1. Introduction
This Card Program Agreement (“Agreement”) governs the establishment and operation of a card programme by a business Client (“you,” “your,” or the “Client”) on the platform operated by Fyatu Financial Technologies Limited (“Fyatu,” “we,” “us,” or “our”). It sets out the rules for issuing and managing cards under the Fyatu card programme, including programme setup, card products, cardholder onboarding, funding, spend controls, limits, fees, disputes, and the allocation of liability between the parties.
This Agreement supplements, and must be read together with, the Terms of Service, the Privacy Policy, the AML Policy, and the Data Processing Agreement. In the event of a conflict, the Terms of Service prevail, followed by this Agreement.
By activating a programme or issuing any card on the Fyatu platform, you confirm that you have read, understood, and agree to be bound by this Agreement.
2. Definitions
- BIN Sponsor — the licensed financial institution, authorised by Visa and/or Mastercard, that is the legal issuer of cards under your programme.
- Card — a virtual, physical, or tokenized payment card issued under your programme.
- Cardholder — an individual to whom a Card is issued under your programme.
- Programme — the card issuing programme you configure and operate on the Fyatu platform.
- Programme Balance — the prefunded balance held against your programme from which card spend and fees are settled.
- Setup Fee — the one-time fee payable to activate a programme.
3. Roles of the Parties
Cards are issued by the BIN Sponsor, which is the legal issuer and is subject to the rules of the applicable card network. Fyatu acts as programme manager, facilitating card issuance, lifecycle management, funding, and transaction processing on behalf of the BIN Sponsor.
You act as the programme operator. You determine the purpose of your programme, onboard your own Cardholders, configure card products and controls, and are responsible for your Cardholders’ use of Cards. You are not a card issuer and must not represent yourself as the issuer of the Cards. Your programme and all Cards issued under it are subject to Visa and/or Mastercard network rules and any additional requirements imposed by the BIN Sponsor.
4. Programme Setup and Activation
To activate a programme you must:
- Hold an active, verified Fyatu business account and have completed all required KYB and business due diligence;
- Pay the applicable Setup Fee;
- Accept this Agreement and the related legal agreements during onboarding; and
- Configure at least one card product before issuing Cards.
Fyatu provides a sandbox environment that mirrors production for testing your configuration and integration before go-live. Fyatu may decline to activate, or may suspend, a programme at its discretion where required for risk, compliance, or BIN Sponsor reasons.
5. Card Products and Capabilities
Virtual Cards
Digital cards with a card number, expiry date, and CVV, issued instantly via API. Suitable for online transactions, subscription billing, and digital-first use cases.
Physical Cards
Standard plastic cards produced and shipped to the cardholder’s address. Lead time and production fees apply and are agreed separately.
Tokenized Cards
Cards that can be provisioned to Apple Pay or Google Pay for contactless payments at supported merchants and terminals. Tokenization is available where enabled in your programme configuration.
Card Networks
Cards are issued on the Visa and/or Mastercard networks. The available network is determined by your BIN configuration and programme agreement.
Card Currency
Cards are denominated in USD or EUR. The denomination currency is set at the card product level and cannot be changed after a card is issued.
6. Programme Configuration
You configure your programme through the Fyatu dashboard or API before issuing Cards. Configuration includes:
- Card product definition (network, currency, card type, validity period);
- Default and per-card spending limits;
- Spend controls (MCC restrictions, merchant blocks, geographic limits);
- KYC mode (Managed, Shared, or Minimal);
- 3D Secure settings; and
- JIT Authorization webhook endpoint (where applicable).
7. Card Issuance
Cards are issued programmatically via the Fyatu REST API or through the Fyatu dashboard. Each Card issued is charged at the card issuance fee set out in your pricing schedule. You are responsible for:
- Ensuring each Cardholder has completed the required identity verification before a Card is issued (see Section 8);
- Passing accurate cardholder data to the Fyatu API at the point of issuance;
- Communicating card details (number, expiry, CVV) to Cardholders securely; and
- Maintaining the confidentiality of cardholder PAN data in compliance with PCI DSS requirements.
Fyatu does not store raw PANs on its infrastructure. Card details are returned at issuance and must be retrieved securely via the API.
8. Cardholder Onboarding and KYC
You are responsible for onboarding your Cardholders. Identity verification is governed by your programme’s KYC mode:
- Managed — Fyatu verifies each Cardholder before a Card can be issued.
- Shared — you submit the documents you already hold and Fyatu performs a background verification on each Cardholder before issuance.
- Minimal (No-KYC) — Fyatu waives its own verification and Cardholders can be issued Cards immediately.
Under Shared and Minimal, you are contractually required to perform full identity verification (KYC) and ongoing AML monitoring on every Cardholder — in-house or through a recognised KYC provider — and to evidence it to Fyatu, the BIN Sponsor, or a regulator on request. Failure to maintain adequate Cardholder KYC/AML controls is a material breach of this Agreement.
9. Programme Funding and Balance
Cards are funded from your Programme Balance. Funding methods available to you:
- Stablecoins — USDT (TRC20) and USDC (Polygon), credited to the Programme Balance upon confirmation;
- Other rails — additional funding rails as agreed in your programme configuration.
You are responsible for maintaining a sufficient Programme Balance to cover card spend, fee deductions, and potential chargebacks. Cards will decline transactions where the available balance is insufficient.
For programmes using JIT Authorization, card funding occurs in real time at the point of authorisation via a webhook call to your server. Your server must respond within the configured timeout window; failure to respond results in a declined transaction.
10. Spend Controls and Limits
You set spending limits and spend controls at the card product level or per individual Card via the API, including:
- Per-transaction limits — maximum single transaction amount;
- Daily and monthly limits — cumulative spend caps per Card;
- MCC restrictions — allow or block specific merchant category codes;
- Merchant-level controls — block or allow specific merchants by name or MID;
- Geographic restrictions — limit card acceptance to specific countries or regions.
Fyatu and the BIN Sponsor reserve the right to apply additional limits for risk management or regulatory compliance, which may override your configured controls.
11. Card Usage
Permitted Use
Cards issued under your programme may be used for:
- Online purchases at merchants that accept Visa or Mastercard;
- Point-of-sale transactions where supported by the card type and programme configuration;
- Contactless payments via Apple Pay or Google Pay (for tokenized cards); and
- Subscription and recurring billing.
Restrictions
- ATM cash withdrawals are not supported;
- Cards may not be used for transactions prohibited under the Terms of Service or the AML Policy;
- Cards may not be used for sanctions-restricted transactions or with sanctioned entities;
- Fyatu may decline transactions flagged by fraud detection systems regardless of available balance.
3D Secure
Cards support 3D Secure 2.0 authentication for online transactions and 3DS is enabled by default on all programmes. You are responsible for configuring your 3DS flow and ensuring Cardholders can complete authentication. Transactions requiring 3DS that cannot be authenticated will be declined.
12. Fees
Fees applicable to your programme are set out in your pricing schedule. The applicable rates under the standard plan are:
| Fee | Basis | Rate |
|---|---|---|
| Card Issuance | per card issued | $1.00 |
| Monthly Card Maintenance | per active card / month | Free |
| Card Termination | per card closed | Free |
| Cross-border Transaction | % of transaction amount | 2.5% |
| Decline Fee | per declined authorisation | $0.40 |
| Refund / Reversal | Free | |
| Dispute / Chargeback | per case, win or lose | $30.00 |
Fees are deducted from the Programme Balance as they occur or invoiced in accordance with the Terms of Service. Fyatu reserves the right to modify fees with at least 30 days’ prior notice.
13. Card Validity
- Card validity periods are 1 year, 3 years, or 5 years, configured at the card product level.
- The expiry date is set at issuance and displayed in the API response and dashboard.
- Cards are not automatically renewed. You must issue a replacement Card if required.
- Any remaining balance on an expired Card is returned to the Programme Balance.
14. Card Suspension and Termination
By the Client
You may freeze (temporarily suspend) or terminate any Card under your programme at any time via the API or dashboard. Freezing a Card declines all subsequent transactions; pending authorisations already submitted to the network may still settle. Termination is permanent and cannot be reversed.
By Fyatu
Fyatu may suspend or terminate Cards or an entire programme without prior notice if:
- Suspicious or fraudulent activity is detected at the card or programme level;
- You breach this Agreement or the Terms of Service;
- Your account is suspended or terminated;
- Required by the BIN Sponsor, card network, or a regulatory or law enforcement authority; or
- You fail to maintain adequate KYC or AML controls for your Cardholders.
15. Disputes and Chargebacks
Merchant Refunds
Refunds initiated by merchants are credited to the originating Card balance. If the Card has been terminated or expired, the amount is credited to the Programme Balance. Processing time depends on the merchant and typically takes 5 to 15 business days.
Chargebacks
You are responsible for managing chargeback disputes on behalf of your Cardholders. To initiate a chargeback:
- Submit the dispute via your dedicated Slack channel or at [email protected] with supporting documentation;
- A $30.00 chargeback fee applies per case, regardless of outcome, deducted from the Programme Balance at the time of filing;
- Chargebacks follow the standard dispute resolution timelines of the applicable card network (Visa or Mastercard);
- The outcome is determined by the card network and is final; and
- You bear full financial responsibility for chargeback losses and any associated network fines.
Fyatu will not accept chargeback disputes submitted by individual Cardholders directly. All disputes must be submitted by you on behalf of your Cardholders. For a full explanation of how refunds are handled across every scenario, see the Refund Policy.
16. Client Obligations and Compliance
As a programme operator, you must:
- Maintain accurate business and Cardholder information;
- Perform and evidence Cardholder KYC/AML consistent with your KYC mode;
- Communicate card details to Cardholders only through secure, encrypted channels and maintain PCI DSS compliance where you handle cardholder data;
- Monitor your programme for fraudulent or suspicious activity and report it to Fyatu promptly;
- Ensure Cards are used only for lawful purposes and in compliance with this Agreement and applicable law; and
- Maintain your own end-user terms with your Cardholders.
17. Prohibited Uses
You may not operate a programme, or permit any Card to be used, for any activity prohibited under the Terms of Service or the AML Policy, for sanctions-restricted transactions, or in any manner that breaches Visa or Mastercard network rules or BIN Sponsor requirements.
18. Liability and Indemnity
You bear full liability for all transactions processed under your programme, including unauthorized transactions resulting from inadequate Cardholder verification or insufficient fraud controls, and for all chargeback losses and network fines arising from your programme. You agree to indemnify Fyatu and the BIN Sponsor against any losses, fines, or claims arising from your operation of the programme or your breach of this Agreement.
Fyatu is not liable for:
- Merchant refusal to accept a Card;
- Card network outages or BIN Sponsor technical failures;
- Transactions declined due to insufficient Programme Balance, spending limits, or fraud flags;
- The quality, safety, or delivery of goods or services purchased using Cards issued under your programme; or
- Chargeback losses or network fines arising from your programme.
Fyatu’s aggregate liability under this Agreement is capped at the Monthly Platform Fee paid in the calendar month immediately preceding the event giving rise to the claim.
19. Term and Wind-down
This Agreement remains in effect for as long as you operate a programme on the Fyatu platform. On termination, all active Cards are terminated, Card balances are returned to the Programme Balance, and the Programme Balance is refunded in accordance with the wind-down procedure in the Terms of Service.
20. Relationship to Other Agreements
This Agreement forms part of the overall agreement between you and Fyatu and does not replace the Terms of Service, Privacy Policy, AML Policy, or Data Processing Agreement. Together these documents govern your use of the Fyatu platform.
21. Amendments
Fyatu may amend this Agreement at any time. Material changes will be communicated via your dedicated Slack channel and by email at least 30 days before taking effect. Continued operation of your programme after the effective date constitutes acceptance of the amended Agreement.
22. Governing Law
This Agreement is governed by the laws applicable to Fyatu Financial Technologies Limited (Tanzania, Company No. 173235208), as set out in the Terms of Service.
23. Contact
For programme, commercial, or compliance inquiries:
- Programme support: [email protected]
- Business inquiries: [email protected]
- Legal: [email protected]