What information may move between components
The useful business data depends on the integration. An order number, amount, location identifier, device identifier, transaction reference, status, and receipt information are common examples in provider documentation. Item details, customer references, refunds, tips, or other fields may be supported only in certain products or configurations.
Map every field before launch. Record where it originates, where it is stored, who can view it, and what happens if it is missing or changed. Keep cardholder data out of ordinary order notes, support tickets, spreadsheets, email, and general contact forms. The integration should use the payment provider's approved customer-entry and payment-data paths rather than asking employees to copy sensitive credentials between systems.
Do not assume that an integration removes all security or operational responsibilities. Review the provider's current implementation instructions, user access controls, device-management process, network requirements, update process, and incident path for the specific deployment. General architecture guidance cannot establish the obligations or boundaries of a merchant's configured environment.