# Consumer Card Issuing marketing, design, and compliance guidelines

Learn how to launch and maintain compliant Consumer Credit, Debit, and Prepaid Card Issuing programs.

If you want to offer and promote Consumer Credit, Debit, and Prepaid Card Issuing, then your marketing, user interfaces, and compliance program must adhere to the following sets of guidelines:

- [Onboarding](https://docs.stripe.com/issuing/consumer-compliance.md#onboarding)
- [Account management](https://docs.stripe.com/issuing/consumer-compliance.md#account-management)
- [Customer communications and documents](https://docs.stripe.com/issuing/consumer-compliance.md#customer-communications-and-documents)
- [Marketing policies and procedures for going live](https://docs.stripe.com/issuing/consumer-compliance.md#going-live)
- [Recordkeeping](https://docs.stripe.com/issuing/consumer-compliance.md#recordkeeping)

These guidelines are unique to Consumer Credit, Debit, and Prepaid Card Issuing and are separate from guidance related to other Stripe Issuing products. Where a requirement applies to only one of these products, we call that out inline.

## Onboarding

First, identify the criteria for the types of customers your program serves, and develop program-specific terms. Your platform must provide onboarding workflows for your customers to complete the main compliance requirements:

- Collect required KYC information.
- For Consumer Debit or Prepaid Card Issuing, present required fee disclosures.
- Present all other required agreements and disclosures.
- Have the customer acknowledge that they’ve read and accepted the required legal agreements.

### Eligibility criteria

The cards associated with Consumer Credit, Debit, and Prepaid Card Issuing are bank products that the issuing bank offers.

**For Consumer Credit Issuing**: the issuing bank determines the credit policy that guides eligibility criteria for your integration. However, you must create your own underwriting rules and procedures to tailor your program to your business and customers. Stripe can provide the underwriting engine to implement and act on your rules. All approval and denial decisions are made pursuant to the credit policy.

**For Consumer Debit or Prepaid Card Issuing**: the cards aren’t credit cards, and no credit check is required. The issuing bank determines the criteria that guide eligibility for your integration, including identity verification requirements. However, you must create your own eligibility rules and procedures, consistent with the issuing bank’s requirements, to tailor your program to your business and customers. Stripe can provide tools to implement and act on your rules. All approval and denial decisions are subject to the issuing bank’s eligibility criteria, including applicable KYC, sanctions screening, and any additional criteria.

### Present required agreements and disclosures

You must present the following program-specific agreements and disclosures for your customers to accept when they open their account:

- The Issuing Bank Terms (program-specific)
- Issuing Bank Privacy Notice (for Consumer Credit Issuing, this is the [Celtic Bank Privacy Notice](https://celticwebback.wpengine.com/wp-content/uploads/2021/07/CelticBank_ModelPrivacy.pdf))
- For Consumer Credit Issuing, [the Stripe Credit Card Terms of Service](https://stripe.com/legal/consumer/credit-card); for Consumer Debit or Prepaid Card Issuing, the [Stripe Consumer Debit Card Terms](https://stripe.com/legal/consumer/debit-card) or the [Stripe Consumer Prepaid Card Terms](https://stripe.com/legal/consumer/prepaid-debit-card), as applicable
- [The Stripe Privacy Policy](https://stripe.com/privacy)

You must provide customers with ongoing access to these agreements and present each one separately. You can’t combine them into one agreement.

In addition, your onboarding flow must:

- Provide your customers with an initial privacy notice about your information collection, usage, and data-sharing practices, plus annual updated notices. Give customers the opportunity to opt out of any information sharing, as required by applicable law.
- Near the links to Issuing Bank Terms and Stripe Credit Card, Consumer Debit Card, or Consumer Prepaid Card Terms, include text that states: “By clicking ‘submit application,’ you agree to the Issuing Bank Terms and the Stripe *{product type}* Terms (including the Stripe Privacy Policy), and you consent to electronic signatures as set forth in the Issuing Bank Terms and the Stripe *{product type}* Terms.” Replace “*{product type}*” with “Credit Card,” “Consumer Debit Card,” or “Consumer Prepaid Card” as appropriate for your business.
- Disclose that you’ll provide personal data to Stripe and the applicable issuing bank, and collect all necessary consents.
- For Consumer Debit or Prepaid Card Issuing, present the short-form fee disclosure before collecting personal information or fees.

You must report to Stripe the details of any fees, credits, and rewards programs you plan to offer, including monthly details about the value of any rewards you distribute to your customers. This helps ensure that your user interfaces and marketing materials are compliant with financial regulations regarding fees or offer credits such as rewards programs. Stripe provides a custom [Compliance Intake Form](https://form.asana.com/?k=8K51UWmWhttehNFD5qBLdg&d=974470123217835) that you use to submit this information.

### Develop custom program terms

As part of a compliant onboarding process, your customers need to agree to certain terms with you, the issuing bank, and Stripe. Because each integration is unique, you need to develop terms specific to your program for approval by the issuing bank. These “Issuing Bank Terms” outline the issuing bank’s relationship with your customers.

**For Consumer Credit Issuing**: the Issuing Bank Terms and associated account opening disclosures must be consistent with the requirements of applicable lending laws and regulations. You also need to make sure that relevant program terms include:

- Authorizations before instructing Stripe to initiate any Automated Clearing House (ACH) debit entries, including a mechanism for your customers to access a copy of any such authorizations
- Consents to allow you and Stripe to email, call, and text your customers as needed
- Authorizations for the issuing bank to access the customer’s credit report, and disclosures regarding potential impacts to the customer’s credit score

**For Consumer Debit or Prepaid Card Issuing**: the Issuing Bank Terms must include, at a minimum:

- [Regulation E](https://www.consumerfinance.gov/rules-policy/regulations/1005/) required disclosures, including the short-form and long-form fee disclosures, with the long-form disclosures covering all of the fees associated with the card, error resolution notices, and liability limitations
- A description of the card, including clear statements that the card isn’t a credit card, checking account, savings account, or gift card
- A description of available loading methods, funds availability timelines, and any applicable transaction limits
- Account closure and remaining balance procedures, including the disposition of funds upon termination
- Consents to allow you and Stripe to email and contact your customers as needed

### Additional cardholders

If your customers create additional cardholders (known as “authorized users” for Consumer Credit Issuing, or “secondary cardholders” for Consumer Debit or Prepaid Card Issuing), you must make sure that each such cardholder is also bound by the Issuing Bank Terms. For secondary cardholders, you must also provide the data fields required by Stripe’s APIs to activate the card. The primary cardholder is responsible for all use by any additional cardholder, including all transactions and any fees or charges they incur.

### Required agreements and disclosures for fees, credits, and rewards programs

Your terms of service and fee schedule must clearly outline the fees, terms, and rewards that you implement as part of your Consumer Credit Issuing integration. At a minimum, fees and terms must be presented as required by [the Truth in Lending Act](https://files.consumerfinance.gov/f/201503_cfpb_truth-in-lending-act.pdf) and [Regulation Z](https://www.consumerfinance.gov/rules-policy/regulations/1026/), and must adhere to associated fee and interest rate caps.

### Make sure that your applicant reads and accepts the required legal agreements

You must have proof that the customer viewed and explicitly agreed to the required legal agreements. Your customers must manually check an empty box, click “I Accept,” or similar. Pre-checked boxes aren’t acceptable. You must also record the customer’s acceptance using Stripe’s corresponding API property, and share the record with Stripe or the issuing bank upon request. We also recommend letting the customer download a copy immediately for their own files.

## Account management

Before you launch Consumer Credit, Debit, or Prepaid Card Issuing, you must implement the proper internal compliance controls. You also need to build the processes described in this section into your workflows, customer service, and product channels.

### Support

Stripe helps you manage customer support cases related to fraud, unauthorized transactions, billing errors, credit reporting, error resolution, and disputes through dedicated support channels. You must implement the following processes so that Stripe can provide this service effectively.

- **Complaint handling**: Complaints are any expression of dissatisfaction with a product, service, policy, or employee related to your Issuing integration, except from your own employees. When you offer financial services products, you must handle complaints properly. If you receive a complaint about your integration directly from a customer, you must immediately refer it to Stripe.
- **Designated customer support employees**: You must designate one or more employees to be responsible for responding to customer support escalations as communicated by Stripe to you. They must assist Stripe in responding to and resolving these escalations.
- **Active/inactive account forecasting** (Consumer Credit Issuing only): Each month, you must provide in writing to Stripe a rolling 3-month forecast of the number of anticipated active accounts and inactive accounts. An “active account” is any account that has activity impacting the credit ledger (that is, the imposition of fees or accrual of interest) within the past 90 days. An “inactive account” is any account that has no activity impacting the credit ledger within the past 90 days.

### Disputes and charge errors

While customers can contact support directly, you must also configure the [Disputes API](https://docs.stripe.com/api/issuing/disputes.md) to allow dispute submission directly through your customer-facing dashboard.

The two most common types of disputes or errors are:

- Your customer believes a charge is unauthorized
- Your customer sees an error on an account statement or in their transaction history

Make your customers aware that Stripe needs specific information to investigate a dispute, such as:

- Details about the customer, including name and account number
- Details about the disputed charge amount
- The transaction date
- An explanation of why the disputed charge is an error or unauthorized

**For Consumer Credit Issuing**: if your customer disputes a charge, Stripe issues them a provisional credit while conducting the investigation. If the customer wins the dispute, you’re responsible for the amount of that credit. If you otherwise directly receive a dispute, you must report it immediately upon notification. Failure to do so might impact your financial liability.

**For Consumer Debit or Prepaid Card Issuing**: your customers’ rights regarding unauthorized transactions and errors are governed by the [Electronic Fund Transfer Act](https://www.federalreserve.gov/boarddocs/caletters/2008/0807/08-07_attachment.pdf) and [Regulation E](https://www.consumerfinance.gov/rules-policy/regulations/1005/), as set forth in the Issuing Bank Terms. You must conspicuously provide two dispute submission options to your customers: your unique, white-labeled phone number provided to you by Stripe support, and a dashboard dispute form configured with Stripe’s Disputes API. Don’t explicitly offer any alternative dispute channels to your customers; however, if you directly receive a dispute through another channel, you must report it immediately using Stripe’s Disputes API. If your customer disputes a charge, Stripe might issue a provisional credit to them while conducting the investigation. The Issuing Bank Terms set forth certain timing requirements for customers to report unauthorized transactions, errors, or disputes. You must not communicate a shorter timeframe to customers, discourage customers from filing disputes, or impose any additional requirements beyond what the Issuing Bank Terms set forth.

### Rewards programs

Stripe must approve any rewards program associated with a Consumer Credit Issuing integration before you offer it to customers.

The Stripe support service doesn’t cover any rewards program you might offer, so you’re responsible for resolving complaints, fraud, and disputes related to any rewards program. You must maintain a dedicated channel for customers to contact you regarding the program. If Stripe receives a complaint or inquiry regarding your rewards program, Stripe refers the customer to the phone line that you provided to Stripe.

### Training

You must establish and maintain customer service guidance and training materials related to promotions, product features, dispute escalation procedures, and other aspects of your Issuing integration. Provide these materials to any customer-facing support representatives, and make sure you keep them up to date. If you have a rewards program, you must also train your representatives to handle complaints and inquiries regarding it, and to prioritize them with the Stripe support team.

### Periodic statements and transaction history

Consumer Credit, Debit, and Prepaid Card Issuing are consumer offerings. Stripe provides the Statement API and sends webhook events when your white-labeled statement PDF is ready. While Stripe configures the information on each customer statement, you’re responsible for delivering it to your customer at the end of the billing cycle, and to permit ongoing access to statements in your customer-facing dashboard or application.

**For Consumer Credit Issuing**: you must provide your customers with periodic statements, as described above.

**For Consumer Debit or Prepaid Card Issuing**: you can provide your customers with access to their transaction history instead of statements. Under this option, you must make available to your customers at least 24 months of electronic transaction history at no charge, and, upon request, provide at least 24 months of written transaction history at no charge. Stripe provides the data through its APIs, and you’re responsible for making your customers’ transaction histories accessible through your customer-facing dashboard or application.

## Customer communications and documents

To comply with applicable laws, Consumer Credit, Debit, and Prepaid Card Issuing platforms must send customer communications upon certain trigger events. Stripe helps you stay compliant by sending properly formatted notices when required. Examples of such notices include:

**For Consumer Credit Issuing**:

- Adverse action notices upon decline
- Credit score disclosure exception notices
- Payment notices upon payment events
- Dispute notices upon dispute events

**For Consumer Debit or Prepaid Card Issuing**:

- Fee change notices
- Dispute and error resolution notices upon dispute events
- Account closure notices

Stripe monitors events requiring a customer notice, and sends an email on your behalf to the customer. When using this feature, you must:

1. Preview and send test emails.

   You can preview our email templates and send test emails to make sure your branding and email addresses are working as expected.

   From Emails, click **Preview and customize** to view the email templates, then click **Send test email**.

2. Confirm your branding settings.

   All customers that receive notices see your business name, icon, and branding colors in the notice emails. To manage these brand settings, go to your Emails, click **Customize branding**, and verify that the information is correct.

3. Confirm your support email and set up your email domain.

   When Stripe sends an email on your behalf, we use your support email for the reply-to address. You can configure this in your Public details settings.

   By default, Stripe sends Issuing notices from card-issuing-notices@stripe.com, using your business name as the display name (for example, “Rocket Rides” card-issuing-notices@stripe.com). You can substitute your own email domain, but you can’t change `card-issuing-notices` (for example, card-issuing-notices@yourcustomdomain.com).

4. Review customer account details.

   Stripe sends notices to the customer’s email provided to Stripe during onboarding. To view notices sent by Stripe to a customer, go to the account’s Activity page in your Dashboard and look at the **Emails** section.

### Events that require a customer notice

Stripe monitors for certain events requiring a notice, including disputes and involuntary account closures. For Consumer Credit Issuing, we also monitor for application rejections and underwriting decisions. For Consumer Debit or Prepaid Card Issuing, we also monitor for error resolution determinations and fee changes. However, if your platform identifies an account that might be in violation of the applicable Stripe terms or the Issuing Bank Terms, [contact support](https://support.stripe.com/contact/login) or otherwise inform Stripe. We’ll perform a review of the account and take appropriate action.

## Marketing policies and procedures for going live 

The following information applies to marketing, releasing, and overseeing your Consumer Credit, Debit, or Prepaid Card Issuing integration.

### General requirements for marketing your account offerings

Any message you provide to the public about financial products or services customers don’t already use must be truthful, fair, and in their interest.

### UDAAP, regulatory requirements, and correct messaging

State and federal regulations prohibit unfair and deceptive acts or practices related to consumer financial products. At the federal level, this also includes a prohibition on abusive acts or practices (collectively, “Unfair, Deceptive, or Abusive Acts or Practices” or “UDAAP”). To avoid UDAAP violations, you must think of the customer first when developing and deploying any marketing materials. For Consumer Credit Issuing, your marketing might also have to comply with other regulations, such as Section 1026.16 of Regulation Z, depending on your integration’s features.

Make sure that marketing materials use clear messaging that fully explains product features, costs, benefits, and limitations. Don’t leave out key terms or fees, and don’t advertise unavailable product uses or features.

| Do | Don’t |
| --- | --- |
| Only use statements about products that are true, accurate, and aligned with how your customers engage with the products. | Don’t leave out information that’s likely to affect whether someone uses the product. |
| If you make claims that require additional data to support them, or if a customer needs more details to know whether a certain claim is true, you must disclose that information and provide documented evidence. | Don’t make exaggerated claims that are hard to prove, or make absolute statements that a single exception disproves. For example, don’t use phrasing like “number one,” “every,” “only,” “all,” “never,” or “always.” |
| Clearly explain all qualifying limitations and requirements needed by customers to get the products or features you’re advertising. | Don’t advertise features or programs that only a few applicants actually qualify for. |
| All disclosures must meet a “clear and conspicuous” standard:
- Font size must be large enough to read.
- Font color must visibly contrast with the background.
- Dynamic or video ads must have the disclosure on screen long enough to be read. | Don’t make disclosures hard to read. |
| Disclosures used to explain or modify a claim must relate to the claim they’re explaining.
- Include a direct hyperlink to the disclosure, or include the disclosure next to the claim in the copy itself.
- Use reference text or symbols (an asterisk, for example) directly after the claim and before the disclosure language. | Don’t bury disclosures in other non-key disclosures or footnotes. |
| Disclose all account fees, costs, benefits, and terms as part of onboarding before your customers access a product. | Don’t advertise products as free if they include any fees or other costs. |
| Make sure all images are properly licensed and that you can document this fact. | Don’t use images, formatting, or copy that implies products are endorsed by, or affiliated with, government entities or celebrities. |
| For Consumer Debit or Prepaid Card Issuing, clearly identify the card as a debit or prepaid debit card issued by the issuing bank. | Don’t refer to a debit or prepaid card as a “bank account,” “checking account,” “savings account,” or “credit card.” |

### CAN-SPAM

The CAN-SPAM Act regulates marketing activity conducted by email. It identifies the following types of email:

- **Commercial message**: The primary purpose of the email is to convey a commercial advertisement or to promote a product or service.
- **Transactional message**: The recipient is an existing customer, and the primary purpose of the email relates to a particular transaction or relationship between you and the customer, such as a payment reminder.

The CAN-SPAM Act imposes more rigorous requirements on commercial email messages than on transactional messages. Transactional messages aren’t subject to most of the requirements of the CAN-SPAM Act. If a message contains both transactional content and commercial content, the CAN-SPAM Act commercial email requirements might apply if the primary purpose of the message can be considered commercial.

To comply with the CAN-SPAM Act, any employee or staff with access to your email systems and resources for marketing must adhere to the following guidelines:

- Every email message, whether commercial or transactional, must not contain:
  - False or misleading header information.
  - A “from” line that doesn’t accurately identify the individual or business that initiated the message.
  - Inaccurate or misleading identification of a protected computer used to initiate the message for purposes of disguising its origin.
- Any commercial email message must not contain deceptive subject headings. For example, a subject heading that misleads the recipient about a material fact regarding the message’s content.
- Any commercial email message must include an opt-out mechanism. You must provide your customers with the ability to opt out of receiving future commercial messages, and you must honor customer requests to opt out within 10 days. You can’t require a user to pay a fee or provide information other than an email address to opt out.
- Any commercial email message must contain clear and conspicuous identification that the message is an advertisement or solicitation.
- Any commercial email message must disclose a valid physical address of the sender.

Failure to comply with CAN-SPAM could result in large fines for each violation.

### Testimonials

If you use testimonials or endorsements in advertising Stripe products to your users, you must follow these guidelines:

- The person giving a testimonial must be a real person and a bona fide user of the service or product they’re talking about.
- You must obtain in writing and keep the source’s permission to use their quote. You must update that permission every 24 months.
- Product benefits, costs, or features in any quotes must be verifiable and true to what most users can expect to get.
- If you paid someone for their quote, or gave them anything of value, you must put a disclaimer near the quote stating this fact. This includes paid actors, if their scripting makes it sound like they’re giving a testimonial.

### Prohibited advertising

You can’t advertise your Consumer Credit, Debit, or Prepaid Card Issuing integration in print, radio, TV, on the internet, or in any other format in a manner that:

- Promotes any unlawful activity
- Causes reputation concerns for Stripe or our bank partners

### Prohibition on international marketing

You must not market your Consumer Credit, Debit, or Prepaid Card Issuing integration to persons or businesses outside of the United States. That includes advertising or promoting your integration through marketing channels such as social media, email, and paid search results.

### Required marketing disclosures

Your customers must understand the role that Stripe’s bank partners play in offering and operating certain financial products. You must communicate that they’re entering into a contractual relationship with these banks when they use the associated products. Your customers must also understand the material costs and fees associated with their use of each financial product.

We require you to build the following disclosures into your marketing materials:

- The name of your program (for example, Rocket Rides Consumer Credit Card, or Rocket Rides Consumer Prepaid Card).
- The relevant statement below identifying the issuing bank. It can be in the footers section of your materials; however, the font must be a legible size and a contrasting color to the background.

| Product | Statement |
| --- | --- |
| Consumer Credit Issuing | Celtic Bank issues [Card Program Name] Visa® credit cards, which run on Stripe APIs and infrastructure. |
| Consumer Debit or Prepaid Card Issuing | [Card Program Name] Visa® [debit/prepaid debit] cards are powered by Stripe and issued by [Issuing Bank]. |

### Marketing and user interface submission

Submit copies of your marketing materials and user interface mockups through the [Compliance Intake Form](https://form.asana.com/?k=8K51UWmWhttehNFD5qBLdg&d=974470123217835) before you launch, and again whenever you change marketing materials, application flows, or user communications. Our team of compliance specialists reviews them with our bank partners and responds within 10 business days.

When submitting your materials:

- Provide full screenshots of product pages that include headers and footers.
- The preferable format for materials is PDF; however, any format where all text is legible is acceptable.
- Describe the types of marketing material you’re submitting (for example, web banners, emails, search engine marketing, and whether it’s only text or images and text).
- You can send up to five attachments per submission.

Send any additional questions to our [platform compliance team](mailto:platform-compliance@stripe.com).

We might request that you change your marketing materials to comply with regulatory requirements. If we request a change, it’s your responsibility to update the materials and provide evidence of the change to Stripe. Failure to update materials at our request might result in Stripe disabling your program capabilities.

### Policies and procedures

You must develop certain policy documents and associated procedures. Example documents include, but aren’t limited to, policies governing anti-discrimination, financial privacy, and advertising.

Submit copies of these policy documents through the [Compliance Intake Form](https://form.asana.com/?k=8K51UWmWhttehNFD5qBLdg&d=974470123217835) before you launch, and again if you change these policies. Our team of compliance specialists reviews them with our bank partners and responds within 10 business days.

## Recordkeeping

You must demonstrate your adherence to the requirements listed in this guide. Keep thorough records of all marketing materials, customer data, account information, and other disclosures you make to customers for at least 5 years. The following is a list of all records to keep, with examples of record types.

| Record type | Example form of records |
| --- | --- |
| Product UI | Screenshots of all deployed versions of the product UI and their deployment dates. Include application flow, customer dashboard, support pages, and so on. |
| Marketing | Inventory of all marketing copy deployed, email distribution lists used, and email solicitation opt-out lists, including timestamps of user opt-outs. |
| Customer communications and complaints | Email interactions and documentation developed in the course of resolving complaints not handled by Stripe, including complaints related to any rewards program. |
| Statements / transaction history | Evidence that you’ve delivered the periodic statements generated by Stripe, or (for Consumer Debit or Prepaid Card Issuing) made at least 24 months of electronic transaction history available to customers at no charge. |
| Fee disclosures (Consumer Debit or Prepaid Card Issuing only) | Copies of all short-form and long-form fee disclosures presented to customers, including evidence of pre-acquisition delivery. |
| Onboarding records | Records of each customer’s acceptance of applicable terms and conditions. |
