Navigating Global Sales Tax for SaaS Founders

EU VAT, US Sales Tax and Merchant of Record Options for Founders Selling Digital Products From Outside the EU and US

Navigating Global Sales Tax for SaaS Founders
BJ
Bob James
β€’
26 min read
0 votes
0 comments

I set out to add a simple paid waitlist to my indie projects and ended up reading EU regulations and US state tax tables. Here's everything I found about EU VAT, US sales tax and Merchants of Record, organized so you can make the same decision faster than I did.

A few days ago I set out to do something that sounded small: set up a paid waitlist so people could support my indie dev journey building SaaS, apps and services for creators.

Little did I know I was heading into the depths of EU VAT law, US state sales tax tables and a lot of questions about whether software counts as a "digital product", a "service", or something that depends on whether you download it.

This guide is what came out of that research. It's written from my situation - a UK tax resident, so neither an EU nor a US seller - but most of it applies to any founder selling software to customers in the EU or US from somewhere else.

⚠️ Warning: This is educational content from my own research as of December 2025. It is not financial, legal or tax advice. Tax rules change often and depend on your exact circumstances, so check with a qualified tax professional before you decide how to sell.


What You'll Learn πŸš€

  1. What counts as a digital product: The four tests, and why SaaS almost always passes them
  2. The two questions that decide your obligations: Platform or direct payments
  3. How EU VAT works for sellers outside the EU: No threshold, the One Stop Shop, and the deemed supplier rules
  4. What selling directly really costs you: 10 years of records and two pieces of location evidence per sale
  5. How US sales tax works: Economic nexus, state-by-state SaaS taxability and registration
  6. What a Merchant of Record does: And what you trade for handing over the compliance
  7. A decision framework: Questions and stage-based rules of thumb for choosing an approach

By the end you'll know which obligations apply to each way of selling, and what to ask before you pick one.



Who This Guide Is For

This is written for indie and early-stage SaaS founders based outside the EU and the US who want to sell to customers in both. My own example is the UK, but the EU and US sections apply the same way to founders in Canada, Australia, India or anywhere else outside those two markets.

It covers three areas:

  • EU VAT - the rules for selling digital services to consumers in the 27 EU member states
  • US sales tax - the state-by-state system that decides when you have to collect tax from US customers
  • Merchants of Record - companies that sell your product on your behalf and take on the tax work

πŸ’‘ Tip: If you're UK-based like me, UK sales are a separate question. UK VAT on sales to UK consumers is handled by HMRC, and registration is compulsory once your UK taxable turnover passes Β£90,000 (the threshold since April 2024). Since Brexit, a UK seller is a non-EU seller for everything in the EU section below.


What Counts as a Digital Product?

Before any rule applies, you need to know whether what you sell is a "digital product". In EU terms the category is electronically supplied services, and it's defined by four tests. Your product qualifies when it is:

  1. Not a physical product - there's nothing to ship
  2. Delivered online - over the internet or an electronic network
  3. Mostly automated - providing it involves minimal human interaction
  4. Impossible without technology - it can't exist or be delivered without IT

Why SaaS falls under digital product taxation

SaaS passes all four tests almost by definition:

  • Subscription software is delivered online and runs without anyone at your company handling each customer
  • Cloud-hosted apps only exist because of the infrastructure behind them
  • Digital downloads, templates and courses that deliver automatically are in the same category

The main exception is anything with significant human involvement, like consulting or custom development delivered over email. That's generally treated as a different kind of service with different rules.

Two questions that decide almost everything

Once you know you're selling a digital product, your obligations mostly come down to two questions:

  1. Are you selling through a marketplace or platform? An app store, Steam, or a Merchant of Record like Paddle or Lemon Squeezy.
  2. Are you taking payments directly? Your own checkout, using a payment processor like Stripe.

The rest of this guide follows those two paths, first in the EU and then in the US.


EU VAT: Where Most of the Complexity Lives πŸ‡ͺπŸ‡Ί

The EU sold its Digital Single Market Strategy as life made simpler and fairer for everyone. For a founder outside the EU, it's simpler than it used to be. Simple, it isn't. Let's find out why 🀣

VAT rates across Europe

For digital services sold to consumers, VAT is charged at the rate of the customer's country, not yours. That means 27 different standard rates. The EU requires a standard rate of at least 15%, and in practice the rates run from 17% in Luxembourg to 27% in Hungary.

Standard VAT rates across Europe, grouped into 15-18%, 19-21% and 22-25% bands, including non-EU Norway, the UK and Switzerland

Your checkout has to charge a Spanish customer Spain's rate, a German customer Germany's rate, and so on.

No threshold when you're outside the EU

This is the part that surprised me most. EU businesses get a €10,000 threshold for cross-border digital sales before they have to charge other member states' VAT. Sellers outside the EU don't get that threshold. VAT is due from your very first sale to an EU consumer.

There's no "I'll deal with it when I'm bigger" option here, at least not when you sell directly.

The One Stop Shop (OSS)

OSS - One Stop Shop, not Open Source Software - is the EU's answer to "do I need to register for VAT in 27 countries?"

For a seller outside the EU, the relevant version is the non-Union OSS scheme:

  • You register once, in one EU member state of your choice
  • You file one quarterly OSS return listing your sales to consumers in every member state
  • You make one payment, and that member state passes the VAT on to the others
  • The return and payment are due by the end of the month after each quarter

That removes 26 registrations. It doesn't remove the work of charging the right rate, keeping the records, and filing every quarter, even for quarters with almost no EU sales.

Selling through a platform: the deemed supplier

This is where the platform question starts to matter.

EU law has rules that treat the platform, not you, as the seller to the consumer. The European Commission's diagram shows the effect:

Figure 2 from the European Commission's VAT e-commerce explanatory notes: the underlying supplier's sale to the EU customer is treated as a deemed B2B supply to the electronic interface, followed by a deemed B2C supply from the interface to the customer

The underlying supplier (you) is treated as selling to the platform, and the platform is treated as selling to the customer.

Two separate provisions do this, and my early notes mixed them up, so it's worth being precise:

  • Article 14a of the VAT Directive is the "deemed supplier" provision. It applies to goods sold through electronic interfaces, and it's what the Commission's explanatory notes and diagram describe.
  • Article 9a of the VAT Implementing Regulation (282/2011) does the equivalent for electronically supplied services like SaaS, apps and digital downloads. When a platform takes part in the supply, it's presumed to be acting in its own name. It can't rebut that presumption if it authorises the charge, handles delivery, or sets the general terms and conditions - which is exactly what app stores do.

The result is the same in both cases.

The sale to the end customer is a B2C supply made by the platform. The platform charges the right VAT rate, files the returns and handles the customer's invoice.

Your sale to the platform is a B2B supply. The Commission's notes point out that when that B2B supply takes place outside the EU, EU VAT rules don't apply to it, so there are no EU VAT invoicing obligations for you as the underlying supplier.

Platforms that work this way include:

  • App stores: Apple's App Store, Google Play, Microsoft Store
  • Game and software marketplaces: Steam and similar storefronts

πŸ’‘ Tip: In my first notes I described selling through a platform as a "B2B distance sale". That's not quite right. The end sale is a B2C sale to a consumer. What's B2B is the deemed sale from you to the platform, and that's why the consumer-facing VAT becomes the platform's job rather than yours.

Merchants of Record like Gumroad, Lemon Squeezy and Paddle get you to a similar place by a different route. Rather than relying on the platform presumption, they contractually buy your product and resell it as the legal seller. There's more on them further down.

Selling directly: everything lands on you

Now flip it around. You build your own checkout and take payments directly through Stripe or another processor.

There's no platform in the middle, so there's no deemed supplier. You are the seller to the EU consumer, and every obligation is yours:

  • Registration - non-Union OSS registration before your first EU sale
  • Collection - charging the correct rate for each customer's country
  • Remittance - quarterly OSS returns and payments
  • Record keeping - detailed records of every sale, kept for 10 years
  • Compliance - proving where each customer is located

Payment processors handle payments. Unless you add a tax product on top, they don't handle any of the above for you.

Records you must keep for 10 years

For every sale you report through OSS, you must keep records for 10 years from the end of the year of the sale, and make them available electronically if a member state asks. For each sale that means:

  • The EU country of consumption - where the customer is
  • The date of supply - when you provided the service
  • The taxable amount, the currency and the VAT rate you applied
  • The amount of VAT due
  • The payment dates and amounts you received
  • The consumer's name, where you know it
  • The information you used to decide where the customer is located

The regulation's own wording for that last item is "the information used to determine the place where the customer is established or has his permanent address or usually resides". That leads straight to the next requirement.

Proving where your customer is

Charging the right country's VAT means knowing the customer's country, and the EU expects you to be able to prove it.

The general rule is two pieces of non-contradictory evidence for each sale. Acceptable types include:

  • Billing address of the customer
  • IP address or geolocation of the device used
  • Bank details, such as the country of the bank account used to pay
  • Mobile country code of the SIM card used
  • Location of a fixed landline used for the service
  • Place of delivery, where relevant
  • Other payment service details
  • ID card or passport details
  • Other commercially relevant information

"Non-contradictory" is the hard part. A German billing address with a German IP address is two consistent pieces. A German billing address with a French IP address is a conflict you have to resolve, and your records have to show how you resolved it.

⚠️ Warning: A payment processor's checkout often collects the billing country and a card country, but that doesn't mean you're storing both as location evidence for 10 years. If you sell directly, check that your checkout and database actually capture and keep two pieces of evidence per sale.

The regulations behind this

If you want the primary sources, these are the pieces I read:

  • Council Directive 2006/112/EC - the EU VAT Directive, including Article 14a (deemed supplier for goods) and Article 242a (record keeping for electronic interfaces)
  • Council Implementing Regulation (EU) No 282/2011 - including Article 9a (platforms presumed to act in their own name for electronic services) and Article 54c (the records platforms must keep)
  • The European Commission's explanatory notes on the VAT e-commerce rules (October 2020) - where the deemed supplier diagram above comes from

Article 54c is a good example of how the rules connect. It sets out the records a platform has to keep when it's deemed to have supplied goods itself under Article 14a, or when it takes part in a supply of electronically supplied services and is presumed to act in its own name under Article 9a. Both routes lead to the same obligation: the platform keeps the records the underlying seller would otherwise have kept.


US Sales Tax: Simpler, Relatively πŸ‡ΊπŸ‡Έ

After the EU, the US was a relief. Not because it's simple - there are 45 states with a sales tax, each with its own rules - but because it has thresholds, so a small seller isn't on the hook from the first sale.

There's also no federal sales tax. Five states have no statewide sales tax at all: Alaska, Delaware, Montana, New Hampshire and Oregon. Alaska allows local sales taxes, and has its own remote-seller arrangement for them.

Economic nexus

Your obligation to collect a state's sales tax starts when you have nexus - a sufficient business presence - in that state. Since the Supreme Court's 2018 South Dakota v. Wayfair decision, you can get nexus from sales alone, even with no office, staff or servers in the state. That's economic nexus, and it applies to sellers outside the US too.

The most common threshold is:

  • $100,000 in sales into the state, or
  • 200 separate transactions into the state

Both are usually measured over the current or previous 12 months, or calendar year. A few large states set higher bars - California and Texas use $500,000 in sales - and a growing number of states have dropped the 200-transaction test and use a sales amount only.

US map showing the states with economic nexus legislation in green, and the five states with no sales tax (Oregon, Montana, New Hampshire, Delaware and Alaska's statewide level) in grey

For a small SaaS, the practical effect is that you can sell into most states for a while before any state's threshold applies to you. That's the opposite of the EU.

Is SaaS taxable? It depends on the state

Crossing a state's threshold only matters if that state taxes what you sell. Here the US splits three ways, because states disagree on whether SaaS is a taxable product or a non-taxable service:

  1. States that tax SaaS - roughly two dozen, including New York, Pennsylvania, Texas and Washington
  2. States that tax it only with a downloadable component - around half a dozen more, such as Illinois, Michigan and North Carolina, where the tax applies if customers have to download software
  3. States that don't tax SaaS - including California, Florida and Georgia (shout out to California, you're the best πŸ€—)

Some of the states that do tax SaaS add their own twists:

  • Connecticut taxes SaaS for personal use at the full rate but business use at 1%
  • Maryland has a reduced 3% rate for business use
  • Iowa taxes personal use and exempts business use
  • Texas treats SaaS as a data processing service that's 80% taxable
  • Chicago has its own Personal Property Lease Transaction Tax that applies to remote sellers over a $100,000 threshold

US state SaaS taxability table: a tick or cross per state, with notes on personal vs business use, downloadable components and special rates

πŸ’‘ Tip: Whether your customers are businesses or consumers matters more in the US than you'd expect. Several states tax the same SaaS product differently depending on whether it's bought for personal or business use.

Registering, collecting and filing

Once you have nexus in a state that taxes your product:

  1. Register with that state's revenue department for a sales tax permit
  2. Collect the right rate from customers in that state from then on - including local rates in states that have them
  3. File returns on the schedule the state assigns you, usually monthly, quarterly or annually depending on your sales volume
  4. Keep records of your sales into each state

Multi-state considerations

Each new state that crosses a threshold adds a registration, a rate to calculate and a filing calendar. To keep that manageable:

  • Track sales by state from day one, so you know when you're getting close to a threshold rather than finding out afterwards
  • Expect registrations to add up over time - each one comes with its own deadlines
  • Use a sales tax tool once you have more than one or two states to manage

The US also has its own version of the EU's deemed supplier: marketplace facilitator laws. Every state with a sales tax requires marketplaces to collect and remit tax on the sales they facilitate. Sell through an app store or a Merchant of Record, and they collect the US sales tax for you.


Merchant of Record: The Strategic Alternative

By this point one idea kept coming up in my research: what if someone else was the seller?

What is a Merchant of Record?

A Merchant of Record (MoR) is the legal entity that sells to your customer. Its name is on the transaction, it takes the payment, and it carries the legal and tax responsibility for that sale.

When you use an MoR, your customer is buying from the MoR, and the MoR is buying from you. From the tax point of view you have one customer - the MoR - and it has thousands.

What an MoR takes off your plate

A full MoR service typically covers:

  • Payment processing - cards, wallets and local payment methods
  • Tax calculation and collection - the right EU VAT or US sales tax on every sale
  • VAT and sales tax remittance - registrations, returns and payments in every jurisdiction
  • Regulatory compliance - consumer rules like refund rights and invoice requirements
  • Record keeping - including the 10-year EU records and location evidence
  • Chargebacks and refunds - handling disputes as the seller
  • Payment-related customer support - "why was I charged this?" questions

These are the options that came up most in my research as of December 2025:

  • Paddle - built specifically as an MoR for software and SaaS
  • FastSpring - a long-standing MoR for software and digital products
  • Lemon Squeezy - an MoR aimed at indie creators and SaaS, acquired by Stripe in 2024
  • Gumroad - a creator marketplace that acts as the MoR for its sellers' sales
  • 2Checkout (now Verifone) - an MoR and payments provider for digital commerce
  • Newer entrants like Creem and Dodo Payments, which are aimed at indie founders

Cost vs benefit

Merchant of Record Direct payments (e.g. Stripe)
Fees Typically around 5% plus a fixed fee per sale, and up to 10% on some platforms Card processing, typically a few percent plus a fixed fee, plus any tax tools you add
EU VAT and US sales tax Handled by the MoR You register, collect, file and keep records
Legal risk Mostly carried by the MoR Carried by you
Checkout The MoR's checkout, with limited customisation Fully yours
Customer relationship The MoR is the seller of record, so customer data is shared with it You own it directly
Payouts On the MoR's schedule, which can be slower On your processor's schedule
Time spent on compliance Close to none Ongoing, every quarter

The benefits come down to:

  • Immediate global compliance from the first sale
  • No tax registrations in the EU or any US state
  • Much lower legal risk
  • Simpler operations, so your time goes into the product

The trade-offs are:

  • Higher fees - often a few percentage points more per sale than direct processing
  • Less control over the checkout experience
  • Questions about customer data ownership
  • Potential payout delays

Why MoR privacy policies look the way they do

One small thing clicked once I'd read the EU location-evidence rules. MoR privacy policies list categories like:

  • Payment data - card type, last four digits, billing address
  • Device and IP data - IP address, device, browser
  • Geolocation data - location derived from the IP address

That isn't data collection for its own sake. Billing address plus IP-based location is the EU's two-piece location evidence. The MoR has to collect it, store it, and keep it for 10 years, because as the seller that obligation is now theirs.

If you sell directly, that's exactly what you'd have to collect too.

When to choose an MoR vs direct payments

  • Early-stage and pre-revenue founders - an MoR usually makes sense. You're validating the product, and compliance work pays for none of that.
  • Scaling founders - the fee difference grows with revenue, so at some point building your own compliance can be cheaper. That point depends on your margins and how much time the work takes.
  • Business model - subscription SaaS with global consumers benefits most from an MoR. B2B sales with VAT-registered EU business customers are simpler to handle directly, because those sales generally fall under the reverse charge, where the business customer accounts for the VAT.
  • Where your customers are - if nearly all your sales are domestic, direct payments may be simple enough. If they're spread across the EU and US from the start, an MoR saves the most work.

A Decision Framework for SaaS Founders

There's no universal right answer, so here's the framework I've been using to think about it.

Five questions to ask yourself

  1. What's your current and projected revenue? The fee difference between an MoR and direct payments only becomes significant at a certain scale.
  2. Where are your customers? EU consumers mean VAT from the first sale if you sell directly. US customers mean thresholds, so you have time.
  3. What's your risk tolerance? Getting VAT wrong in the EU is your problem when you sell directly, and it's the MoR's problem when you don't.
  4. Do you have the time or money for compliance? Quarterly returns, record keeping and threshold tracking don't stop.
  5. How much does margin matter right now? A few percentage points on every sale is real money at scale, and very little money at the start.

Stage-based rules of thumb

These are rules of thumb from my research, not hard lines - your margins and customer mix will move them.

Stage Suggested approach Why
Pre-revenue / MVP Use an MoR Focus on validating the product, not on compliance
Early revenue (under $50k ARR) MoR or marketplace sales Direct-sales compliance isn't worth the effort yet
Growing ($50k-$250k ARR) Evaluate both Weigh the fee savings against the compliance work, your customer concentration and your growth trajectory
Established (over $250k ARR) Consider moving to direct payments with proper compliance The margin gain can pay for tools and advisors, if you have the capability in-house

Hybrid approaches

It doesn't have to be one or the other:

  • Use an MoR for international sales, direct payments for domestic - keep your home market simple and hand the EU and US to someone else
  • Use different payment methods for different segments - for example, direct invoicing for large B2B customers and an MoR checkout for individual consumers

Compliance Best Practices If You Sell Directly

If you do go direct, these are the practices that came up again and again.

Set up before your first sale

  • Implement robust location detection - capture at least two pieces of location evidence per sale and store them
  • Use a tax calculation service - so every sale gets the right rate automatically
  • Automate record keeping - build the 10-year EU records into your data model from the start
  • Put filing deadlines in your calendar - quarterly OSS returns, plus each US state's schedule
  • Work with an international tax accountant - especially for the first registrations and returns

Essential tools and services

  • Payment processors with tax features - for example Stripe with Stripe Tax, which calculates and collects tax at checkout
  • Tax automation platforms - such as TaxJar, Avalara and Quaderno, for calculation, reporting and in some cases filing
  • Accounting software with multi-currency support - because you'll be recording sales in euros, dollars and more
  • Legal document templates - terms of service, refund policy and privacy policy that match how you sell

⚠️ Warning: A tax calculation tool is not the same as a Merchant of Record. Tools like Stripe Tax help you calculate and collect the right tax, but you are still the seller - you still register, file returns and keep the records.

Red flags to avoid

  • Ignoring small foreign sales - there's no "under the radar" threshold for non-EU sellers in the EU
  • Inconsistent location evidence - two pieces of evidence that contradict each other, with no record of how you resolved it
  • Poor record keeping - 10 years is a long time to reconstruct records you didn't store
  • Missing filing deadlines - OSS returns are due every quarter, even quarters with almost no sales
  • Misclassifying your product - SaaS vs downloadable software changes the answer in several US states

What to Watch in 2026 and Beyond

Tax rules for digital products are still moving, and all in the same direction: more reporting, more platform responsibility, and more automation.

  • More digital taxation globally - more countries now require foreign sellers of digital services to register and collect tax
  • Thresholds and enforcement are changing - US states keep adjusting their nexus rules, and several have dropped transaction counts
  • Platforms are reporting more - under the EU's DAC7 rules, platforms have reported their sellers' income to tax authorities since 2023

What to monitor

  • OECD digital tax work - the international framework many countries' digital tax rules build on
  • The EU's VAT in the Digital Age (ViDA) package - adopted in 2025, it expands the One Stop Shop and phases in digital reporting and e-invoicing over the rest of the decade
  • US state law updates - new SaaS taxability decisions and threshold changes
  • Emerging markets - more countries adding VAT or GST on digital services sold by foreign businesses

Building for compliance from day one

Even if you start with an MoR, a few architecture decisions keep your options open:

  • Store the customer's country and your location evidence with each order, even if the MoR also stores it
  • Keep pricing and tax separate in your data model, so switching between tax-inclusive and tax-exclusive pricing isn't a rewrite
  • Keep your billing logic behind one interface, so moving from an MoR to direct payments later is a change of provider, not a rebuild

Where This Leaves Me

I started this research wanting a paid waitlist, and I've ended it with a much clearer picture of what each option costs. Here's where it landed.

Key takeaways

  1. Digital products face real international tax obligations - and SaaS is squarely a digital product
  2. Marketplaces and MoRs simplify compliance dramatically - the platform or MoR becomes the seller, and the obligations move with it
  3. Direct payments mean significant compliance work - EU VAT from the first sale, 10 years of records and two pieces of location evidence per sale
  4. The US system is more forgiving than the EU's - thresholds give you time before any state applies
  5. The right choice depends on your stage, scale and resources - there's no single answer

Action steps

  1. Assess your situation - where your customers are, and what you sell
  2. Calculate the true cost of each approach - MoR fees against direct fees plus tools, accountant and your own time
  3. Choose the right approach for your current stage, knowing you can change later
  4. Put proper systems in place before you scale, not after
  5. Talk to a tax professional before you commit

My decision, for now

I haven't made the final call yet. Direct payments through Stripe give me full control of the checkout and the customer relationship, and an MoR takes the EU VAT, US sales tax and 10-year record keeping off my plate from day one. For a small product at the start, that trade-off is closer than I expected.

What I do know is which questions decide it, and that's what this guide is for: working out the answer before the first sale, not after.

Compliance isn't optional, but it is manageable with the right approach. Early on, the focus belongs on product-market fit, and an MoR removes a lot of friction while you find it. Plan for the transition as you scale.


Resources and References

Official documentation

  • Council Directive 2006/112/EC - the EU VAT Directive (Articles 14a and 242a)
  • Council Implementing Regulation (EU) No 282/2011 - Articles 9a and 54c, and the rules on customer location evidence
  • European Commission, Explanatory notes on the VAT e-commerce rules (October 2020)
  • Each US state's department of revenue - for current nexus thresholds and SaaS taxability

Further reading

These are the articles I bookmarked while researching, and they're worth reading next:

When to bring in professionals

  • An international tax accountant - before your first OSS registration, and when you get close to your first US state threshold
  • A lawyer - to review your terms, refund policy and privacy policy if you sell directly

That's a Wrap on Global Sales Tax

What started as a paid waitlist turned into a crash course in EU VAT law, US state tax tables and the business model behind every Merchant of Record checkout I've ever used.

If you're an indie founder about to take your first international payment, I hope this saves you the few days it took me.

Hi, I'm Bob, the Tech Wizard nobody's heard of.

Until the next one, keep building.

Login to vote on this article

Share:

Discussion

Login to add a comment

No comments yet 🀯 but its such an awesome article.
Be the first to comment and start a discussion πŸ€—