Security and hosting
Do I need SSL on a website that takes no payments?
Yes. Browsers mark any HTTP page with a form as "Not secure", HTTPS is a confirmed ranking signal, and certificates are free with automated renewal on any serious host. There is no scenario in which a public business site should still be served over HTTP.
What happens without it
- Chrome and Safari display a "Not secure" warning beside your address
- Any form submission travels in plain text across every network in between
- Referral data from HTTPS sites is stripped, so your analytics under-reports
- Modern browser features — geolocation, service workers — refuse to run
- Search engines treat HTTPS as a positive signal, however small
What it costs
Nothing, in most cases. Let’s Encrypt certificates are free and are issued and renewed automatically by every mainstream host and CDN. Paying for a certificate is rarely necessary and buys validation rather than encryption.
The failure to watch for
Expiry. An expired certificate produces a full-page browser interstitial that stops every visitor, and automated renewal that silently stopped working is common. Monitor the expiry date independently of the renewal process.
The longer version
This answer is deliberately short. If you want the full treatment, Technical SEO, in the order the problems actually block you covers it in about 4 minutes — free, ungated, written from client work.
Who answered this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan — fifteen live client sites, six of them stores taking real payments. These answers come from those projects rather than from a content brief. More about how I work, or ask me something directly.