Six documents, four triggers
They do not all become due at once. The privacy policy is due now, because the application form carries a work email and twelve months of chargeback history into the merchant portal and an account is created from it. The merchant agreement is not due until there is a rail to bind a merchant to.
The set
Terms of Use
Covers the website, not the service. The rate card is information, not an offer.
Due now /legal/privacy-policyPrivacy Policy
Australian Privacy Principles. The one document with statutory force behind it.
Due nowBlocked on entity /legal/acceptable-useAcceptable Use Policy
A risk control, not boilerplate. What we board, what we never board, what breach costs.
Due now /legal/merchant-agreementMerchant Agreement
The binding contract. Every commercial term in it is already a promise on the pricing page.
First merchantNeeds counsel /legal/disclaimerDisclaimer
Rates are indicative. We are not a bank, and several advertised capabilities are intent.
Due now /legal/complianceCompliance & Disclosures
PCI posture, scheme programmes, AML position, complaints. The page an acquirer asks for.
First acquirer callNeeds counselSequencing
Ordered by what makes each document due, not by how hard it is to write.
The application form has a destination
Already true. The public form hands step one to the merchant portal, which creates an account from it.
Privacy Policy · Terms of Use · Disclaimer · Acceptable Use · this hub
First acquirer conversation
It is the document they ask for, and having it ready says how the portfolio will be run.
Compliance & Disclosures
Direct merchant account signed
Nothing can be bound before there is a rail to bind it to.
Merchant Agreement · first full legal review of everything above
First third-party merchant boarded
A contract nobody accepted a specific version of is a contract with no terms.
Versioned acceptance · sub-processor annex · change notification
What the site already promises
Each row is live copy today. The documents either honour it or the site stops saying it.
| Claim | Where | What has to be true |
|---|---|---|
| Decision in four business days | Hero, apply | A service commitment, or soften to “usually” |
| 8.9% / 11.9% / from 5.9% | Pricing | A forward price on a rail we do not hold — the disclaimer must say so |
| No setup fee, no annual registration, no monthly minimum | Pricing masthead | Fee schedule contains none, and variation cannot add them silently |
| 5% / 10% reserve, released at 180 days | Plan cards | Exact reserve and release clause |
| A$25 chargeback fee | Calculator | Named in the fee schedule at that number |
| Repriced to Standard after six clean cycles | Elevated plan | A right the merchant can hold us to; “clean cycle” defined |
| Cascading acquirers, pre-chargeback alerts | Plan cards | Not implemented. Build it, or the disclaimer covers it |
| We never pull consumer credit | Apply form | A binding limit, repeated in the privacy policy |
| We may contact your prior processor | Apply form | Needs a disclosure basis in the privacy policy |
Before any of this is signed off
Five facts appear verbatim across these documents and none of them is settled.
- Gallantree Pty Ltd ABN and registered office — every footer block
- Whether the EEA entity forms, and which entity contracts with merchants — merchant agreement, privacy policy, disclaimer
- Whether this activity is a designated service under the AML/CTF Act — compliance page, KYC clauses
- Privacy officer and complaints address — required by APP 1.4
- MongoDB Atlas and Railway regions — the APP 8 cross-border disclosure
None of these is hard to answer. All of them stop publication. The rest — structure, routing, the category lists, the PCI posture statement, first drafts of the terms and the disclaimer — is a description of what we already do, and we are the authority on that.