Hardware explainer

Android smart terminals and PayDroid, explained.

An Android payment terminal is a handheld device that runs a locked-down, payment-certified build of Android instead of the consumer version on your phone. That build, branded PayDroid (and now PAXBiz) on PAX hardware, only runs vendor-approved apps, which is what lets one pocket-sized device be a card reader, receipt printer, barcode scanner and app platform while still qualifying as a certified payment endpoint.

An Android payment terminal is a handheld device that runs a hardened, payment-certified build of Android rather than the consumer operating system on a normal phone. On PAX hardware that build has been branded PayDroid, and on current models it ships as the PAXBiz Android layer. The distinction matters more than the marketing suggests: it is the difference between a device that a card network and an acquirer will trust as a payment endpoint and a device that merely has a payment app installed on it.

This guide explains what the category actually is, what PayDroid does under the hood, and how a dedicated smart terminal differs from running softPOS (also called Tap to Phone) on a consumer handset. It is vendor-neutral where it should be, and honest about the tradeoffs, so you can decide which model fits your counter.

What is an Android smart terminal?

A smart terminal is a countertop or handheld device built on Android but locked to a payment-grade configuration. Think of the PAX A920 Pro: per PAX's own 2026 specifications it runs Android 14 under the PAXBiz layer, carries a 6000mAh battery for all-day use, an integrated thermal printer rated up to 80mm per second, a barcode scanner, and dual cameras, and it is certified to PCI PTS 7.x with SRED for hardware-level card data encryption.

The point of the category is convergence. Instead of a dumb dial-up terminal plus a separate register, scanner and printer, you get one device that reads chip, contactless and swipe, prints or emails a receipt, scans an item, and runs a real application on a touchscreen. Because the OS is Android, that application can be updated over the air and swapped out the way any app is, which is why these devices feel closer to a smartphone than to the black terminal box they replaced. For a side-by-side on specific models, see our PAX A920 vs Clover vs Square Terminal comparison.

What is PayDroid?

PayDroid is PAX's payment-hardened version of Android. It is not a different operating system so much as a stripped-down, controlled distribution of the same Android you know, with the consumer parts removed and payment-security machinery added. There is no open Google Play Store on the device; there is a managed catalog, and every application that reaches the terminal is vendor-approved and cryptographically signed before it can run.

Two things flow from that design. First, the attack surface shrinks dramatically because you cannot sideload arbitrary code. Second, the device stays inside its certification. A generic Android phone changes constantly as the user installs apps and the OEM pushes updates; a PayDroid build is frozen to a validated state that PAX and the acquirer have tested against payment rules. That stability is the whole reason a card processor will treat it as a trusted endpoint. On current PAX hardware this same discipline carries the PAXBiz branding, and remote management runs through PAXSTORE, which PAX describes as its platform for pushing and monitoring approved apps across a fleet of devices.

Why "vendor-approved apps only" matters

The restriction that frustrates tinkerers is exactly the feature merchants are paying for. When only signed, reviewed apps can execute, a compromised or malicious app cannot quietly harvest card data in the background, and the device's PCI PTS certification stays intact between updates. The tradeoff is real and worth stating plainly: you trade the freedom to install anything for a device you can trust with cardholder data on day 400 as much as on day one. If you want the vocabulary behind terms like PCI PTS, SRED and tokenization, our payments glossary defines them in one place.

Smart terminal vs softPOS on a phone

SoftPOS, which Visa markets as Tap to Phone, turns an NFC-enabled consumer smartphone into a contactless card reader with no extra hardware. Visa reported more than 700,000 Tap to Phone terminals active across 71 countries as of August 2022, and its Back to Business Study found that 82% of surveyed SMB owners globally had updated their operations to meet demand for digital payments (Visa, 2021). It is a genuinely useful model for mobile sellers, pop-ups and anyone who wants to accept a tap without buying a device.

But softPOS solves a narrower problem, and it does so by pushing hard security work into software running on a device the payment industry does not control. The PCI Security Standards Council created a dedicated standard for this, MPoC (Mobile Payments on COTS), which builds on the earlier SPoC and CPoC standards and, in the Council's words, allows the entry of both PIN and contactless cardholder data on the same commercial-off-the-shelf device. Meeting it is non-trivial: Google's Android Developers Blog explained in 2023 that Stripe adopted the Play Integrity API specifically to satisfy PCI MPoC, which requires verifying that the payment app is unmodified and was installed from a trusted source such as the Play Store.

That is the crux of the difference. A smart terminal starts from certified, tamper-resistant hardware and a frozen OS; softPOS starts from an uncontrolled phone and works to prove, per transaction, that the phone can be trusted. Here is how the two models compare on the dimensions merchants actually feel:

DimensionAndroid smart terminalSoftPOS on a phone
Card entry methodsChip, contactless, swipe, and PIN padContactless tap, PIN on glass
Hardware securityPCI PTS certified with SRED encryptionRelies on PCI MPoC software attestation
OS controlLocked PayDroid/PAXBiz, signed apps onlyConsumer OS, user installs anything
PeripheralsBuilt-in printer, scanner, all-day batteryNone; phone-dependent
Best fitFixed counters, high volume, receiptsMobile sellers, low volume, backup

Neither is "better" in the abstract. A food truck taking a few dozen taps a day may be perfectly served by softPOS; a restaurant or shop running hundreds of chip transactions, printing receipts and scanning items will get more reliability and a cleaner compliance story from a smart terminal. If you are weighing acceptance methods against processing cost, our guide to choosing a payment gateway covers the decisions that sit behind the hardware.

What you actually get in one device

The reason smart terminals took over the counter is that they collapse several pieces of hardware into a single, updatable unit. On a PAX A920 Pro that means:

  • A certified card reader. Chip, contactless and swipe with hardware encryption, so raw card data is protected at the point of read rather than in software.
  • A built-in printer. PAX rates the A920 Pro's thermal printer at up to 80mm per second, so a paper receipt is one tap away with no add-on hardware.
  • A scanner and cameras. An integrated top-side scanner plus front and rear cameras handle barcodes and QR-based flows without a tethered gun.
  • All-day battery and connectivity. A 6000mAh battery plus 4G, dual-band Wi-Fi and Bluetooth mean the device leaves the counter and keeps working.
  • A real app platform. Because it is Android under the hood, the terminal runs a genuine touchscreen application that can be updated over the air through PAXSTORE.

If you are setting one up for the first time, our PAX A920 setup and app guide walks through activation, and the PAX payment app overview explains how the payment application layer sits on top of the device.

The security posture, without the hand-waving

A smart terminal earns its trust from two directions at once. The hardware holds a PCI PTS certification with SRED, meaning card data is encrypted the instant it is read, inside a tamper-resistant secure element. The software side stays clean because PayDroid refuses unsigned apps, so the certified state does not drift as the device ages.

On top of the terminal, the processing stack matters just as much. Lifted Payments encrypts card data end to end using Voltage tokenization, which supports a SAQ-A compliance posture for card-present acceptance because sensitive data never lands in your systems in the clear. A keyed virtual terminal, by contrast, falls under SAQ C-VT rather than SAQ-A, since a person is typing the card number. We spell out the whole model, and why the distinction is not pedantic, in our guide to tokenization and SAQ-A compliance.

Where Lifted Pay fits

Lifted Pay is our terminal application for exactly this class of device. It is a PAX-signed, PayDroid-certified app that runs on the PAX A920, A920 Pro and A920 Max. Because it plays by the smart-terminal rules, it runs alongside BroadPOS and never draws over the card screen during a transaction, which keeps the certified payment interaction untouched and the device inside its certification. You can read more on the dedicated Lifted Pay page.

Underneath the app, card transactions route to the Maverick gateway and ACH or eCheck payments route to NMI. Commercial cards get Level 2 and Level 3 data appended automatically, which can lower interchange on business-card volume. We have also proven refund-after-settlement on live PAX A920 Pro hardware using tokenized capture, so a settled sale can be refunded cleanly rather than left to a manual workaround.

Pricing is deliberately plain: interchange-plus, quoted only after we review one of your recent statements, with no application fee. The software runs $15 per month per device and $5 per month for each added user. A few features merchants ask about, such as an item catalog with cost and margin, invoices, payment links, purchase orders and full device and user management, are on the roadmap and not yet live, so we will not sell them as shipping today. What is live is a certified Android terminal experience on hardware you may already own, backed by an honest rate. If that is the direction you are heading, our merchant services overview is the place to start.

Sources

  1. PAX A920 Pro product specifications — Android 14 / PAXBiz layer, 6000mAh battery, 80mm/s thermal printer, PCI PTS 7.x with SRED, PAXSTORE remote management, integrated top-side scanner, front/rear/scanner cameras, 4G + dual-band Wi-Fi + Bluetooth 5.0 (PAX, 2026). Verified via WebFetch 2026-07-26.
  2. PCI SSC — Mobile Payments on COTS (MPoC) — MPoC builds on the existing SPoC and CPoC standards and includes entry of both PIN and contactless cardholder data on the same COTS device (PCI Security Standards Council). Verified via WebFetch 2026-07-26.
  3. Android Developers Blog — Stripe Tap to Pay on Android SDK — Stripe uses the Play Integrity API to meet PCI MPoC, verifying that payment apps are unmodified and installed from a trusted source like the Play Store (Google, 2023). Verified via WebFetch 2026-07-26.
  4. Visa — Tap to Phone (softPOS) — 700,000+ Tap to Phone terminals active in 71 countries per Visa internal metrics as of August 2022; separately, the Visa Back to Business Study (2021) found 82% of surveyed SMB owners globally updated operations for digital payments; no additional hardware required (Visa). Verified via WebFetch 2026-07-26.
Questions

Android smart terminal and PayDroid FAQ

What is PayDroid?
PayDroid is PAX's payment-hardened build of Android. It removes the consumer parts of the OS, blocks sideloading, and runs only vendor-approved, cryptographically signed apps, which keeps the device inside its PCI PTS certification. On current PAX models the same layer is branded PAXBiz.
Is an Android smart terminal the same as softPOS?
No. A smart terminal is dedicated, certified hardware with a locked OS, a printer, a scanner and hardware card encryption. SoftPOS (Visa's Tap to Phone) turns an ordinary NFC smartphone into a contactless reader and leans on the PCI MPoC software standard to prove the phone can be trusted per transaction. See our terminal comparison for model-level detail.
Can I install any app on a PAX smart terminal?
No, and that is intentional. There is no open app store on the device; apps are distributed through a managed catalog (PAXSTORE) and must be vendor-approved and signed before they can run. This restriction is what preserves the terminal's payment certification over time.
Is a smart terminal PCI compliant?
The hardware itself carries a PCI PTS certification with SRED encryption, and PayDroid keeps the software state validated. Combined with end-to-end tokenization, card-present acceptance can support a SAQ-A posture because raw card data never reaches your systems in the clear.
Which Android terminals does Lifted Pay run on?
Lifted Pay is a PAX-signed, PayDroid-certified app for the PAX A920, A920 Pro and A920 Max. It runs alongside BroadPOS and never draws over the card screen during a transaction. Details are on the Lifted Pay page.
Does Lifted Pay replace BroadPOS on the terminal?
No. Lifted Pay coexists with BroadPOS rather than replacing it, and it deliberately stays off the screen while the card interaction is happening, so the certified payment flow is never disturbed. Setup is covered in our PAX A920 setup guide.
One statement, one honest rate

Put a certified Android terminal on your counter.

Send us one recent processing statement and we'll come back with a straight interchange-plus rate review, no application fee. Card on Maverick, ACH on NMI, Level 2/3 appended automatically, and Lifted Pay running on the PAX hardware you already know.