Merchant of Record (MoR)

The Merchant of Record (MoR) is the legal entity that sells the booking to the guest and is responsible for processing the payment. The MoR appears on the guest's card statement, holds the acquiring relationship, owes any card-scheme liability including chargebacks and fraud losses, issues refunds, and is generally the party accountable for collecting and remitting transaction taxes. In hotel distribution, whether the OTA or the hotel is the merchant of record is the single question that determines who holds the guest's money, who bears the risk, and who owns the payment relationship.

Who is the merchant in each model

  • Merchant model — the OTA is the MoR. It charges the guest at booking, keeps its margin, and pays the hotel afterwards, often by virtual credit card. Expedia's traditional model works this way.
  • Agency model — the hotel is the MoR. It charges the guest directly at or before stay and pays the OTA a commission after the fact. Booking.com's classic model works this way.
  • Facilitated or hybrid payments — the OTA collects the guest payment as a payment facilitator on the hotel's behalf while the hotel remains the contractual seller. Booking.com's Payments by Booking.com and similar programmes sit here, and the MoR designation depends on the specific contract and market.

Example

A guest books a €600 stay through an OTA operating as merchant of record. The OTA charges the guest's card €600 and the guest's statement shows the OTA's name. The hotel receives a €480 virtual card to charge at check-in. If the guest disputes the charge, the chargeback lands with the OTA, not the hotel — but so does the guest's payment data, the refund decision and, in many jurisdictions, the VAT treatment of the transaction.

Why it matters

MoR status drives cash flow timing, working capital, and the true cost of a channel: a merchant-model booking is settled net and late, an agency booking is settled gross and early with commission invoiced later. It also determines who must comply with card-scheme rules, PCI DSS scope and Strong Customer Authentication in Europe, and who is exposed when a guest disputes a charge. Commercially, the MoR usually controls the payment page, the payment methods offered and the guest's payment credentials — which is why payment ownership has become a strategic battleground between hotels and platforms rather than a back-office detail.

Related

See Merchant Model and Agency Model for the two commercial structures, VCC (Virtual Credit Card) for how merchant-model payouts reach the hotel, and Chargeback and SCA (Strong Customer Authentication) for the risk and compliance obligations that follow the merchant.