Operated by: Keynoverse FZC
Platform: KeynoBite
Contact: onboarding@keynobite.com
Companion Policies
This is the primary merchant governance document for KeynoBite. It should be read together with:
| Document | Purpose |
|---|---|
| Audit & Record-Keeping Policy | Audit trails, retention, regulatory cooperation |
| AML & Fraud Prevention Policy | Sanctions screening, fraud detection, financial crime controls |
| Merchant Risk & Escalation Framework | Escalation tiers, suspension and termination procedures |
1. Introduction
This Merchant Onboarding & Compliance Policy (“Policy”) outlines the onboarding standards, verification requirements, operational compliance expectations, acceptable use rules, and merchant governance framework applicable to restaurants, vendors, food businesses, and related merchant entities using the KeynoBite platform.
KeynoBite is a restaurant commerce and operational technology platform operated by Keynoverse FZC.
1.1 Who This Policy Applies To
This Policy applies to:
- Restaurants, cafés, cloud kitchens, food retailers, grocery operators, QSR businesses, and multi-branch operators
- Merchant applicants, approved merchants, and authorized users
- Ultimate beneficial owners (UBOs), directors, authorized signatories, and control persons
- Agency, referral, and onboarding partners
- All other merchant entities accessing the KeynoBite ecosystem
By onboarding onto or using the platform, merchants acknowledge and agree to this Policy and to any supplemental requirements imposed by KeynoBite or by licensed payment service provider (PSP) partners.
1.2 Purpose
This unified Policy establishes:
- Know Your Business (KYB) and identity verification standards
- Risk-based merchant onboarding and classification at scale
- Permitted and prohibited platform use
- Ongoing monitoring, re-verification, and compliance governance
- Secure coordination with licensed PSPs and acquirers.
- KeynoBite’s position as a non-custodial technology platform — not a PSP, acquirer, or settlement operator
1.3 Regulatory Posture — UAE & GCC
KeynoBite is operated by Keynoverse FZC, registered in the United Arab Emirates. Controls are designed with regard to UAE commercial licensing, food safety requirements, applicable AML/CTF expectations for technology platforms supporting payment-enabled commerce, PSP partner requirements in the UAE and GCC, and applicable data protection obligations.
KeynoBite does not hold a payment services license and does not perform regulated payment activities. Compliance controls focus on merchant verification, risk governance, auditability, and PSP coordination — not on custody or settlement of customer funds.
2. Nature of the Platform
2.1 What KeynoBite Is
KeynoBite operates as:
- A SaaS platform provider and restaurant commerce infrastructure layer
- An operational workflow system for orders, kitchens, and back-of-house operations
- A technology integration layer connecting merchants to PSPs, delivery workflows, and customer channels
- A merchant enablement ecosystem for direct online ordering and branded storefronts
KeynoBite provides branded online ordering, order management, kitchen display tools, merchant onboarding workflows, and secure transmission of onboarding data to PSP partners via API bridges.
2.2 What KeynoBite Is Not
KeynoBite does not operate as:
| KeynoBite is NOT | Explanation |
|---|---|
| Payment Service Provider (PSP) | Does not obtain payment licenses or authorize payments independently |
| Marketplace settlement operator | Does not pool or route merchant customer settlements |
| Merchant acquirer or payment facilitator | Does not underwrite or acquire merchant payment accounts |
| Merchant-of-record | Does not act as seller-of-record for end-customer food orders |
| E-money issuer or wallet operator | Does not issue stored value or operate wallets |
| Financial institution or regulated payment intermediary | Does not hold, pool, or control merchant customer funds |
| Logistics operator | Does not operate delivery services unless separately contracted by the merchant |
Merchants onboarded onto the platform remain independent business entities responsible for their own operational, financial, and regulatory obligations. Payment settlements, where applicable, occur directly between the licensed PSP and the merchant.
3. Merchant Eligibility
To onboard onto KeynoBite, merchants must meet applicable eligibility requirements and may be required to provide valid and verifiable information including:
- Business name and trading name
- Trade license and applicable food/health licensing
- Owner and authorized signatory identification
- Tax/VAT information where applicable
- Contact information and operational details
- Banking and settlement information
- Supporting compliance documentation
Additional requirements:
- Permitted category — lawful food/beverage business within approved categories (Section 4), not a prohibited category (Section 13)
- Verifiable identity — owner, UBO, and authorized representative identities can be reasonably verified
- Operational substance — genuine operating premises or lawful cloud/delivery kitchen model
- Banking suitability — valid settlement account in the licensed entity’s name (where online payments are required)
- Accurate declarations — complete and truthful onboarding information and transaction profile
- Screening clearance — no match against applicable sanctions lists or internal denial lists
- PSP suitability — acceptable to the relevant PSP partner where payment enablement is requested
KeynoBite reserves the right to request additional documentation for operational verification, fraud prevention, compliance review, or platform security, and reserves the absolute right to reject any application at its discretion.
4. Approved Merchant Categories
KeynoBite onboarding is intended for lawful food and beverage businesses, including:
- Restaurants (full-service, casual, fine dining, hotel)
- Quick-service and fast-food outlets
- Cafés, bakeries, dessert shops, juice bars
- Cloud kitchens (single-brand, multi-brand, delivery-only)
- Food trucks and catering operators
- Grocery, specialty food, and supermarket food retail (where licensed)
- Franchise and multi-branch food operators
Multi-branch merchants must declare branch count at onboarding. KeynoBite may require per-branch or sample-branch verification. Additional branches added post-approval may trigger re-verification.
5. Merchant Verification, KYB & Onboarding
5.1 Verification & Review
All onboarding requests remain subject to operational review and verification. KeynoBite may:
- Verify submitted information and document authenticity
- Review merchant operational activity and business model
- Request clarification or additional documentation
- Conduct risk-based assessments and sanctions/PEP screening
- Coordinate with PSP partners on merchant suitability
- Reject onboarding requests at its discretion
Approval onto the platform does not constitute legal, financial, regulatory, or compliance certification of any merchant activity.
5.2 Onboarding Workflow
Each application receives a unique reference (e.g. KB-VAPP-XXXXXX).
| Step | Section | Data Collected |
|---|---|---|
| 1 | Account Creation | Owner contact, email, phone, credentials |
| 2 | Business Details | Legal entity, trade license, authorized representative, address |
| 3 | Compliance & Risk | Cuisine, branches, service modes, countries, delivery model |
| 4 | Transaction Profile | AOV, expected monthly/annual volumes and revenue |
| 5 | Banking | Account name, IBAN, bank name, branch |
| 6 | UBO | Beneficial owners, control persons, PEP declarations |
| 7 | Documents | KYB/KYC document package upload |
| 8 | Review & Submit | Merchant attestation and submission |
| 9 | Plan & Payment | Subscription selection and platform fee |
5.3 Post-Submission Review States
| Status | Description |
|---|---|
kyc_review |
KeynoBite compliance review of KYB package |
psp_review |
PSP partner review and credential readiness |
approved |
Approved for platform provisioning |
pushed |
Live on KeynoBite platform |
rejected |
Declined with documented reason |
All status transitions and reviewer actions are logged for audit and traceability (see Audit Policy).
5.4 Required Documentation — KYB Package
| Category | Document | Requirement |
|---|---|---|
| Corporate | Trade License | Required |
| Corporate | MOA / MOU | Required |
| Corporate | Commercial Register | Optional |
| Corporate | VAT Certificate | Jurisdiction-dependent |
| Corporate | Food / Health License | As applicable |
| Address | Tenancy Contract / Lease | Required |
| Address | Utility Bill (e.g. DEWA) | Required |
| Premises | Photographs (min. 4) | Required |
| Banking | Bank Confirmation Letter | Required |
| Identity | Owner/UBO Passport | Required |
| Identity | Emirates ID (UAE residents) | Required |
| Identity | Visa | Optional |
Documents are reviewed for completeness, consistency, validity, name/entity matching, and signs of alteration or misrepresentation. Shell entities or unverifiable addresses may be rejected.
6. Beneficial Ownership & PEP Screening
Merchants must identify all Ultimate Beneficial Owners (UBOs) and persons exercising significant control, including individuals owning or controlling 25% or more of the entity (or lower thresholds where required by PSP or law).
For each UBO/control person, KeynoBite collects full legal name, designation, residential address, contact details, PEP status (self-declaration), and supporting identity documentation.
Politically Exposed Persons (PEPs) must be declared at onboarding. PEP identification triggers Enhanced Due Diligence (EDD) per Section 8.
Material changes in ownership, UBO composition, or control structure must be reported within 14 business days and may trigger re-verification.
7. Merchant Risk Classification
KeynoBite applies risk-based merchant categorization:
| Tier | Description | Review Cycle |
|---|---|---|
| Low | Single-location restaurant, standard AOV, complete docs | Every 24 months |
| Medium | Multi-branch, cloud kitchen, franchise, cross-border | Every 12 months |
| High | PEP, adverse indicators, volume mismatch, prior PSP rejection | Every 6 months or continuous |
Risk factors include entity/licensing profile, ownership structure, geography, business model, transaction profile, behavioral indicators, screening results, and PSP feedback. KeynoBite reserves the right to reject, defer, or conditionally approve any merchant based on risk outcomes.
8. Enhanced Due Diligence (EDD)
EDD is applied when standard KYB is insufficient, including for PEP involvement, high-risk tier classification, sanctions/adverse media indicators, transaction profile mismatches, complex corporate structures, PSP mandates, or suspicious onboarding patterns.
EDD may include additional documentation, source-of-funds/wealth inquiries, premises verification, senior compliance approval, extended PSP review, and restricted payment enablement until cleared.
9. Payment & PSP Compliance
Where payment functionality is enabled:
- Merchants may maintain independent relationships with licensed PSPs
- Merchants may undergo direct PSP onboarding and KYC/compliance review
- Merchants may receive PSP-issued credentials and settlement arrangements
- Settlements occur directly between the PSP and the merchant
KeynoBite itself does not hold merchant funds, process settlements, operate wallets, or act as merchant-of-record for merchant customer transactions.
| Responsibility | KeynoBite | PSP Partner | Merchant |
|---|---|---|---|
| KYB data collection | ✓ | ||
| Platform compliance review | ✓ | ||
| Regulated KYC/AML review | ✓ | ||
| Payment authorization & settlement | ✓ | Receives | |
| Merchant credentials | Facilitates secure handoff | Issues | Maintains |
KeynoBite transmits onboarding packages to PSP partners via secure API integration. Payment credentials are never activated until PSP authorization is confirmed. Merchants remain responsible for complying with PSP operational and compliance requirements.
10. Independent Merchant Responsibility
Merchants using KeynoBite remain solely responsible for:
- Their products and services, including food quality and safety
- Operational fulfillment, pricing, and menu accuracy
- Customer support and complaint handling
- Delivery operations (where merchant-managed)
- Legal compliance, tax obligations, and regulatory requirements
- PSP terms, chargeback rules, and wallet KYC requirements applicable to their business
Each merchant operates independently and is not an employee or agent of Keynoverse FZC. KeynoBite does not assume responsibility for merchant business conduct, food safety outcomes, or customer disputes.
11. Permitted Platform Use
Merchants may use KeynoBite to:
- Operate branded online ordering for lawfully licensed food and beverage businesses
- Manage menus, pricing, orders, and operational workflows
- Configure delivery, takeaway, and dine-in service modes
- Integrate with approved PSPs for customer payment acceptance
- Communicate order status to customers through platform channels
- Manage staff access to merchant admin and kitchen tools
- Operate multi-branch locations declared and verified at onboarding
All use must align with the merchant’s declared business category and transaction profile. Use of the platform is a privilege conditioned on lawful, honest, and compliant behavior.
12. Merchant Responsibilities
Merchants and authorized users must:
- Provide accurate, complete, and truthful onboarding and operational information
- Maintain valid licensing and lawful business conduct
- Protect login credentials and role-appropriate access controls
- Fulfill orders promptly and handle refunds/cancellations per applicable law and PSP rules
- Ensure customer communication and fulfillment practices are proper
- Notify KeynoBite within 14 business days of material changes to ownership, licensing, banking, operational structure, or legal status
- Cooperate with compliance, fraud, audit, and PSP inquiries
13. Prohibited Activities, Categories & Conduct
Merchants may not use KeynoBite for unlawful, fraudulent, deceptive, abusive, or prohibited activities.
13.1 Prohibited Business Categories
| Category | Examples |
|---|---|
| Gambling & gaming | Casinos, betting, online gambling, lottery schemes |
| Adult services | Pornography, escort services, adult entertainment |
| Unlicensed financial services | Money transfer, remittance, unlicensed lending, forex |
| Cryptocurrency & digital assets | Crypto exchanges, ICO/token sales, unregulated NFT marketplaces |
| Illegal substances | Narcotics, controlled drugs, drug paraphernalia |
| Weapons & hazardous materials | Firearms, ammunition, explosives |
| Counterfeit & pirated goods | Fake brands, counterfeit products, IP infringement |
| Sanctioned entities | Businesses owned/controlled by sanctioned parties |
| Shell / pass-through merchants | No genuine food operation; third-party payment processing |
| Deceptive schemes | Fake restaurants, bait-and-switch, undisclosed non-food sales |
| Any unlawful business | Illegal under UAE law or merchant jurisdiction |
13.2 Prohibited Conduct
Prohibited activities include, but are not limited to:
- Fraud & misrepresentation — false onboarding information, forged documents, identity misrepresentation, duplicate accounts to evade rejection
- Financial crime — fraudulent transactions, money laundering, sanctions violations, transaction laundering, chargeback fraud
- Payment abuse — processing payments outside declared food business, PSP credential misuse, manipulated transaction/refund patterns
- Platform abuse — unauthorized access, API abuse, malware/bots, circumventing compliance controls
- Customer harm — unsafe or mislabeled products, deceptive pricing, unauthorized data harvesting
- Legal violations — unlicensed operation, IP infringement, PSP terms violations
- Sale of prohibited goods, unauthorized financial services, or unlawful operational conduct
KeynoBite reserves the right to suspend or terminate platform access where prohibited or suspicious activity is identified, including immediately and without prior notice where fraud or serious compliance risk is identified.
13.3 Restricted Categories (Conditional Approval)
The following require enhanced approval and ongoing monitoring:
- Shisha cafés and lounges (valid licensing required)
- Multi-brand cloud kitchens and large multi-branch chains
- Cross-border operations outside primary licensing jurisdiction
- Age-restricted items where locally permitted
14. Operational Monitoring & Risk Review
KeynoBite may conduct operational monitoring and risk reviews for:
- Fraud prevention, platform security, and operational integrity
- Abuse detection, compliance management, and ecosystem protection
- Onboarding activity, merchant behavior, and platform usage patterns
- Customer complaints, dispute trends, refund activity, and chargeback signals
- Suspicious conduct indicators and deviation from declared transaction profiles
14.1 Periodic & Event-Driven Re-Verification
Re-verification may be triggered by license expiry, ownership/banking changes, new branches, business model changes, sustained volume variance (>50%), elevated disputes/chargebacks, PSP notices, sanctions/PEP hits, or suspicious activity.
Detailed fraud and AML monitoring controls are in the AML & Fraud Prevention Policy. Escalation procedures are in the Risk & Escalation Framework.
KeynoBite reserves the right to restrict, suspend, or terminate platform access where elevated operational or compliance risk is identified.
15. Agency, Partner & Content Standards
Agencies and referral partners must onboard only genuine licensed food businesses, not coach misrepresentation, report suspected fraud, and not share portal credentials. Agencies may be suspended for non-compliant referral patterns.
Merchant content (menus, images, promotions) must be accurate, lawful, non-deceptive, and must not infringe third-party intellectual property. KeynoBite may remove violating content without prior notice.
16. Third-Party Services & Integrations
Merchants may utilize integrations provided by third parties including PSPs, logistics providers, POS systems, and communication services.
KeynoBite does not assume responsibility for third-party operational failures, compliance obligations, or contractual disputes. KeynoBite may disable integrations that create compliance or security risk. Each third party remains responsible for its own regulatory obligations.
17. Data Retention & Audit Rights
KeynoBite retains merchant KYB/KYC records, review notes, risk classifications, UBO declarations, and audit logs for a minimum of five (5) years following merchant offboarding, or longer as required by UAE law, PSP contracts, or active investigations.
Audit trails cover onboarding portal actions, API transmissions, review status changes, and platform provisioning. Full controls are defined in the Audit & Record-Keeping Policy.
18. Suspension, Restriction & Termination
KeynoBite may suspend, restrict, or terminate merchant access where:
- False, incomplete, or misleading information is submitted
- Compliance concerns, fraud, or prohibited activity is suspected or confirmed
- Documents are expired, forged, or inconsistent
- PSP review is declined or credentials are revoked
- Periodic re-verification is not completed
- This Policy or companion policies are violated
- Subscription or contractual obligations are materially breached
Escalation tiers and appeal paths are defined in the Merchant Risk & Escalation Framework.
19. Regulatory Cooperation
KeynoBite cooperates with competent authorities, licensed PSPs, acquirers, and auditors on lawful requests relating to merchant onboarding and platform governance, subject to applicable law and data protection requirements. Merchants agree to cooperate with reasonable compliance inquiries from KeynoBite and its PSP partners.
20. Limitation of Liability
To the maximum extent permitted by applicable law, KeynoBite shall not be liable for:
- Merchant business losses or operational interruptions
- Regulatory actions arising from merchant conduct
- PSP decisions, settlement delays, or credential revocation
- Third-party service failures or compliance-related disputes
Merchants remain solely responsible for their own business activities and operational conduct.
21. Changes to This Policy
KeynoBite may update this Policy periodically to reflect operational changes, compliance requirements, platform updates, risk management enhancements, or legal developments.
Material updates will be communicated via the onboarding portal, merchant dashboard, or direct notice where appropriate. Continued use of the platform constitutes acceptance of the revised Policy.
This Policy is owned by Keynoverse FZC and reviewed at least annually, or upon material platform, regulatory, or PSP partner changes.
22. Contact
For onboarding, compliance, or merchant governance inquiries:
| Channel | Details |
|---|---|
| onboarding@keynobite.com | |
| Website | KeynoBite |
| Operator | Keynoverse FZC |
KeynoBite is a technology platform operated by Keynoverse FZC. This Policy describes merchant onboarding, compliance governance, and acceptable use controls. It does not constitute legal, financial, or regulatory advice.