Designing a verified checkout experience for municipal payments

Role

UX/UI designer

DURATION

2 weeks

Team

2 PM, 1 Developer

Scope

Strategy, UX, UI

Background

Paykal is a municipal payment platform used by cities and local councils across Israel to provide purchsable services such as: cultural events, facility rentals, kindergarten enrollment fees, permit applications, and more.

Its user base is diverse, ranging from residents completing a single one-time transaction to recurring users. Unlike standard e-commerce, these payments are time-sensitive and carry higher personal stakes

The project was initiated by recurring complaints from municipal admins and our support team

The Challenge

The existing checkout made no distinction between new and returning residents. Registration and identity verification followed the same flow for every purchase, requiring everyone to manually enter their full personal details each time.

Product constraints

  • Mandatory identification using National ID or Company ID

  • Guest checkout was not permitted

Resulting UX issues

  • Returning users had to re-enter personal details for every purchase

  • Authentication occurred late in the checkout flow

  • Personal details and payment separated into different pages

These constraints created tension between security requirements and a fast checkout experience.

My approach

Rather than redesigning the form itself, I reframed the problem as an identity handling challenge. The goal was to resolve user identity earlier in the checkout flow and avoid repeated data entry.

Step 1 — Identity Gap Analysis

Reviewed checkout behavior and recurring support complaints across municipalities. Both research and platform data pointed to the same issue: returning users had to re-enter their details on every purchase.

Step 2 – Identity Model

Introduced a lightweight ID + OTP model that:

  • Resolves identity before form completion

  • Recognizes returning users

  • Maintains verification standards

  • Avoids forced account creation

Step 3 – Flow Restructure

Separated identification from payment. Key decisions:

  • Early OTP verification

  • Conditional field exposure

  • clear communication of user status

Step 4 – Validation

Validated through stakeholder walkthroughs and pilot rollout. Post-launch refinements focused on OTP reliability and edge cases.

Research

Support team interviews

Conversations with the support team revealed a consistent pattern: users expected the system to recognize them. The phrase "I've already filled this in before" appeared repeatedly in support logs, exposing a clear gap between user expectations and system behavior.

Analytics review

GA4 funnel analysis showed that the checkout-to-confirmation drop-off was the primary conversion barrier. Users who reached checkout had clear purchase intent—the friction wasn't in decision-making, but in execution. The form itself was the obstacle.

Findings

Invisible Drop-Off

Checkout abandonment had no clear drop-off point, making it hard to diagnose.

Checkout abandonment had no clear drop-off point, making it hard to diagnose.

Identity State Ambiguity

Identity Ambiguity

Users never knew if the system recognized them, re-entering everything each purchase.

Users never knew if the system recognized them, re-entering everything each purchase.

Late identity reslution

Identity was resolved too late in the flow, increasing redundant effort for both all users.

Identity was resolved too late in the flow, increasing redundant effort for both all users.

Coupled Authentication

Authentication and registration were tightly coupled, preventing flexible state handling.

Authentication and registration were tightly coupled, preventing flexible state handling.

Key insight

The Identity issue was resolved too late, and the system had no way to recognize returning users. The solution wasn't to redesign the form, but to introduce a lightweight identity layer that resolves user state before checkout begins.

Guiding principles

Separation

Decouple identification from registration and payment to enable flexible state handling.

Early Resolution

Identify returning users before collecting full form data to reduce redundant effort.

Usage Fit

Avoid account-heavy patterns in systems used for one-time or infrequent transactions

Exploration

The redesign moves identity resolution to the start of checkout. Users whose ID is not found complete a one-time registration; on future purchases, their details are recalled automatically.

Checkout flow

    Deliverables

    The redesign focused on a single structural shift: moving identity resolution before the form, so the system could adapt to the user rather than the user adapting to the system. Every decision, from progressive disclosure to the side panel OTP, followed from that principle.

    Before and after

    Additional improvements made in the same release:

    • Product images in the order summary

    • Cart was not editable from the checkout page

    The new identity step

    Before reaching the form, users now enter their National ID or Company ID. This single field determines the entire experience: returning users are recognized and their details pre-filled; new users complete a one-time registration that saves their details for future purchases.

    New visitors / first time purchase

    Rather than forcing users into full account creation before they can complete a purchase, the panel captures only the minimum required information at the moment it's actually needed.

    Rather than forcing users into full account creation before they can complete a purchase, the panel captures only the minimum required information at the moment it's actually needed. The ID field arrives pre-filled, so the user isn't repeating themselves. More importantly, this is a one-time step: once submitted, the details are tied to the ID and retrieved automatically on every future visit. The friction is front-loaded once, then eliminated entirely.

    The ID field arrives pre-filled, so the user isn't repeating themselves. More importantly, this is a one-time step: once submitted, the details are tied to the ID and retrieved automatically on every future visit. The friction is front-loaded once, then eliminated entirely.

    First-time users complete a one-time registration; their details are saved and auto-filled in future purchases.

    Impact

    Performance was evaluated by comparing the same six-month window (January–June) across two consecutive years.

    The new version was released in late 2024 and is currently live across 90 municipalities.

    Primary metrics

    86%

    Checkout completion rate, up from 84.3%- a gain of 1.6 percentage points.

    12%

    Increase in successful order confirmations, from 1,911 to 2,140.

    Secondary metrics

    Checkout visitors

    ↑ 9.9%

    Completed orders

    ↑ 12%

    Total platform traffic

    ↑ 10%

    Drop-off rate under increased traffic

    Stable

    Data sources

    Google Analytics, external payment system

    The old GIS

    Research

    Insights

    Iterations

    New design

    © 2026 Michal Oring

    michal.oring@gmail.com

    ·

    LinkedIn