Web

Getting the merchant account approved before you commission the checkout

The store is finished. The design was approved, the products are loaded, the delivery integration works, and the invoice has been paid. And it cannot take a single dirham, because the payment application is still being reviewed and nobody started it until the build was done.

This is the most avoidable delay in UAE e-commerce and it happens constantly, because the approval runs on somebody else’s timetable, it can be refused outright, and some of what it requires has to be visible on the website itself. Start it first and the whole project shortens.

Two different things, applied for separately

The word gateway gets used for two things that are not the same. One is the technical service that carries a card transaction from your checkout onwards. The other is the arrangement under which a bank or licensed provider agrees to accept those transactions and settle money to you, which the Central Bank’s rulebook defines as merchant acquiring: contracting with a payee to accept and process payment transactions, resulting in a transfer of funds.

The first is a technology decision and can be changed. The second is an underwriting decision about your business, and it is the one that takes weeks and can come back as no. Everything below is about the second.

Four cards showing the merchant approval sequence: eligibility, documents, website requirements and settlement terms
Only the fourth card depends on your website being built.

Eligibility is checked before anything else

Every provider publishes a list of business types it will not accept and a second list it accepts only with extra scrutiny. These are specific rather than vague. Checkout.com’s own eligibility page prohibits categories including weapons, illicit substances, pornography and pyramid schemes, and restricts crypto, marketplaces, dropshipping and nutraceuticals. Stripe publishes a UAE-specific list that includes some genuinely surprising entries — domestic charter air travel, matchmaking services and private investigators among them.

Read the list for your intended provider before you do anything else, and read it honestly. The restricted categories are where projects stall: a marketplace that takes money on behalf of other sellers, or a subscription box, or anything shipped from a supplier you do not hold stock of, is not refused outright but is examined properly, and that examination takes time nobody budgeted.

If your model is in a restricted category, say so in the first conversation. Providers respond much better to a merchant who raises it than to one whose model becomes apparent in week three.

The documents, and who they belong to

The list is consistent across providers because it comes from the same regulatory obligations. Checkout.com states that UAE verification requires a trade licence and a tax registration document, plus the shareholder structure for anyone holding twenty-five per cent or more. PayTabs lists what activation needs in similar terms: identity documents, passport and visa, a trade licence matching the website’s line of business, the memorandum of association, and a bank certificate showing the account details.

Two details in that list cause most of the delays.

The trade licence has to match what the website sells. If your licence lists trading in building materials and your site sells cosmetics, the application stops there, and the fix is a licence amendment on a government timetable rather than a document you can produce.

And the shareholder documentation has to reach actual people. Where a company is owned by another company, expect to be asked for the layers above until a natural person appears. Companies with an offshore holding structure should assume this adds weeks and start collecting the paperwork now.

What the acquirer requires on the website itself

This is the part that surprises people, and it is the reason the sequence matters. The provider will not approve a site that does not display certain things, and several of them are unusual enough that no designer includes them by default.

Telr publishes its checklist plainly, and it requires among other things that the terms state the United Arab Emirates as the country of domicile, and that refunds be returned to the original payment method within a stated period. Alongside that, every provider expects the same core set: a refund and cancellation policy, a delivery policy with timescales, full contact details including a physical address, the currency shown at checkout, the accepted card marks, and terms and privacy pages that name your actual company.

None of that is difficult. All of it has to exist before the review, which means the content has to be written while the site is being built rather than after it launches.

The policy pages are also the item most often left to the developer, who reasonably copies something from another site. That is where a UAE application fails for a reason nobody expects: terms that name another company, or a jurisdiction that is not this one, or a returns window that contradicts what the delivery page says. Somebody at the provider reads these properly, which is more than most customers do.

The sequence that actually works

Read the provider’s prohibited and restricted lists, and confirm your model is acceptable. Check the trade licence matches the intended website. Open the corporate bank account, because a bank certificate is required and accounts take their own time. Submit the application with the documents, and ask specifically what the current review time is.

Then build, with the required pages written as part of the build rather than afterwards. Provide the site for review when it is complete enough to be assessed, which usually means a staging URL with real policy pages rather than placeholder text.

Run that in parallel with construction and the payment approval finishes at roughly the same time as the store. Run it afterwards and you have a finished shop and an empty account for several weeks. The platform choice sits alongside this rather than inside it, and is settled separately — that is the Shopify or WooCommerce question, decided by how UAE payments behave.

While you wait

Launch the site without card payments rather than holding it back. Take orders by bank transfer and cash on delivery, publish the catalogue, let the pages start being indexed, and use the period to find out whether anything about the store confuses real customers. That is far more useful than a finished site nobody has seen.

It also gives you something the approval itself benefits from: a live site with real policy pages, real products and a real address, which is a more convincing application than a staging link. Providers assess a business, and a business that is trading looks different from one that is waiting to.

And make sure enquiries during that period actually reach a person, because a store that cannot yet take payment is entirely dependent on the contact route working — which is exactly where enquiries get lost. If you are inheriting an existing store and cannot find out who holds the merchant agreement or the gateway credentials, that is a records problem and the first thing technical due diligence establishes. Building it properly the first time is what the web work is for.

Once the account is approved, my company builds the store around it rather than the other way round: WooCommerce stores at Tothiq.

Frequently asked questions

How long does approval actually take?

Ask the provider directly for their current figure rather than relying on a published range, because it moves with their volume and with your category. What is predictable is the shape: a straightforward company with matching documents in a permitted category is measured in days to a couple of weeks; a restricted category, a mismatched licence or a layered ownership structure turns it into a month or more. The variance is in your paperwork rather than in their speed.

Can we apply to more than one provider at once?

Yes, and for anything time-sensitive it is sensible. The document set is largely the same, so the extra effort is small, and the second application is insurance against a refusal you did not anticipate. It also gives you real pricing to compare rather than a published rate card. Be straightforward about it if asked; nobody is offended by a merchant taking two quotations.

We are a free zone company. Does that change anything?

It changes which providers will onboard you and occasionally what they ask for, rather than the process itself. Some acquirers prefer mainland entities for certain categories, and some free zone licences describe activities in wording that does not obviously match an online shop. Raise the entity type in the first conversation and let them tell you, because the answer varies by provider and by year and is not worth guessing.

What if we are refused?

Ask for the reason and treat it as information rather than a verdict. Refusals are often about a specific mismatch — a licence activity, a missing policy page, an unclear ownership chain — and are fixable. Where the refusal is about the business model itself, that is a genuine constraint and the honest response is to change the model or find a provider who serves that category, not to reapply with the same file.

Do we need this if we only sell to other businesses?

Only if you want to take card payments online. Plenty of business-to-business sellers in this market run entirely on invoices and bank transfer and never need an acquiring arrangement, which removes this whole timeline. The trade-off is a slower cash cycle and a manual reconciliation step. Decide it as a commercial question rather than assuming an online shop must take cards.

Have a project, problem or idea?

Let's discuss what you're trying to build, improve or grow — and whether I can help.

Discuss Your Project