KeynoBite
Restaurant Operating Ecosystem
Legal & Compliance

Merchant Onboarding & Compliance Policy

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

Primary intent: Merchant Onboarding & Compliance Policy policy Entity: merchant-onboarding-compliance-policy

Operated by: Keynoverse FZC
Platform: KeynoBite
Contact: onboarding@keynobite.com


Companion Policies

This is the primary merchant governance document for KeynoBite. It should be read together with:

Document Purpose
Audit & Record-Keeping Policy Audit trails, retention, regulatory cooperation
AML & Fraud Prevention Policy Sanctions screening, fraud detection, financial crime controls
Merchant Risk & Escalation Framework Escalation tiers, suspension and termination procedures

1. Introduction

This Merchant Onboarding & Compliance Policy (“Policy”) outlines the onboarding standards, verification requirements, operational compliance expectations, acceptable use rules, and merchant governance framework applicable to restaurants, vendors, food businesses, and related merchant entities using the KeynoBite platform.

KeynoBite is a restaurant commerce and operational technology platform operated by Keynoverse FZC.

1.1 Who This Policy Applies To

This Policy applies to:

  • Restaurants, cafés, cloud kitchens, food retailers, grocery operators, QSR businesses, and multi-branch operators
  • Merchant applicants, approved merchants, and authorized users
  • Ultimate beneficial owners (UBOs), directors, authorized signatories, and control persons
  • Agency, referral, and onboarding partners
  • All other merchant entities accessing the KeynoBite ecosystem

By onboarding onto or using the platform, merchants acknowledge and agree to this Policy and to any supplemental requirements imposed by KeynoBite or by licensed payment service provider (PSP) partners.

1.2 Purpose

This unified Policy establishes:

  • Know Your Business (KYB) and identity verification standards
  • Risk-based merchant onboarding and classification at scale
  • Permitted and prohibited platform use
  • Ongoing monitoring, re-verification, and compliance governance
  • Secure coordination with licensed PSPs and acquirers.
  • KeynoBite’s position as a non-custodial technology platform — not a PSP, acquirer, or settlement operator

1.3 Regulatory Posture — UAE & GCC

KeynoBite is operated by Keynoverse FZC, registered in the United Arab Emirates. Controls are designed with regard to UAE commercial licensing, food safety requirements, applicable AML/CTF expectations for technology platforms supporting payment-enabled commerce, PSP partner requirements in the UAE and GCC, and applicable data protection obligations.

KeynoBite does not hold a payment services license and does not perform regulated payment activities. Compliance controls focus on merchant verification, risk governance, auditability, and PSP coordination — not on custody or settlement of customer funds.


2. Nature of the Platform

2.1 What KeynoBite Is

KeynoBite operates as:

  • A SaaS platform provider and restaurant commerce infrastructure layer
  • An operational workflow system for orders, kitchens, and back-of-house operations
  • A technology integration layer connecting merchants to PSPs, delivery workflows, and customer channels
  • A merchant enablement ecosystem for direct online ordering and branded storefronts

KeynoBite provides branded online ordering, order management, kitchen display tools, merchant onboarding workflows, and secure transmission of onboarding data to PSP partners via API bridges.

2.2 What KeynoBite Is Not

KeynoBite does not operate as:

KeynoBite is NOT Explanation
Payment Service Provider (PSP) Does not obtain payment licenses or authorize payments independently
Marketplace settlement operator Does not pool or route merchant customer settlements
Merchant acquirer or payment facilitator Does not underwrite or acquire merchant payment accounts
Merchant-of-record Does not act as seller-of-record for end-customer food orders
E-money issuer or wallet operator Does not issue stored value or operate wallets
Financial institution or regulated payment intermediary Does not hold, pool, or control merchant customer funds
Logistics operator Does not operate delivery services unless separately contracted by the merchant

Merchants onboarded onto the platform remain independent business entities responsible for their own operational, financial, and regulatory obligations. Payment settlements, where applicable, occur directly between the licensed PSP and the merchant.


3. Merchant Eligibility

To onboard onto KeynoBite, merchants must meet applicable eligibility requirements and may be required to provide valid and verifiable information including:

  • Business name and trading name
  • Trade license and applicable food/health licensing
  • Owner and authorized signatory identification
  • Tax/VAT information where applicable
  • Contact information and operational details
  • Banking and settlement information
  • Supporting compliance documentation

Additional requirements:

  1. Permitted category — lawful food/beverage business within approved categories (Section 4), not a prohibited category (Section 13)
  2. Verifiable identity — owner, UBO, and authorized representative identities can be reasonably verified
  3. Operational substance — genuine operating premises or lawful cloud/delivery kitchen model
  4. Banking suitability — valid settlement account in the licensed entity’s name (where online payments are required)
  5. Accurate declarations — complete and truthful onboarding information and transaction profile
  6. Screening clearance — no match against applicable sanctions lists or internal denial lists
  7. PSP suitability — acceptable to the relevant PSP partner where payment enablement is requested

KeynoBite reserves the right to request additional documentation for operational verification, fraud prevention, compliance review, or platform security, and reserves the absolute right to reject any application at its discretion.


4. Approved Merchant Categories

KeynoBite onboarding is intended for lawful food and beverage businesses, including:

  • Restaurants (full-service, casual, fine dining, hotel)
  • Quick-service and fast-food outlets
  • Cafés, bakeries, dessert shops, juice bars
  • Cloud kitchens (single-brand, multi-brand, delivery-only)
  • Food trucks and catering operators
  • Grocery, specialty food, and supermarket food retail (where licensed)
  • Franchise and multi-branch food operators

Multi-branch merchants must declare branch count at onboarding. KeynoBite may require per-branch or sample-branch verification. Additional branches added post-approval may trigger re-verification.


5. Merchant Verification, KYB & Onboarding

5.1 Verification & Review

All onboarding requests remain subject to operational review and verification. KeynoBite may:

  • Verify submitted information and document authenticity
  • Review merchant operational activity and business model
  • Request clarification or additional documentation
  • Conduct risk-based assessments and sanctions/PEP screening
  • Coordinate with PSP partners on merchant suitability
  • Reject onboarding requests at its discretion

Approval onto the platform does not constitute legal, financial, regulatory, or compliance certification of any merchant activity.

5.2 Onboarding Workflow

Each application receives a unique reference (e.g. KB-VAPP-XXXXXX).

Step Section Data Collected
1 Account Creation Owner contact, email, phone, credentials
2 Business Details Legal entity, trade license, authorized representative, address
3 Compliance & Risk Cuisine, branches, service modes, countries, delivery model
4 Transaction Profile AOV, expected monthly/annual volumes and revenue
5 Banking Account name, IBAN, bank name, branch
6 UBO Beneficial owners, control persons, PEP declarations
7 Documents KYB/KYC document package upload
8 Review & Submit Merchant attestation and submission
9 Plan & Payment Subscription selection and platform fee

5.3 Post-Submission Review States

Status Description
kyc_review KeynoBite compliance review of KYB package
psp_review PSP partner review and credential readiness
approved Approved for platform provisioning
pushed Live on KeynoBite platform
rejected Declined with documented reason

All status transitions and reviewer actions are logged for audit and traceability (see Audit Policy).

5.4 Required Documentation — KYB Package

Category Document Requirement
Corporate Trade License Required
Corporate MOA / MOU Required
Corporate Commercial Register Optional
Corporate VAT Certificate Jurisdiction-dependent
Corporate Food / Health License As applicable
Address Tenancy Contract / Lease Required
Address Utility Bill (e.g. DEWA) Required
Premises Photographs (min. 4) Required
Banking Bank Confirmation Letter Required
Identity Owner/UBO Passport Required
Identity Emirates ID (UAE residents) Required
Identity Visa Optional

Documents are reviewed for completeness, consistency, validity, name/entity matching, and signs of alteration or misrepresentation. Shell entities or unverifiable addresses may be rejected.


6. Beneficial Ownership & PEP Screening

Merchants must identify all Ultimate Beneficial Owners (UBOs) and persons exercising significant control, including individuals owning or controlling 25% or more of the entity (or lower thresholds where required by PSP or law).

For each UBO/control person, KeynoBite collects full legal name, designation, residential address, contact details, PEP status (self-declaration), and supporting identity documentation.

Politically Exposed Persons (PEPs) must be declared at onboarding. PEP identification triggers Enhanced Due Diligence (EDD) per Section 8.

Material changes in ownership, UBO composition, or control structure must be reported within 14 business days and may trigger re-verification.


7. Merchant Risk Classification

KeynoBite applies risk-based merchant categorization:

Tier Description Review Cycle
Low Single-location restaurant, standard AOV, complete docs Every 24 months
Medium Multi-branch, cloud kitchen, franchise, cross-border Every 12 months
High PEP, adverse indicators, volume mismatch, prior PSP rejection Every 6 months or continuous

Risk factors include entity/licensing profile, ownership structure, geography, business model, transaction profile, behavioral indicators, screening results, and PSP feedback. KeynoBite reserves the right to reject, defer, or conditionally approve any merchant based on risk outcomes.


8. Enhanced Due Diligence (EDD)

EDD is applied when standard KYB is insufficient, including for PEP involvement, high-risk tier classification, sanctions/adverse media indicators, transaction profile mismatches, complex corporate structures, PSP mandates, or suspicious onboarding patterns.

EDD may include additional documentation, source-of-funds/wealth inquiries, premises verification, senior compliance approval, extended PSP review, and restricted payment enablement until cleared.


9. Payment & PSP Compliance

Where payment functionality is enabled:

  • Merchants may maintain independent relationships with licensed PSPs
  • Merchants may undergo direct PSP onboarding and KYC/compliance review
  • Merchants may receive PSP-issued credentials and settlement arrangements
  • Settlements occur directly between the PSP and the merchant

KeynoBite itself does not hold merchant funds, process settlements, operate wallets, or act as merchant-of-record for merchant customer transactions.

Responsibility KeynoBite PSP Partner Merchant
KYB data collection
Platform compliance review
Regulated KYC/AML review
Payment authorization & settlement Receives
Merchant credentials Facilitates secure handoff Issues Maintains

KeynoBite transmits onboarding packages to PSP partners via secure API integration. Payment credentials are never activated until PSP authorization is confirmed. Merchants remain responsible for complying with PSP operational and compliance requirements.


10. Independent Merchant Responsibility

Merchants using KeynoBite remain solely responsible for:

  • Their products and services, including food quality and safety
  • Operational fulfillment, pricing, and menu accuracy
  • Customer support and complaint handling
  • Delivery operations (where merchant-managed)
  • Legal compliance, tax obligations, and regulatory requirements
  • PSP terms, chargeback rules, and wallet KYC requirements applicable to their business

Each merchant operates independently and is not an employee or agent of Keynoverse FZC. KeynoBite does not assume responsibility for merchant business conduct, food safety outcomes, or customer disputes.


11. Permitted Platform Use

Merchants may use KeynoBite to:

  • Operate branded online ordering for lawfully licensed food and beverage businesses
  • Manage menus, pricing, orders, and operational workflows
  • Configure delivery, takeaway, and dine-in service modes
  • Integrate with approved PSPs for customer payment acceptance
  • Communicate order status to customers through platform channels
  • Manage staff access to merchant admin and kitchen tools
  • Operate multi-branch locations declared and verified at onboarding

All use must align with the merchant’s declared business category and transaction profile. Use of the platform is a privilege conditioned on lawful, honest, and compliant behavior.


12. Merchant Responsibilities

Merchants and authorized users must:

  • Provide accurate, complete, and truthful onboarding and operational information
  • Maintain valid licensing and lawful business conduct
  • Protect login credentials and role-appropriate access controls
  • Fulfill orders promptly and handle refunds/cancellations per applicable law and PSP rules
  • Ensure customer communication and fulfillment practices are proper
  • Notify KeynoBite within 14 business days of material changes to ownership, licensing, banking, operational structure, or legal status
  • Cooperate with compliance, fraud, audit, and PSP inquiries

13. Prohibited Activities, Categories & Conduct

Merchants may not use KeynoBite for unlawful, fraudulent, deceptive, abusive, or prohibited activities.

13.1 Prohibited Business Categories

Category Examples
Gambling & gaming Casinos, betting, online gambling, lottery schemes
Adult services Pornography, escort services, adult entertainment
Unlicensed financial services Money transfer, remittance, unlicensed lending, forex
Cryptocurrency & digital assets Crypto exchanges, ICO/token sales, unregulated NFT marketplaces
Illegal substances Narcotics, controlled drugs, drug paraphernalia
Weapons & hazardous materials Firearms, ammunition, explosives
Counterfeit & pirated goods Fake brands, counterfeit products, IP infringement
Sanctioned entities Businesses owned/controlled by sanctioned parties
Shell / pass-through merchants No genuine food operation; third-party payment processing
Deceptive schemes Fake restaurants, bait-and-switch, undisclosed non-food sales
Any unlawful business Illegal under UAE law or merchant jurisdiction

13.2 Prohibited Conduct

Prohibited activities include, but are not limited to:

  • Fraud & misrepresentation — false onboarding information, forged documents, identity misrepresentation, duplicate accounts to evade rejection
  • Financial crime — fraudulent transactions, money laundering, sanctions violations, transaction laundering, chargeback fraud
  • Payment abuse — processing payments outside declared food business, PSP credential misuse, manipulated transaction/refund patterns
  • Platform abuse — unauthorized access, API abuse, malware/bots, circumventing compliance controls
  • Customer harm — unsafe or mislabeled products, deceptive pricing, unauthorized data harvesting
  • Legal violations — unlicensed operation, IP infringement, PSP terms violations
  • Sale of prohibited goods, unauthorized financial services, or unlawful operational conduct

KeynoBite reserves the right to suspend or terminate platform access where prohibited or suspicious activity is identified, including immediately and without prior notice where fraud or serious compliance risk is identified.

13.3 Restricted Categories (Conditional Approval)

The following require enhanced approval and ongoing monitoring:

  • Shisha cafés and lounges (valid licensing required)
  • Multi-brand cloud kitchens and large multi-branch chains
  • Cross-border operations outside primary licensing jurisdiction
  • Age-restricted items where locally permitted

14. Operational Monitoring & Risk Review

KeynoBite may conduct operational monitoring and risk reviews for:

  • Fraud prevention, platform security, and operational integrity
  • Abuse detection, compliance management, and ecosystem protection
  • Onboarding activity, merchant behavior, and platform usage patterns
  • Customer complaints, dispute trends, refund activity, and chargeback signals
  • Suspicious conduct indicators and deviation from declared transaction profiles

14.1 Periodic & Event-Driven Re-Verification

Re-verification may be triggered by license expiry, ownership/banking changes, new branches, business model changes, sustained volume variance (>50%), elevated disputes/chargebacks, PSP notices, sanctions/PEP hits, or suspicious activity.

Detailed fraud and AML monitoring controls are in the AML & Fraud Prevention Policy. Escalation procedures are in the Risk & Escalation Framework.

KeynoBite reserves the right to restrict, suspend, or terminate platform access where elevated operational or compliance risk is identified.


15. Agency, Partner & Content Standards

Agencies and referral partners must onboard only genuine licensed food businesses, not coach misrepresentation, report suspected fraud, and not share portal credentials. Agencies may be suspended for non-compliant referral patterns.

Merchant content (menus, images, promotions) must be accurate, lawful, non-deceptive, and must not infringe third-party intellectual property. KeynoBite may remove violating content without prior notice.


16. Third-Party Services & Integrations

Merchants may utilize integrations provided by third parties including PSPs, logistics providers, POS systems, and communication services.

KeynoBite does not assume responsibility for third-party operational failures, compliance obligations, or contractual disputes. KeynoBite may disable integrations that create compliance or security risk. Each third party remains responsible for its own regulatory obligations.


17. Data Retention & Audit Rights

KeynoBite retains merchant KYB/KYC records, review notes, risk classifications, UBO declarations, and audit logs for a minimum of five (5) years following merchant offboarding, or longer as required by UAE law, PSP contracts, or active investigations.

Audit trails cover onboarding portal actions, API transmissions, review status changes, and platform provisioning. Full controls are defined in the Audit & Record-Keeping Policy.


18. Suspension, Restriction & Termination

KeynoBite may suspend, restrict, or terminate merchant access where:

  • False, incomplete, or misleading information is submitted
  • Compliance concerns, fraud, or prohibited activity is suspected or confirmed
  • Documents are expired, forged, or inconsistent
  • PSP review is declined or credentials are revoked
  • Periodic re-verification is not completed
  • This Policy or companion policies are violated
  • Subscription or contractual obligations are materially breached

Escalation tiers and appeal paths are defined in the Merchant Risk & Escalation Framework.


19. Regulatory Cooperation

KeynoBite cooperates with competent authorities, licensed PSPs, acquirers, and auditors on lawful requests relating to merchant onboarding and platform governance, subject to applicable law and data protection requirements. Merchants agree to cooperate with reasonable compliance inquiries from KeynoBite and its PSP partners.


20. Limitation of Liability

To the maximum extent permitted by applicable law, KeynoBite shall not be liable for:

  • Merchant business losses or operational interruptions
  • Regulatory actions arising from merchant conduct
  • PSP decisions, settlement delays, or credential revocation
  • Third-party service failures or compliance-related disputes

Merchants remain solely responsible for their own business activities and operational conduct.


21. Changes to This Policy

KeynoBite may update this Policy periodically to reflect operational changes, compliance requirements, platform updates, risk management enhancements, or legal developments.

Material updates will be communicated via the onboarding portal, merchant dashboard, or direct notice where appropriate. Continued use of the platform constitutes acceptance of the revised Policy.

This Policy is owned by Keynoverse FZC and reviewed at least annually, or upon material platform, regulatory, or PSP partner changes.


22. Contact

For onboarding, compliance, or merchant governance inquiries:

Channel Details
Email onboarding@keynobite.com
Website KeynoBite
Operator Keynoverse FZC

KeynoBite is a technology platform operated by Keynoverse FZC. This Policy describes merchant onboarding, compliance governance, and acceptable use controls. It does not constitute legal, financial, or regulatory advice.

The Challenge

What challenge does Merchant Onboarding & Compliance Policy address?

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

The KeynoBite Approach

How KeynoBite approaches Merchant Onboarding & Compliance Policy

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

Need a walkthrough?

Map Merchant Onboarding & Compliance Policy to your restaurant setup

Book a walkthrough with the KeynoBite team to see how this area fits your operating model.