Android smart terminals and PayDroid, explained.
An Android payment terminal is a handheld device that runs a locked-down, payment-certified build of Android instead of the consumer version on your phone. That build, branded PayDroid (and now PAXBiz) on PAX hardware, only runs vendor-approved apps, which is what lets one pocket-sized device be a card reader, receipt printer, barcode scanner and app platform while still qualifying as a certified payment endpoint.
An Android payment terminal is a handheld device that runs a hardened, payment-certified build of Android rather than the consumer operating system on a normal phone. On PAX hardware that build has been branded PayDroid, and on current models it ships as the PAXBiz Android layer. The distinction matters more than the marketing suggests: it is the difference between a device that a card network and an acquirer will trust as a payment endpoint and a device that merely has a payment app installed on it.
This guide explains what the category actually is, what PayDroid does under the hood, and how a dedicated smart terminal differs from running softPOS (also called Tap to Phone) on a consumer handset. It is vendor-neutral where it should be, and honest about the tradeoffs, so you can decide which model fits your counter.
What is an Android smart terminal?
A smart terminal is a countertop or handheld device built on Android but locked to a payment-grade configuration. Think of the PAX A920 Pro: per PAX's own 2026 specifications it runs Android 14 under the PAXBiz layer, carries a 6000mAh battery for all-day use, an integrated thermal printer rated up to 80mm per second, a barcode scanner, and dual cameras, and it is certified to PCI PTS 7.x with SRED for hardware-level card data encryption.
The point of the category is convergence. Instead of a dumb dial-up terminal plus a separate register, scanner and printer, you get one device that reads chip, contactless and swipe, prints or emails a receipt, scans an item, and runs a real application on a touchscreen. Because the OS is Android, that application can be updated over the air and swapped out the way any app is, which is why these devices feel closer to a smartphone than to the black terminal box they replaced. For a side-by-side on specific models, see our PAX A920 vs Clover vs Square Terminal comparison.
What is PayDroid?
PayDroid is PAX's payment-hardened version of Android. It is not a different operating system so much as a stripped-down, controlled distribution of the same Android you know, with the consumer parts removed and payment-security machinery added. There is no open Google Play Store on the device; there is a managed catalog, and every application that reaches the terminal is vendor-approved and cryptographically signed before it can run.
Two things flow from that design. First, the attack surface shrinks dramatically because you cannot sideload arbitrary code. Second, the device stays inside its certification. A generic Android phone changes constantly as the user installs apps and the OEM pushes updates; a PayDroid build is frozen to a validated state that PAX and the acquirer have tested against payment rules. That stability is the whole reason a card processor will treat it as a trusted endpoint. On current PAX hardware this same discipline carries the PAXBiz branding, and remote management runs through PAXSTORE, which PAX describes as its platform for pushing and monitoring approved apps across a fleet of devices.
Why "vendor-approved apps only" matters
The restriction that frustrates tinkerers is exactly the feature merchants are paying for. When only signed, reviewed apps can execute, a compromised or malicious app cannot quietly harvest card data in the background, and the device's PCI PTS certification stays intact between updates. The tradeoff is real and worth stating plainly: you trade the freedom to install anything for a device you can trust with cardholder data on day 400 as much as on day one. If you want the vocabulary behind terms like PCI PTS, SRED and tokenization, our payments glossary defines them in one place.
Smart terminal vs softPOS on a phone
SoftPOS, which Visa markets as Tap to Phone, turns an NFC-enabled consumer smartphone into a contactless card reader with no extra hardware. Visa reported more than 700,000 Tap to Phone terminals active across 71 countries as of August 2022, and its Back to Business Study found that 82% of surveyed SMB owners globally had updated their operations to meet demand for digital payments (Visa, 2021). It is a genuinely useful model for mobile sellers, pop-ups and anyone who wants to accept a tap without buying a device.
But softPOS solves a narrower problem, and it does so by pushing hard security work into software running on a device the payment industry does not control. The PCI Security Standards Council created a dedicated standard for this, MPoC (Mobile Payments on COTS), which builds on the earlier SPoC and CPoC standards and, in the Council's words, allows the entry of both PIN and contactless cardholder data on the same commercial-off-the-shelf device. Meeting it is non-trivial: Google's Android Developers Blog explained in 2023 that Stripe adopted the Play Integrity API specifically to satisfy PCI MPoC, which requires verifying that the payment app is unmodified and was installed from a trusted source such as the Play Store.
That is the crux of the difference. A smart terminal starts from certified, tamper-resistant hardware and a frozen OS; softPOS starts from an uncontrolled phone and works to prove, per transaction, that the phone can be trusted. Here is how the two models compare on the dimensions merchants actually feel:
| Dimension | Android smart terminal | SoftPOS on a phone |
| Card entry methods | Chip, contactless, swipe, and PIN pad | Contactless tap, PIN on glass |
| Hardware security | PCI PTS certified with SRED encryption | Relies on PCI MPoC software attestation |
| OS control | Locked PayDroid/PAXBiz, signed apps only | Consumer OS, user installs anything |
| Peripherals | Built-in printer, scanner, all-day battery | None; phone-dependent |
| Best fit | Fixed counters, high volume, receipts | Mobile sellers, low volume, backup |
Neither is "better" in the abstract. A food truck taking a few dozen taps a day may be perfectly served by softPOS; a restaurant or shop running hundreds of chip transactions, printing receipts and scanning items will get more reliability and a cleaner compliance story from a smart terminal. If you are weighing acceptance methods against processing cost, our guide to choosing a payment gateway covers the decisions that sit behind the hardware.
What you actually get in one device
The reason smart terminals took over the counter is that they collapse several pieces of hardware into a single, updatable unit. On a PAX A920 Pro that means:
- A certified card reader. Chip, contactless and swipe with hardware encryption, so raw card data is protected at the point of read rather than in software.
- A built-in printer. PAX rates the A920 Pro's thermal printer at up to 80mm per second, so a paper receipt is one tap away with no add-on hardware.
- A scanner and cameras. An integrated top-side scanner plus front and rear cameras handle barcodes and QR-based flows without a tethered gun.
- All-day battery and connectivity. A 6000mAh battery plus 4G, dual-band Wi-Fi and Bluetooth mean the device leaves the counter and keeps working.
- A real app platform. Because it is Android under the hood, the terminal runs a genuine touchscreen application that can be updated over the air through PAXSTORE.
If you are setting one up for the first time, our PAX A920 setup and app guide walks through activation, and the PAX payment app overview explains how the payment application layer sits on top of the device.
The security posture, without the hand-waving
A smart terminal earns its trust from two directions at once. The hardware holds a PCI PTS certification with SRED, meaning card data is encrypted the instant it is read, inside a tamper-resistant secure element. The software side stays clean because PayDroid refuses unsigned apps, so the certified state does not drift as the device ages.
On top of the terminal, the processing stack matters just as much. Lifted Payments encrypts card data end to end using Voltage tokenization, which supports a SAQ-A compliance posture for card-present acceptance because sensitive data never lands in your systems in the clear. A keyed virtual terminal, by contrast, falls under SAQ C-VT rather than SAQ-A, since a person is typing the card number. We spell out the whole model, and why the distinction is not pedantic, in our guide to tokenization and SAQ-A compliance.
Where Lifted Pay fits
Lifted Pay is our terminal application for exactly this class of device. It is a PAX-signed, PayDroid-certified app that runs on the PAX A920, A920 Pro and A920 Max. Because it plays by the smart-terminal rules, it runs alongside BroadPOS and never draws over the card screen during a transaction, which keeps the certified payment interaction untouched and the device inside its certification. You can read more on the dedicated Lifted Pay page.
Underneath the app, card transactions route to the Maverick gateway and ACH or eCheck payments route to NMI. Commercial cards get Level 2 and Level 3 data appended automatically, which can lower interchange on business-card volume. We have also proven refund-after-settlement on live PAX A920 Pro hardware using tokenized capture, so a settled sale can be refunded cleanly rather than left to a manual workaround.
Pricing is deliberately plain: interchange-plus, quoted only after we review one of your recent statements, with no application fee. The software runs $15 per month per device and $5 per month for each added user. A few features merchants ask about, such as an item catalog with cost and margin, invoices, payment links, purchase orders and full device and user management, are on the roadmap and not yet live, so we will not sell them as shipping today. What is live is a certified Android terminal experience on hardware you may already own, backed by an honest rate. If that is the direction you are heading, our merchant services overview is the place to start.
Sources
- PAX A920 Pro product specifications — Android 14 / PAXBiz layer, 6000mAh battery, 80mm/s thermal printer, PCI PTS 7.x with SRED, PAXSTORE remote management, integrated top-side scanner, front/rear/scanner cameras, 4G + dual-band Wi-Fi + Bluetooth 5.0 (PAX, 2026). Verified via WebFetch 2026-07-26.
- PCI SSC — Mobile Payments on COTS (MPoC) — MPoC builds on the existing SPoC and CPoC standards and includes entry of both PIN and contactless cardholder data on the same COTS device (PCI Security Standards Council). Verified via WebFetch 2026-07-26.
- Android Developers Blog — Stripe Tap to Pay on Android SDK — Stripe uses the Play Integrity API to meet PCI MPoC, verifying that payment apps are unmodified and installed from a trusted source like the Play Store (Google, 2023). Verified via WebFetch 2026-07-26.
- Visa — Tap to Phone (softPOS) — 700,000+ Tap to Phone terminals active in 71 countries per Visa internal metrics as of August 2022; separately, the Visa Back to Business Study (2021) found 82% of surveyed SMB owners globally updated operations for digital payments; no additional hardware required (Visa). Verified via WebFetch 2026-07-26.
Android smart terminal and PayDroid FAQ
What is PayDroid?
Is an Android smart terminal the same as softPOS?
Can I install any app on a PAX smart terminal?
Is a smart terminal PCI compliant?
Which Android terminals does Lifted Pay run on?
Does Lifted Pay replace BroadPOS on the terminal?
Put a certified Android terminal on your counter.
Send us one recent processing statement and we'll come back with a straight interchange-plus rate review, no application fee. Card on Maverick, ACH on NMI, Level 2/3 appended automatically, and Lifted Pay running on the PAX hardware you already know.