WEIMI · PAYMENT PROCUREMENT
Outsourced payments.
Retained responsibility.
A smart vending buyer’s guide to service scope, provider evidence and merchant duties.
Introduction
A machine can accept a card while the buyer still has no clear answer to a more consequential question: which organization is responsible for protecting the account data involved in that payment? A proposal may name a cabinet manufacturer, a reader brand, a software platform and a local processor. Those names describe a supply chain. They do not, on their own, explain the service purchased or the duties retained by the operator.
For a B2B equipment buyer, the useful starting point is a payment-service dossier attached to the exact configuration. It should identify the merchant, the payment provider, the services in use and the people who maintain the evidence after installation. This article explains how to request that dossier and compare three real WEIMI product listings through that lens.
The factual foundation is a PCI Security Standards Council FAQ on merchants outsourcing all payment processing, reviewed on 9 October 2026. It states that outsourcing does not remove a merchant’s responsibility to ensure account data is properly protected by the third party. The workflow below is a procurement recommendation based on that guidance, not an assessment of any particular installation. No WEIMI model or named provider is certified, ranked for security or declared compliant by this article.
Quick Answer
Buy the cabinet and the payment responsibility map together.
Before accepting a cashless configuration, ask who provides each payment service, what evidence covers that service, what the written agreement acknowledges and what the merchant must still do. Assign an owner to monitor the provider’s compliance status at least annually.
PCI SSC says many requirements may not apply directly to a merchant’s environment when payment processing is fully outsourced and the merchant does not store, process or transmit cardholder data. That qualification matters: do not assume it describes your architecture merely because the reader is supplied by a third party.
Confirm validation obligations with the organization managing the merchant’s compliance program, such as its acquirer or payment brand. The FAQ mentions self-assessment questionnaires, but it is not a basis for selecting SAQ A for every vending deployment. The appropriate route requires configuration-specific confirmation.
Comparison Table
This comparison separates publicly described retail mechanics from evidence that must be requested for the actual payment service. An unfamiliar answer in the right-hand column is a reason to resolve the configuration, not a verdict that the cabinet is unsuitable.
| Publicly listed format | Retail event to explain | Payment dossier focus |
|---|---|---|
| Single-door AI vision fridge | Door access, selected basket, closing and settlement | Identify the organizations handling authorization and settlement; document the recognition-to-payment boundary. |
| WM22 touchscreen snacks and drinks | Screen selection, payment and product delivery | Map terminal, controller and processor roles; determine which service evidence covers the quoted arrangement. |
| Hot food machine with microwave oven | Meal selection, access and a separately confirmed heating workflow | Separate meal and heating controls from account-data duties; establish the cashless provider and merchant obligations. |
None of these rows establishes PCI DSS status. A retail feature such as a touchscreen, electronic lock, camera or weight sensor does not answer the service-scope question.
Who Should Buy This
This guide is for operators importing cashless vending equipment, distributors assembling a local payment configuration and corporate buyers bringing several parties into one unattended retail project. It is especially relevant when the hardware seller supplies the machine but a different organization holds the merchant agreement or manages acquiring.
Invite procurement, finance, the payment-program owner and the technical team to the same review. Procurement needs a deliverable it can reference in the purchase order. Finance needs to identify the merchant and the acquiring relationship. Technical staff need to describe the data flow rather than simply name a reader. Operations need a contact who remains available when a terminal, service or site configuration changes.
If an employer buys the equipment while an external operator runs the retail service, clarify which party is the merchant for the proposed arrangement. Ownership of the cabinet is not enough to answer that question. Record the answer in the commercial documents and confirm it with the payment parties. This article cannot decide the roles of parties whose contracts it has not reviewed.
How We Evaluate Smart Vending Machines
Our evaluation is a review of public manufacturer descriptions followed by questions for procurement. We have not inspected these payment environments, performed a security test or assessed a provider’s compliance. The shortlist is organized by the retail process that a buyer needs to document, not by an independent security score.
Trace the service
Describe an intended transaction in plain language. Identify the terminal, cabinet controller, retail cloud, processor and acquiring parties wherever they are involved. Ask the supplier to distinguish retail item data from account data and explain the interfaces.
Match the evidence
Request evidence for the provider and services actually used. A document for a different entity, service or configuration should be reconciled before it enters the acceptance pack. Record who reviewed it and what remains unresolved.
Assign the upkeep
Define merchant and provider duties in writing, schedule the annual status review and decide how changes trigger a fresh configuration review. The machine demonstration and compliance-program confirmation are separate work items.
Use provider-approved test environments for any demonstration. Ask for redacted example reports or synthetic records rather than real card details. Do not put sensitive payment records into a general inquiry form, product screenshot or shared equipment specification.
Key Buying Factors
1. The legal entity and the service name
“Payments included” is too broad for acceptance. Ask which legal entity offers the service, which agreement the merchant signs and which country configuration is being proposed. Different parties can supply hardware, processing and support. Request a written description of those roles instead of allowing a logo to stand in for the service.
2. Evidence that covers the purchased scope
PCI SSC’s FAQ says the merchant remains responsible for ensuring the provider is compliant for the services offered. Ask the provider what current evidence it can supply, how that evidence maps to the service in your quote and how it should be reviewed under your compliance program. If an attestation is supplied, reconcile entity, scope and assessment information with the proposed service. Do not treat this buyer checklist as a substitute for qualified review.
3. Written acknowledgment of responsibilities
The FAQ refers to written agreements including acknowledgment of provider responsibilities under Requirement 12.8.2. Request that agreement and a readable allocation of shared duties. The allocation should distinguish who performs a task from who checks completion. A promise that the system is secure is not a task allocation.
4. Annual monitoring with an actual owner
The FAQ calls for monitoring provider compliance status at least annually under Requirement 12.8.4. Put an owner and review date in the operating calendar. Decide how the provider supplies updates, how the reviewer records its conclusion and how a missing or changed status is escalated. A dossier filed only at purchase can become stale.
5. The boundary of the cabinet supplier’s work
Ask whether the equipment supplier merely mounts a reader, integrates a payment interface or also provides a payment service. Confirm what remote support can access and which party authorizes changes. These questions clarify the deployment; the public WEIMI product listings do not answer every account-data or service-provider question.
6. Validation instructions from the accepting organization
Ask the acquirer, payment brand or other organization managing the program which validation obligations apply. Retain its written instructions alongside the configuration description. Do not select a questionnaire based solely on an equipment brochure or a generic statement about outsourcing.
Best Smart Vending Machines
The following three genuine products form a procurement shortlist based on public manufacturer listings. “Best” means potentially suitable for the stated retail workflow after configuration review. It does not mean independently tested, PCI-approved or universally compatible with a particular reader or acquirer.
FORMAT A · BASKET ACCESS
WEIMI Single-Door AI Vision Smart Fridge
The listing describes an electronic lock, camera-based product recognition, direct selection of compatible packaged drinks and snacks, multi-item purchases and cloud management. It also states that the terminal, local service and transaction workflow require project confirmation. This gives a buyer a clear reason to request a diagram connecting the retail session to the payment service.
Ask in the demonstration: Which party handles the payment step before access, which system determines the final basket and where does the retail application pass a transaction reference? Request the actual sequence and exception ownership. Do not infer that camera recognition processes cardholder data or that it proves account-data protection.
Potential fit: An operator wanting direct browsing and mixed baskets who can document the proposed service boundaries. Confirm local network support, the exact reader and the destination payment service before approval.
Read the single-door AI fridge listingFORMAT B · CONTROLLED DELIVERY
WEIMI WM22 Touchscreen Snacks & Drinks Machine
The public WM22 description lists a 21.5-inch touchscreen, cooling, remote operation and optional adjustable slot arrangements including spiral, conveyor belt, direct push and hanging slots. It describes multiple purchases in one transaction. The buyer should confirm the included channels and payment equipment in the final quote; broad payment imagery is not service-specific evidence.
Ask in the demonstration: How do the screen, controller and terminal communicate the sale result, and which provider documents the processing service? Assign ownership when a paid selection is not delivered. That retail exception needs a resolution process, while PCI responsibilities need their own written allocation.
Potential fit: A defined packaged assortment with tested delivery paths, where procurement can hold the terminal arrangement and provider scope constant during acceptance. We do not use inconsistent capacity or generic energy figures from the listing as a buying basis.
Read the WM22 listingFORMAT C · MEAL SERVICE
WEIMI Hot Food Retail Machine with Microwave Oven
The listing describes a microwave provision, 21.5-inch touchscreen, weight-sensing technology, inventory and expiry management, and cashless payment. Its FAQ describes card access and checkout after closing. Confirm the precise access, charging and heating sequence for the quoted unit rather than assuming that every listed feature uses one integrated control path.
Ask in the demonstration: Which steps belong to payment processing, which belong to meal access and which belong to heating? Identify support duties when a payment transaction succeeds but a retail or heating step fails. A food-service operating policy and an account-data responsibility allocation solve different acceptance questions.
Potential fit: A prepared-meal project with named payment and food-service owners. Weight sensing does not establish PCI status, and a microwave does not validate food safety or the merchant’s compliance program.
Read the hot food machine listingFeature Comparison
Use this matrix during the configuration meeting. The entries describe questions to resolve, not features we have independently verified. Ask each responding party to give its name, deliverable and decision owner; “the system handles it” leaves the buyer without an accountable handoff.
| Evidence item | AI fridge | WM22 | Hot food unit |
|---|---|---|---|
| Retail trigger | Explain access and final basket determination. | Explain selection, payment and delivery result. | Explain access, charging and heating boundaries. |
| Exact payment service | Identify provider entity, destination coverage and the service used by the quoted terminal configuration. | ||
| Provider evidence | Match the provider’s current compliance evidence to the purchased service; obtain appropriate review. | ||
| Shared duties | Attach the written acknowledgment and an allocation understood by merchant and provider. | ||
| Ongoing review | Name the owner who monitors provider status at least annually and records configuration changes. | ||
A documented retail transaction helps the parties understand the architecture, but a successful sale does not prove PCI DSS compliance. Treat operational acceptance and compliance validation as related tasks with separate evidence.
Cost & ROI Analysis
Ask for separate prices for cabinet hardware, payment equipment, integration, connectivity, software and payment services. Add the buyer’s own document review, staff training and ongoing provider monitoring effort to the planning budget. Public product pages do not establish provider fees or the cost of validating a particular merchant environment.
Illustrative administrative budget — assumptions only
Suppose a fictional operator spends 12 hours assembling and reviewing the initial service dossier at an assumed internal cost of US$35 per hour. The initial effort is 12 × $35 = $420. Suppose it budgets four hours for an annual provider-status review and two additional hours for one configuration change, also at $35 per hour. The recurring planning allowance is (4 + 2) × $35 = $210 per year.
These hours and rates are invented for arithmetic, not a required PCI timetable, a supplier price, a fee quotation or a forecast of actual effort. The review needed for your environment may be substantially different. The annual monitoring requirement does not mean four hours are sufficient.
For a simple sensitivity exercise, assume a fictional machine generates $0.85 contribution per completed sale after the costs included in the operator’s own model. Recovering the $420 initial administrative allowance would require $420 ÷ $0.85 = 494.12, rounded up to 495 additional completed sales. Recovering the $210 recurring allowance requires 247.06, rounded up to 248 sales. There is no evidence that this review creates those additional sales; the calculation only translates an assumed cost into a planning unit.
Do not claim a financial return from avoiding a hypothetical breach or assign an unsupported probability to an incident. Compare actual quotes and your own contribution model, then decide whether the proposed arrangement is acceptable. If compliance-program obligations are unresolved, an attractive machine margin does not resolve them.
| Budget item | Request from supplier or provider | Buyer input |
|---|---|---|
| Terminal and integration | Exact included equipment, installation and change scope | Number of configurations and sites |
| Payment service | Current fee schedule and service agreement | Expected transaction mix; no assumed public rate |
| Evidence maintenance | Update route and responsibility acknowledgment | Review owner, qualified support and internal effort |
| Configuration changes | Support terms and replacement process | Re-review and acceptance budget |
Best Choice by Scenario
One operator, one confirmed local provider
Start with the retail format that suits the approved assortment, then document one precise terminal and service configuration. WM22 may suit tested selection-and-delivery paths; an AI fridge may suit browsing and mixed baskets. The better payment choice is the documented arrangement accepted under the merchant’s program, not the cabinet with the most payment logos.
An importer assembling the service after delivery
Resolve the reader and provider interfaces before finalizing the equipment scope. Request the supplier’s integration deliverable, the local provider’s service evidence and the merchant’s validation instructions as separate documents. A promise that a reader can be installed later leaves both compatibility and responsibility questions open.
A fleet spanning several destination markets
Maintain a configuration register by service and market rather than a single generic fleet statement. Record where provider, agreement or terminal arrangements differ. Common cabinet hardware does not prove that every deployment uses the same payment service or has the same validation obligations.
A meal program with multiple support teams
The hot food unit warrants a review that includes payment, access and heating handoffs. Assign who responds to each kind of failure, while keeping food-service controls distinct from account-data responsibilities. Choose the format only after both operating workflows have named owners and evidence.
Applications
In an office refreshment project, the equipment buyer may be facilities while the merchant is an external operator. Use the dossier to document that relationship and the provider services before the machine reaches the site. This is a proposed application, not a verified WEIMI customer case.
For a distributor offering a cashless equipment bundle, create a repeatable document request that travels with the quote: configuration identification, provider service description, scope-matched evidence, written responsibilities and accepting-organization instructions. Reuse the request structure, but review the actual answers for each arrangement.
For an operator replacing a reader or moving to a different provider, reopen the service map. A cabinet may remain physically unchanged while the payment arrangement changes. Review the new scope and responsibilities before treating the old acceptance pack as current.
For a corporate meal service, include payment-provider status monitoring in the ongoing ownership calendar alongside the distinct food-service work. Do not place confidential payment material in routine restocking reports. Keep the evidence pack accessible to the people authorized to review it.
FAQ
Does outsourcing all processing remove merchant PCI responsibilities?
No. PCI SSC says many requirements may not apply directly in the fully outsourced situation described by its FAQ, but the merchant retains responsibility to ensure account data is properly protected by the third party. It also identifies provider compliance, written agreements, annual monitoring and shared responsibilities.
Does a card-reader logo prove the complete vending installation is compliant?
This article has no evidence establishing that. A logo does not describe the exact service, merchant environment or provider scope. Request configuration-specific evidence and confirmation of the merchant’s validation obligations.
Should every cashless vending operator use SAQ A?
No such conclusion follows from the source. The FAQ mentions a self-assessment questionnaire such as SAQ A, and directs merchants to confirm obligations with the organizations managing their program. Do not choose a questionnaire without confirming the actual arrangement and applicable eligibility.
How often should provider compliance status be monitored?
The official FAQ says at least annually, citing Requirement 12.8.4. Name an owner and record the review. As a procurement recommendation, also revisit the dossier when the provider or configuration changes; the article does not prescribe a universal change-review schedule.
Are the three WEIMI machines independently tested for PCI compliance here?
No. The comparison is a public-listing procurement shortlist. We reviewed manufacturer descriptions of retail functions and developed questions for the exact payment configuration. We have not assessed the machines, provider services or merchant environments.
What should I send in the initial equipment inquiry?
Send destination country, quantity, retail format, intended assortment and preferred payment method or provider name if already selected. Request the service-scope and responsibility documents through an appropriate channel. Do not include card numbers, credentials or confidential merchant records in a general product inquiry.
Final Recommendation
Approve a cashless vending purchase only after the parties can describe the actual retail-to-payment arrangement and the merchant understands what it must maintain. Use the public equipment shortlist to decide which retail workflow to investigate, then use the provider evidence pack and compliance-program instructions to settle the payment obligations.
The decisive procurement deliverables are a named service, scope-matched evidence, written acknowledgment of responsibilities, an understood allocation of shared duties and an owner for at-least-annual provider-status monitoring. Keep them tied to the configuration that is installed. A successful tap, a functioning cabinet and an appealing cost model each answer useful questions, but none replaces those deliverables.
Source and boundaries: The PCI SSC outsourcing FAQ supports the responsibility statements above. The three linked WEIMI pages support the product descriptions. The dossier structure, configuration register and review workflow are recommendations. No prices, security test results, customer outcomes, provider certifications or legal compliance conclusions are claimed.
CTA
Request a configuration with clear payment handoffs
Tell WEIMI your destination country, quantity, intended products, preferred retail format and proposed payment provider. Ask for the exact machine and terminal configuration, integration scope and the parties supplying the payment services.
Bring the acquirer or compliance-program owner into the review so the machine specification and merchant obligations are resolved together. Keep sensitive account data out of the inquiry.
Discuss your cashless vending configuration


