Compliance & Attestation Policy
This policy explains how ComplyRUO is designed to help a Merchant operationalize the preventive measures that Stripe’s published policy requires for research-use peptides, and what the Merchant remains responsible for. “ComplyRUO,” the “Service,” the “Company,” “we,” “us,” or “our” means Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO. “Merchant,” “you,” or “your” means the business that uses ComplyRUO; a “Buyer” or “Customer” is the Merchant’s end customer, a research counterparty. ComplyRUO provides a researcher gate, a locked intended-use attestation, a tamper-evident record, and weekly content monitoring that are intended to help a Merchant put those preventive measures in place and demonstrate them on demand. ComplyRUO does not verify any Buyer and does not guarantee any compliance, regulatory, or payment outcome.
Contents
- Purpose and relationship to the Terms
- The Stripe policy basis
- The researcher gate
- The intended-use attestation
- The tamper-evident record
- Truthfulness, accuracy, and KYC
- Weekly compliance monitoring
- Limitations of automated scanning
- The controls are provided AS IS
- The changing regulatory landscape
- Merchant responsibilities
- No reliance and independent professional advice
- High-risk acknowledgment and assumption of risk
- What this policy is NOT
- Records, cooperation, and changes
- Contact
1.Purpose and relationship to the Terms
This Compliance & Attestation Policy explains the controls that ComplyRUO provides to help a Merchant put preventive measures in place for the business-to-business, Research-Use-Only (RUO) sale of peptides to qualified research counterparties. It describes how the researcher gate, the locked intended-use attestation, the tamper-evident record, and the weekly compliance scan work, and it sets out what the Merchant remains responsible for. As used in this policy, “ComplyRUO” means Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO.
This policy is part of, and is incorporated by reference into, the ComplyRUO Terms of Service and the Acceptable Use Policy, and it must be read together with them. Where this policy describes a control, the binding allocation of responsibility and the master protections are set out in those documents and govern. Those master protections include, without limitation: the broad disclaimer of warranties (AS IS and AS AVAILABLE); the limitation of liability and the liability cap; the indemnification in favor of ComplyRUO and Cevgate LLC; the card-network fines, BRAM, and recoupment terms; the binding individual arbitration agreement, the jury-trial waiver, and the class-action and representative-action waivers; and the choice of Arizona governing law and venue. This policy supplements and does not limit those protections.
Order of precedence. In the event of any conflict or inconsistency, the order of precedence is: first, the Terms of Service; then the Acceptable Use Policy, the Data Processing Addendum, the Privacy Policy, this Compliance & Attestation Policy, and the Affiliate Agreement. If there is any conflict, the Terms of Service control, and nothing in this policy shall be read to expand ComplyRUO’s obligations or to narrow the disclaimers, waivers, and limitations stated in the Terms of Service.
2.The Stripe policy basis
Stripe permits the sale of research-use peptides on a conditional basis. Stripe’s published support guidance, under “Pharmaceutical and peptides businesses,” states:
“Peptides that are for research purposes may be sold on Stripe as long as there are preventive measures in place to ensure these are not accessible to those who would purchase research chemicals for nonresearch purposes.”
ComplyRUO is designed to help a Merchant operationalize those preventive measures. The researcher gate, the locked intended-use attestation, the tamper-evident record, and the weekly content scan described in this policy are intended to support the “preventive measures” condition: to help limit an RUO storefront from being readily accessible to those who would buy research chemicals for nonresearch purposes, and to help produce evidence that those measures were in place at the time of each sale. ComplyRUO does not guarantee, represent, or warrant that these controls will in fact satisfy Stripe’s condition, prevent any misuse, or achieve any compliance, regulatory, or payment outcome.
Stripe’s Prohibited & Restricted Businesses List separately prohibits “incorrectly labeled research chemicals” and “pseudo-pharmaceuticals or nutraceuticals that are not safe or make harmful claims,” and restricts online pharmacies, prescription-only and regulated products, and CBD. ComplyRUO’s controls are intended to help the Merchant address this risk area, by supporting correct RUO and FDA labeling, discouraging medical, therapeutic, or efficacy claims, and reinforcing that products are not for direct-to-consumer or human or animal consumption use. Putting preventive measures in place does not change the underlying rule. The Merchant must still satisfy Stripe’s conditions in fact, and Stripe and the Card Networks decide, at their sole discretion, whether to onboard, continue, restrict, or terminate any account. The Stripe Services Agreement, the Stripe Connected Account Agreement, and the Stripe Prohibited & Restricted Businesses List (the “Stripe Agreements”) govern the Merchant’s relationship with Stripe and apply in addition to this policy.
3.The researcher gate
Before a Buyer can reach the Merchant’s store, ComplyRUO presents a researcher gate that the Buyer must clear. The gate is shown up front, ahead of any product or pricing, and it requires the Buyer to:
- affirm that they are 21 years of age or older;
- affirm that they are a qualified research counterparty acquiring product for legitimate research purposes; and
- acknowledge the Research-Use-Only nature of the products and the FDA non-evaluation disclaimer, which are displayed prominently on the gate before access is granted.
No store access, product catalog, pricing, or checkout is available until the Buyer confirms each of these items. The minimum age requirement is fixed at 21 and is not a configurable setting. The RUO and FDA disclaimer wording shown on the gate is locked (see Section 4). The Merchant may style and brand the gate, but it cannot remove the gate, lower the age, weaken the affirmations, or grant access before confirmation.
4.The intended-use attestation
At or before checkout, the Buyer must complete an intended-use attestation. The attestation asks the Buyer to state, on the record, the type of counterparty they are and the intended use of the products being purchased, consistent with the FDA “intended use” standard at 21 CFR §201.128, under which a product’s intended use is determined from its labeling, its advertising, and the circumstances of its sale. The Buyer attests that the products are acquired for Research Use Only, for in vitro or laboratory use, and not for human or animal consumption and not for any medical, therapeutic, diagnostic, or clinical use.
The substance of the attestation wording, including the RUO statement and the disclaimer “For research use only. Not for human or animal consumption,” is LOCKED. The Merchant cannot edit, weaken, reorder away the meaning of, or remove the locked attestation wording. The Merchant may customize surrounding design and branding, but not the compliance content itself.
A signature is captured on file as part of the attestation. The signature, together with the attestation wording and the Buyer’s responses, becomes part of the tamper-evident record described in Section 5.
5.The tamper-evident record
For each completed attestation, ComplyRUO writes a record to an audit ledger. The record is designed to be tamper-evident, so that the Merchant can show, after the fact, what the Buyer was shown and what the Buyer attested at the moment of the transaction. Each record captures, at a minimum:
- the exact attestation wording presented, and the version of that wording in effect at the time;
- the counterparty type the Buyer selected;
- the intended use the Buyer stated;
- the timestamp of the attestation;
- the originating IP address;
- the sealed signature captured on file; and
- a cryptographic hash that binds the record’s contents together.
Records are sealed when written. Because each record carries a cryptographic hash over its contents, any later edit to a sealed record causes it to flag as altered rather than passing silently as original. The ledger is exportable on demand, so that the Merchant can provide a complete, verifiable export to a payment processor, an acquirer, an auditor, or another authorized reviewer.
The tamper-evident design demonstrates that a control was in place and records what occurred. It does not by itself prove that any underlying transaction was lawful, that any Buyer attested truthfully, or that any processor or reviewer will accept or credit the export. Truthfulness, accuracy, and the limits of the record are addressed in Section 6.
6.Truthfulness, accuracy, and KYC
ComplyRUO records what a Buyer submits; it does not, and cannot, verify that what a Buyer submits is true. ComplyRUO does not authenticate, verify, validate, vouch for, or guarantee any Buyer’s identity, age, status as a research counterparty, signature, contact information, or stated intended use, and it does not authenticate or verify the accuracy of any information the Merchant provides. ComplyRUO captures responses, the signature on file, and the attestation as submitted, and seals them. The Merchant is responsible for knowing its Buyers and counterparties to the extent the law, the Stripe Agreements, or the Card Network rules require, and for any “know your customer” (KYC) or customer-due-diligence obligations that apply to its business.
The tamper-evident seal proves only the integrity of the record, that is, that the recorded contents have not been altered since the record was written. It does not prove that the recorded contents are true, that the attestation was made by the person or entity it names, that the stated intended use was genuine, or that any product was in fact used or destined for research only. A false, mistaken, incomplete, or omitted attestation, and any inaccuracy in Buyer or Merchant information, is the risk of the Merchant and its Buyer and not of ComplyRUO.
The Merchant must keep its own account, business, and payout information current and accurate. As stated more fully in the Terms of Service and the Stripe Connected Account Agreement, the Merchant is the merchant of record and is responsible for its own compliance and for the accuracy of its information; a misrepresentation or material omission is a breach and is grounds for suspension, termination, and reporting. ComplyRUO does not warrant the integrity or truth of any compliance evidence beyond the limited tamper-evidence described in Section 5.
6.1 ComplyRUO does NOT verify any Buyer
ComplyRUO does NOT verify, authenticate, vet, screen, qualify, or confirm any Buyer. ComplyRUO does not verify any Buyer’s identity, age, credentials, licensure, registrations, qualifications, institutional affiliation, research purpose, or bona fides, and it does not confirm that any Buyer is in fact a qualified research counterparty. The researcher gate and the intended-use attestation capture the Buyer’s own self-affirmations only. They record what the Buyer states about itself; they do not test, prove, or stand behind the truth of any of it.
The Merchant alone decides whom to serve, whom to accept, and whom to refuse, and the Merchant alone bears the consequences of, and any reliance on, a Buyer’s self-affirmations. ComplyRUO does not guarantee, represent, or warrant that any attestation is true, accurate, or complete, that any Buyer is who or what it claims to be, or that the gate or the attestation will exclude, screen out, or prevent access by any ineligible, underage, unqualified, or bad-faith Buyer. Any decision to grant access, accept an order, ship product, or rely on a self-affirmation is the Merchant’s decision and the Merchant’s risk.
COMPLYRUO DOES NOT VERIFY ANY BUYER’S IDENTITY, AGE, CREDENTIALS, LICENSURE, QUALIFICATIONS, OR BONA FIDES. THE GATE AND THE ATTESTATION CAPTURE SELF-AFFIRMATIONS ONLY AND ARE NOT INDEPENDENTLY VERIFIED. COMPLYRUO DOES NOT GUARANTEE THAT ANY ATTESTATION IS TRUE OR THAT THE GATE WILL EXCLUDE ANY INELIGIBLE, UNDERAGE, UNQUALIFIED, OR BAD-FAITH BUYER. THE MERCHANT ALONE DECIDES WHOM TO SERVE AND BEARS ALL RISK OF RELIANCE ON ANY SELF-AFFIRMATION.
7.Weekly compliance monitoring
ComplyRUO runs an automated weekly scan of the Merchant’s product and policy pages. The scan looks for content risk signals, including:
- medical, therapeutic, efficacy, dosing, diagnostic, or human or animal use claims;
- language inconsistent with Research-Use-Only positioning; and
- missing or incomplete RUO and FDA non-evaluation disclaimers.
The scan produces a compliance score and a list of flagged lines, so the Merchant can find and fix risky content before a processor or a Card Network does. This is MONITORING, not a guarantee, and it is best-effort only. The Merchant controls its own website, product copy, advertising, and claims, and the Merchant is solely responsible for that content and for acting on, or declining to act on, any flag. A clean compliance score, a high score, or the absence of a flag is not a certification of legality, is not a determination of compliance, and does not bind, and is not an opinion of, ComplyRUO, Stripe, or any Card Network. The limits of the scan are stated in Section 8.
7.1 Monitoring as described, not guaranteed
The controls described above are what ComplyRUO does: a weekly automated scan of reachable product and policy pages, with automated claim checks and disclaimer checks. ComplyRUO performs these controls as described, but it is not obligated to detect, flag, or catch every issue, every prohibited or risky claim, every missing or defective disclaimer, or every applicable legal or Network requirement, and the monitoring is intended to support, not to guarantee, the Merchant’s compliance. Monitoring is not a guarantee of compliance, legality, or any outcome, and the absence of a flag is not assurance that content is compliant or acceptable to any processor, Card Network, or regulator.
The Merchant remains solely responsible for keeping current with, and complying with, all changing FDA, FTC, DEA, and state requirements, as well as Stripe Agreements and Card Network rules, as described in Section 10. ComplyRUO’s monitoring does not relieve the Merchant of this duty.
8.Limitations of automated scanning
The weekly compliance scan is an automated, software-based, best-effort tool. It is NOT exhaustive and is NOT a substitute for the Merchant’s own legal, regulatory, and compliance review. The Merchant should understand and accept the following limits before relying on any scan output:
- Best-effort and not exhaustive. The scan applies a set of automated checks to the content it can reach at the time it runs. It does not, and is not designed to, identify every compliance issue, every prohibited claim, or every applicable legal or Network requirement.
- False positives. The scan may flag content that is, in fact, compliant or lawful. A flag is a signal for the Merchant’s review, not a finding that anything is unlawful.
- False negatives. The scan may fail to flag content that is, in fact, non-compliant, risky, or unlawful. The absence of a flag does not mean the content is compliant, lawful, or acceptable to any processor, Card Network, or regulator.
- Automated and may err. The scan is performed by software, which may contain errors, may be unavailable, may be interrupted, may misclassify content, and may change over time.
- Reachable content only. The scan reviews only the content it is able to reach and read. It does not review content it cannot access, content behind authentication, dynamic or off-platform content, advertising on third-party channels, packaging, labeling, fulfillment, or anything outside the scanned pages.
THE WEEKLY COMPLIANCE SCAN AND ITS SCORES, FLAGS, AND OUTPUTS ARE PROVIDED AS IS AND ON A BEST-EFFORT, NON-EXHAUSTIVE BASIS, MAY PRODUCE FALSE POSITIVES AND FALSE NEGATIVES, AND ARE OFFERED WITHOUT ANY WARRANTY OF ANY KIND. NO SCORE, FLAG, OR ABSENCE OF A FLAG IS A DETERMINATION OF COMPLIANCE OR LEGALITY OR A GUARANTEE OF ANY OUTCOME. THE MERCHANT REMAINS ONE HUNDRED PERCENT (100%) RESPONSIBLE FOR ITS CONTENT, PRODUCTS, LABELING, CLAIMS, AND COMPLIANCE REGARDLESS OF ANY SCORE OR THE PRESENCE OR ABSENCE OF ANY FLAG.
8.1 A clean scan has no legal effect
A passing compliance score, a high score, or a clean scan is an internal, best-effort, non-exhaustive software signal only. It has NO bearing on, and does not determine, satisfy, or influence, the FDA “intended use” standard at 21 CFR §201.128, under which a product’s intended use is determined from its labeling, its advertising, and the circumstances of its sale. A clean scan does not change how that standard applies to the Merchant’s products, pages, or claims, and it has no bearing on any decision of the FDA, the FTC, the DEA, any other regulator, or Stripe or any Card Network, bank, acquirer, or processor.
A clean scan is best-effort and not exhaustive; false positives and false negatives are possible, and a clean result does not mean that all issues were detected or that none exist. A clean scan creates NO safe harbor, no certification, no defense, and no presumption of compliance or legality, and the Merchant may not rely on it as any of those things.
A PASSING COMPLIANCE SCORE OR A CLEAN SCAN HAS NO BEARING ON THE FDA INTENDED-USE STANDARD AT 21 CFR §201.128 OR ON ANY DECISION OF ANY REGULATOR OR CARD NETWORK. IT IS BEST-EFFORT AND NOT EXHAUSTIVE, MAY PRODUCE FALSE POSITIVES AND FALSE NEGATIVES, AND CREATES NO SAFE HARBOR, CERTIFICATION, DEFENSE, OR PRESUMPTION OF COMPLIANCE OR LEGALITY.
9.The controls are provided AS IS
The researcher gate, the intended-use attestation, the tamper-evident record and its export, the audit ledger, the compliance scan, and every other control and feature described in this policy are tools. They are provided to assist the Merchant in putting preventive measures in place; they do not assume, transfer, or discharge any of the Merchant’s legal, regulatory, or contractual responsibilities.
THE GATE, THE ATTESTATION, THE LEDGER, THE RECORD, THE EXPORT, AND THE SCAN ARE PROVIDED AS IS AND AS AVAILABLE, WITHOUT WARRANTIES OF ANY KIND, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, OR QUIET ENJOYMENT. THESE CONTROLS MAY BE UNAVAILABLE, INTERRUPTED, OR INACCURATE, AND MAY ERR. COMPLYRUO DOES NOT WARRANT THAT THE CONTROLS WILL PREVENT OR REDUCE ANY FINE, HOLD, RESERVE, FREEZE, CHARGEBACK, ASSESSMENT, ACCOUNT REVIEW, MATCH OR TERMINATED MERCHANT FILE LISTING, SUSPENSION, OR TERMINATION, AND DOES NOT WARRANT THAT ANY EXPORT OR RECORD WILL BE ACCEPTED, CREDITED, OR RELIED UPON BY ANY PROCESSOR, ACQUIRER, BANK, CARD NETWORK, AUDITOR, REGULATOR, OR OTHER REVIEWER.
9.1 No liability for the software or for decisions made on it
The gate, the attestation, and the scan are software tools provided AS IS. The Merchant configures, deploys, brands, integrates, operates, and maintains them within its own store and its own environment, and the Merchant decides whether and how to use their outputs. ComplyRUO is not liable for the operation, performance, availability, accuracy, or results of the gate, the attestation, or the scan; for any failure, error, downtime, interruption, misclassification, or bypass of them; for any false, mistaken, incomplete, or omitted attestation or self-affirmation; or for any decision the Merchant or any third party makes or declines to make in reliance on them. Any decision to grant access, accept or refuse an order, ship or withhold product, publish or change content, or act or not act on any score, flag, record, or output is the Merchant’s sole decision and sole responsibility.
THE GATE, THE ATTESTATION, AND THE SCAN ARE PROVIDED AS IS. THE MERCHANT CONFIGURES, DEPLOYS, AND MAINTAINS THEM. COMPLYRUO IS NOT LIABLE FOR THEIR OPERATION, FOR ANY FAILURE, ERROR, INTERRUPTION, OR BYPASS, FOR ANY FALSE OR MISTAKEN ATTESTATION, OR FOR ANY DECISION MADE OR NOT MADE IN RELIANCE ON THEM.
This Section supplements, and is subject to, the broader disclaimer of warranties and the limitation of liability in the Terms of Service, which govern. Nothing here grants the Merchant any warranty or remedy beyond what the Terms of Service provide.
10.The changing regulatory landscape
The legal and regulatory environment for research-use peptides changes, and it changes often. The statutes, regulations, guidance, enforcement priorities, and interpretations of the U.S. Food and Drug Administration (FDA), the Federal Trade Commission (FTC), the Drug Enforcement Administration (DEA), and other federal and state authorities, as well as the rules and policies of Stripe, the Card Networks, banks, acquirers, and processors, can and do change over time, and new requirements may be added at any time.
ComplyRUO’s controls, its locked attestation and disclaimer wording, its gate requirements, and its scan logic reflect ComplyRUO’s point-in-time understanding of those requirements as of the “Last updated” date above. They are not, and do not purport to be, a complete, current, or authoritative statement of the law or of any Network or processor rule. ComplyRUO does not undertake to identify, track, or notify the Merchant of every change in the law or in any Network or processor rule, and ComplyRUO’s controls being in place does not mean they are current or comprehensive.
The Merchant is solely responsible for independently monitoring, staying current with, and complying with all applicable laws, regulations, guidance, enforcement positions, Stripe Agreements, and Card Network rules as they exist and as they change, and for re-confirming, on an ongoing basis, that its business, products, labeling, claims, and content remain compliant. The Merchant may not rely on ComplyRUO, its controls, or its locked wording as being current or as relieving the Merchant of this duty. ComplyRUO may update its controls and locked wording from time to time as described in Section 15, but it is not obligated to do so on any schedule.
11.Merchant responsibilities
The controls in this policy assist the Merchant; they do not replace the Merchant’s own obligations. The Merchant is solely responsible for, at a minimum:
- correct Research-Use-Only and FDA labeling on all products and pages;
- refraining from medical, therapeutic, efficacy, diagnostic, dosing, or human or animal consumption claims, and from any prohibited claim;
- keeping its website, product information, advertising, and policy pages accurate and compliant on an ongoing basis;
- selling strictly business-to-business to qualified research counterparties, and not direct to consumers;
- obtaining and maintaining all licenses, registrations, and permits its business requires;
- keeping its own account, business, payout, and tax information accurate and current, and meeting any applicable KYC and customer-due-diligence obligations; and
- full compliance with all applicable laws (including the Federal Food, Drug, and Cosmetic Act and FDA rules, the FTC Act, the Controlled Substances Act and DEA rules, the Analogue Act, state law, export controls and sanctions, anti-money-laundering law, and privacy law), with the Stripe Agreements, and with all Card Network rules.
The full statement of what the Merchant may and may not sell or do through ComplyRUO is in the Acceptable Use Policy, which is incorporated here by reference. Using ComplyRUO’s controls does not relieve the Merchant of any of these responsibilities.
12.No reliance and independent professional advice
Nothing ComplyRUO provides, and nothing in this policy, on the ComplyRUO site, in the Service, or in any scan, score, flag, record, attestation, export, or other output, is legal, regulatory, compliance, tax, accounting, financial, scientific, or medical advice, and none of it is the opinion of a lawyer, regulator, or medical, scientific, or regulatory authority. ComplyRUO is not the Merchant’s law firm, lawyer, accountant, tax advisor, financial or investment advisor, or fiduciary, and no professional relationship is created by the Merchant’s use of the Service.
THE MERCHANT ACKNOWLEDGES THAT IT HAS OBTAINED, OR HAS HAD THE OPPORTUNITY TO OBTAIN, ITS OWN INDEPENDENT LEGAL, REGULATORY, COMPLIANCE, TAX, AND OTHER PROFESSIONAL ADVICE, AND THAT IT DOES NOT RELY, AND HAS NOT RELIED, ON COMPLYRUO, THE SERVICE, THE SITE, OR ANY SCAN, SCORE, FLAG, RECORD, ATTESTATION, EXPORT, OR THIS POLICY IN DECIDING WHETHER OR HOW TO OPERATE ITS BUSINESS, LABEL OR DESCRIBE ITS PRODUCTS, MAKE OR REFRAIN FROM ANY CLAIM, OR ACCEPT ANY RISK. THE MERCHANT IS SOLELY RESPONSIBLE FOR ITS OWN COMPLIANCE DECISIONS.
13.High-risk acknowledgment and assumption of risk
The Merchant acknowledges that the sale of research-use peptides is a high-risk activity for payment acceptance, that Stripe, banks, acquirers, processors, and the Card Networks treat this vertical as high-risk, and that account review, additional scrutiny, and adverse action are foreseeable risks of operating in this vertical regardless of any control ComplyRUO provides. The controls in this policy are designed to help reduce, but cannot eliminate, those risks, and ComplyRUO does not promise, and the compliance product does not imply, that ComplyRUO will shield the Merchant from them.
THE MERCHANT EXPRESSLY ASSUMES ALL RISK OF ACCOUNT REVIEW, HOLDS, RESERVES, FREEZES, FINES, ASSESSMENTS, PENALTIES, CHARGEBACKS, MATCH OR TERMINATED MERCHANT FILE LISTING, SUSPENSION, AND TERMINATION BY STRIPE, ANY BANK, ANY ACQUIRER, ANY PROCESSOR, OR ANY CARD NETWORK, AND WAIVES ALL RECOURSE AND CLAIMS AGAINST COMPLYRUO AND CEVGATE LLC FOR ANY OF THEM, WHETHER OR NOT ANY COMPLYRUO CONTROL, SCAN, SCORE, RECORD, OR EXPORT WAS IN PLACE, USED, FLAGGED, OR ACCEPTED. THIS ASSUMPTION OF RISK AND WAIVER OF RECOURSE IS A MATERIAL PART OF THE BARGAIN AND IS IN ADDITION TO THE WAIVERS AND LIMITATIONS IN THE TERMS OF SERVICE.
14.What this policy is NOT
This policy describes software controls. To be clear about its limits, this policy and the controls it describes are NOT:
- legal, regulatory, compliance, tax, accounting, financial, scientific, or medical advice, and not the opinion of a lawyer, regulator, or medical, scientific, or regulatory authority;
- a determination, certification, or opinion that any product, page, claim, Buyer, or sale is lawful, correctly labeled, or compliant;
- underwriting, risk-acceptance, or approval of any Merchant or transaction; ComplyRUO is not a payment processor, bank, acquirer, money transmitter or money services business, merchant of record, fiduciary, escrow agent, insurer, broker, financial or investment advisor, or law firm; and
- a guarantee of any outcome, including approval or continued processing by Stripe or any Card Network, or the avoidance of holds, reserves, freezes, fines, assessments, chargebacks, account review, MATCH or Terminated Merchant File listing, suspension, or termination.
THIS POLICY AND THE COMPLYRUO CONTROLS ARE NOT LEGAL, REGULATORY, COMPLIANCE, TAX, ACCOUNTING, FINANCIAL, SCIENTIFIC, OR MEDICAL ADVICE; ARE NOT A LEGAL DETERMINATION, CERTIFICATION, OR OPINION OF COMPLIANCE OR LEGALITY; ARE NOT UNDERWRITING, RISK-ACCEPTANCE, OR APPROVAL OF ANY MERCHANT OR TRANSACTION; AND ARE NOT A GUARANTEE OF APPROVAL, OF CONTINUED PROCESSING, OF THE AVOIDANCE OF ANY FINE, HOLD, RESERVE, FREEZE, CHARGEBACK, REVIEW, MATCH OR TERMINATED MERCHANT FILE LISTING, SUSPENSION, OR TERMINATION, OR OF ANY OTHER OUTCOME WHATSOEVER.
COMPLYRUO DOES NOT DECIDE PAYMENT APPROVAL AND DOES NOT GUARANTEE APPROVAL, CONTINUED PROCESSING, OR ANY OTHER OUTCOME. STRIPE AND THE CARD NETWORKS UNDERWRITE AND ACT AT THEIR SOLE DISCRETION. COMPLYRUO DOES NOT GUARANTEE THAT ANY CONTROL, SCAN, RECORD, OR EXPORT WILL PREVENT ANY FINE, HOLD, RESERVE, CHARGEBACK, REVIEW, MATCH OR TERMINATED MERCHANT FILE LISTING, SUSPENSION, OR TERMINATION, AND COMPLYRUO IS NOT RESPONSIBLE FOR THE ACTS OR OMISSIONS OF STRIPE, ANY CARD NETWORK, BANK, ACQUIRER, PROCESSOR, OR REGULATOR.
15.Records, cooperation, and changes
By using ComplyRUO, the Merchant authorizes ComplyRUO to operate the weekly compliance scan and the attestation recordkeeping described in this policy. ComplyRUO may retain attestation records, scan results, and related logs, and may disclose and share them with Stripe, the Card Networks, banks, acquirers, processors, auditors, and governmental or law-enforcement authorities, as ComplyRUO considers reasonably necessary or as it is required to do, including to respond to a request, investigation, audit, subpoena, or legal obligation. Handling of personal data is governed by the Privacy Policy and, where applicable, the Data Processing Addendum.
ComplyRUO may update this policy, the locked attestation wording, the disclaimer text, the gate requirements, and the scan logic from time to time, including to track changes in the policies or rules of Stripe or the Card Networks, in applicable law (including FDA, FTC, DEA, and state requirements), or in ComplyRUO’s controls. The current version applies to use of the Service after it takes effect, and continued use after an update constitutes acceptance of the updated policy. Material changes will be reflected by the “Last updated” date above. ComplyRUO’s right to update its controls and wording is not a commitment to keep them current with every legal or Network change, and the Merchant’s duty to keep current under Section 10 remains in full force.
16.Contact
Questions about this policy or about how a specific control works can be sent to support@complyruo.com. Legal notices and requests should be sent to support@complyruo.com, addressed to Cevgate LLC.