shopper confirms what they are buying, gives contact and delivery details, chooses how to pay and places the order. It starts when someone leaves the basket and ends on the order confirmation page.
How a checkout works
Most checkouts follow the same stages, whether they are spread across several pages or held on a single page:
- Contact: an email address, plus the choice to sign in, create an account or continue as a guest.
- Delivery: the address (ideally with a postcode lookup), the delivery method and its cost, or a collection option.
- Payment: card, Apple Pay or Google Pay, PayPal or buy now, pay later, all handled by a payment gateway that passes the details securely to the banks.
- Review: a summary of the items, delivery, total price and terms, followed by the order button.
- Confirmation: an order number on screen and a confirmation email.
Card payments often add one more step. Under the UK’s payment services rules, many online card payments need Strong Customer Authentication (SCA), meaning the shopper proves who they are in two ways. In practice that is the bank’s 3-D Secure screen or a prompt in the banking app. The gateway can request exemptions, for example for some low-value or low-risk payments, and the shopper only sees a challenge when the bank asks for one.
Why it matters
Everyone who reaches the checkout has already been brought to the site, often at a cost, and has decided to buy. A clumsy checkout loses them at the last step, which makes it the most expensive place on the site to have a problem.
It is also where UK consumer law applies most directly. The Consumer Contracts Regulations 2013 require key information before the order is placed, including the total price with VAT and delivery, and the final button must make clear the shopper is committing to pay. “Place order and pay” does that; a bare “Continue” does not. Pre-ticked boxes that add paid extras are not allowed. Since April 2025, the DMCC Act has also made it unlawful to hold back compulsory fees until the checkout.
Common mistakes
- Forcing account creation before payment. Offer guest checkout and invite the customer to save their details on the confirmation page instead.
- Showing the delivery cost for the first time at the payment step.
- Asking for details you do not need, such as a phone number with no explanation of what it is for.
- Placing the discount code box so prominently that shoppers leave to search for a code.
- Never testing 3-D Secure on a phone, where the bank’s screen can fail to load or time out.
- Tracking it badly: the begin_checkout and purchase events in GA4 should each fire once, and the purchase should not repeat when the confirmation page is refreshed.
How to act on it
Place a real order on your own site from a phone every month, with a card that triggers 3-D Secure, and note every moment of doubt. Then look at the step-by-step drop-off in your analytics, compare it with your cart abandonment rate, and fix the step that loses the most people first.
Keep the legal information visible without cluttering the page: the total including delivery, links to delivery and returns terms, the right to cancel, and a clearly worded order button. Checkout pages should normally carry a noindex tag, since they have no value in search results. When I work on a website redesign for an online shop, the checkout is tested with live payments before anything else is signed off, because a fault there stops revenue immediately.
