Checkout Terms and Policies Checklist: What Must Be Visible Before Payment
What must be visible before the buy button: terms, privacy, refund and shipping policies, contact details, amount and currency, recurring terms, descriptor notice and consent, and what each proves in a dispute.
Before a customer pays, the checkout must show the legal entity's terms and privacy policy, the refund and shipping terms, contact details, amount and currency, any recurring terms, a descriptor notice and an unticked consent action. Underwriters compare these pages with the application. Dispute analysts ask whether this cardholder saw and accepted them on this order. Log every consent with the policy version; a footer link is not disclosure.
Before a customer can pay, the checkout must show who takes the payment and on what terms: the legal entity's terms of service and privacy policy, the refund and cancellation policy, the shipping terms, working contact details, the exact amount and currency, any recurring amount and frequency next to the buy button, a notice of the name that will print on the card statement, and an unticked consent action that records the cardholder's agreement. The website checklist on this blog covers site content and credibility; the refund policy guide drafts the policy itself.
The checklist: nine elements and what each one proves
Two readers check the checkout. The underwriter, during the KYB review before a MID is issued, checks that the legal pages exist, name the entity on the application, match the declared product and billing model, and show pricing, currency and contact details without a login. The dispute analyst arrives after a chargeback and, for the consumer dispute reason codes (not received, not as described, cancelled, credit not processed), asks what the customer was told before paying, whether the customer agreed, and whether you can prove both for this order. The elements below are the answers.
| Element | Where it must be visible | What it proves in a dispute |
|---|---|---|
| Terms of service | Linked from every page and the checkout, named next to the consent action | Which entity sold what, under which conditions, and that the customer accepted them |
| Privacy policy | Linked from every page and the checkout | What data was collected and that card data stayed with the gateway |
| Refund and cancellation policy | Summarised before the buy button, full page one click away | That the refund window or no-refund rule was disclosed before the sale |
| Shipping and delivery policy | Product page and before the buy button, with the delivery window | What delivery was promised, against the tracking in a not-received case |
| Contact details | Footer, contact page and confirmation email: support email or phone, and the business address | That the customer could reach you before calling the bank |
| Amount and currency | Next to the buy button: line items, taxes, shipping, total, currency charged | That the amount charged is the amount shown |
| Recurring terms | Next to the buy button: amount, frequency, trial, first charge date, how to cancel | Express consent to recurring billing |
| Descriptor notice | Checkout and confirmation email: "this charge appears as BRAND on your statement" | That the customer knew which name to expect on the statement |
| Consent capture | An unticked checkbox or a clearly labelled button, logged with time, IP and policy version | That this cardholder agreed to these terms on this order |
Terms of service and privacy policy: naming who takes the payment
The terms of service answer one question first: who is the merchant. The entity named must be the legal entity that takes the payment, the one on the articles, the EIN letter and the merchant application. If customers know a brand and the entity has another name, both appear, the same pair the descriptor carries. Which clauses the terms need and how they are worded is a legal question; a professional decides, and IBOCore gives no legal or tax advice. This checklist only requires visibility: a footer link on every page, a link at the checkout, and the document named next to the consent action.
The privacy policy states what data the store collects, why, who receives it and how long it is kept; what the privacy laws of your markets require in it is for a professional to confirm. One line matters most to an underwriter: how card data is handled. A store using the gateway's hosted fields or a redirect never sees the card number and should say so; a store claiming to store card data invites questions about its PCI DSS scope. Name the gateway among the recipients of customer data.
Refund, cancellation and shipping policies: disclosed before the button
Card network rules typically require the refund and return policy to be disclosed to the cardholder before the sale completes, and a footer link alone does not meet that test. The policy, or a short and accurate summary, sits on the checkout page before the buy button, with the full version one click away. A no-refund rule, where the product and the law of your markets allow one, is disclosed and accepted the same way. Shipping terms follow the same logic: the delivery window, the countries served and who pays return shipping appear before the sale, because a not-received dispute is judged against what was promised.
- Same terms everywhere. The summary at the checkout, the full page and the confirmation email state the same window and conditions.
- Product-specific rules stated, not implied. When the refund right ends for a course, a download or a service belongs in the summary; the refund policy guide on this blog covers how to write it for each product type.
- Match the application. The refund terms the underwriter saw at boarding are the ones the acquirer expects to find; tightening them later is a change to disclose.
Boarding a checkout on a fresh US entity
Browse the US IBO packages in stock today: one package, one price, delivered the same day the payment confirms.
The buy button: amount, currency, recurring terms and the descriptor notice
The last screen before payment is where the amount, the billing model and the descriptor are disclosed, so both readers open it. Line items, taxes, shipping and the total appear together, in the currency the card will be charged in; a price shown in one currency and charged in another produces amount disputes the store rarely wins. If any part of the sale recurs, the recurring amount, its frequency, the length and price of any trial, the first full charge date and the way to cancel appear in plain sentences next to the button, not behind a link. Card network rules for subscription and trial billing typically add an express consent, a confirmation after enrolment, a reminder before a trial converts and an online way to cancel; the free trial to continuity guide on this blog covers those elements one by one. The descriptor notice closes the screen: one sentence naming the exact string that will print on the statement.
- One total, one currency. The amount authorised equals the total shown; surcharges and conversion are disclosed here or not charged.
- The descriptor string. Written exactly as the acquirer boarded it; the billing descriptor guide on this blog covers the fields and their limits.
Capturing consent and keeping the proof
Consent is an affirmative action taken after the terms are visible: an unticked checkbox next to a sentence that names the terms, the refund policy and, when relevant, the recurring terms, or a button whose label states what clicking it does, for example "Pay $89 now and $89 every month until cancelled". A pre-ticked box, a grey line saying that continuing implies acceptance, or terms shown after payment are rarely credited as consent. The action is logged and tied to the order. In a representment, the compelling evidence is that log, the checkout as it looked that day, the confirmation email, the delivery record and the support history.
- The consent record. Timestamp, IP, device, order ID, the sentence the customer agreed to and the version numbers of the policies linked from it.
- Policy versions. A dated archive of every version of the terms, refund, shipping and privacy pages, with a screenshot of the checkout at each change.
- Delivery and access records. Tracking for physical goods, login and download logs for digital goods, session records for services.
Failures that cost a boarding or a dispute
- Policies only in the footer. Present on the site, absent from the checkout; the underwriter notes it, the analyst treats the customer as uninformed.
- A checkout that contradicts the application. A subscription at the button on a store declared as one-time sales; the acquirer reads it as an undisclosed change.
- A different company in the terms. A previous entity, a template company or the platform provider instead of the entity on the application.
- Pre-ticked consent, or none. Acceptance implied by clicking Pay.
- A contact page with a form only. No email, no phone, no address; both readers see a merchant that does not want to be reached.
Where the IBOCore package fits
IBOCore supplies the entity and the director, not the checkout. The package is a US LLC or C-Corp incorporated in the director's home state with its EIN issued, a business bank account at Bluebanc or Relay in the company's name with full operational access, and a professional email on the company domain. The director is the IBO (Independent Business Operator), a real, KYC-verified US resident, exclusive to one merchant, with a zero criminal record and a credit score of 650 or more, who takes the acquirer's verification calls and stays out of the business. For this checklist, the legal name in your terms is the name on the articles and the EIN letter, the contact email on your legal pages can be the professional email, and the director must know what the checkout says: the verification call often asks what the company sells, at what price and under which name, and the IBO answers from the briefing you give your account manager in the private Telegram group. What the public record shows is that entity and its director on the state filing and the EIN. At the time of writing, FinCEN's interim final rule of March 2025 exempts domestic companies and US persons from beneficial ownership reporting, while companies formed under foreign law that register in a US state remain subject to it; verify the current FinCEN guidance before relying on that status.
The IBO package costs $999 setup, then $2,999 per month from 30 days after delivery, whatever the vertical or the billing model. The optional document template pack, $499 one time, includes refund policy and terms of service templates; the final wording remains a decision for you and a professional.
Processing capacity in stock today
Message the channel with your vertical and billing model, or browse the packages delivered the same day payment confirms.
Questions merchants ask
Is a link to the policies in the footer enough for the underwriter?
No. The underwriter checks that the refund policy and the terms are disclosed where the customer decides to pay: on the checkout page, before the buy button, with a consent action that names them. Footer links prove that the policies exist, not that a given customer saw them before paying. Screenshot the result for the application.
Does the checkout need a physical business address?
Card network rules typically expect the website to show where the merchant is located, at least the country, so the cardholder can identify the merchant and knows when a charge is cross-border, and acquirers commonly ask for the full business address on the contact page or in the terms. Use the address on the merchant application, the one the bank and the state filing carry, so the records agree.
My checkout runs on a hosted platform. Can I still meet this checklist?
Often yes. Hosted checkouts commonly allow policy links, an unticked consent checkbox, a descriptor notice and the recurring terms on the payment screen; whether a consent log exists and can be exported for one order varies by platform. Check three things before boarding: that the checkout shows your entity name and not the platform's, that you can retrieve the consent record for a single order, and that policy pages can be versioned.
Compliance touchpoints that survive audit
Clean setups disclose beneficial ownership, file BOI, use genuine IDs, and keep the IBO informed of website and descriptor changes. Processors re-scan for prohibited products, undisclosed aggregation, and transaction laundering. Violations land on MATCH and kill future MID applications.
- AML / CDD: customer due diligence on the merchant entity.
- PEP screening: politically exposed persons get enhanced review.
- OFAC / SDN: sanctions lists checked on owners and signers.
- Website compliance: refund policy, terms, pricing visible before checkout.
Compliance shortcuts that trigger MATCH
Fake guarantors, borrowed SSNs, cloaked websites, and third-party processing through your MID are the fastest paths to MATCH listings. Recovery requires legal work and years of delay. Disclose, document, and keep the IBO in the loop.
FAQ: quick answers
How fast can I get an IBO package on IBOCore?
Available inventory ships the same day after payment. You receive Articles, EIN letter, registered agent details, bank onboarding pack and signer contact through your merchant dashboard. Processor onboarding typically follows over the next one to two weeks.
Where can I look up payment-processing jargon?
Use the Resources glossary on IBOCore (/resources) for 580+ definitions: MID, chargeback ratio, MATCH, rolling reserve, MCC, RDR, KYB and high-risk vertical vocabulary.
Ready for instant delivery?
Browse live IBO inventory or ask about your vertical on Telegram.