The card authorization wording your clients agree to
Where you write the sentence clients read and agree to before saving a card, see the exact block they see, and change it without touching Stripe.
Where the page lives
Settings > Billing & Pricing > Card Authorization, its own settings page. It works with or without Stripe connected, since the wording is written before you ever turn card capture on.
Authorization wording
The box where you write your own sentence. Leave it blank and the built-in wording is used, already written to cover what card networks expect and translated into each client's language. Type your own and it is shown exactly as typed, in every language, never translated or checked for you.
Billed-by identity line
The legal entity your clients are authorizing. It appears under the wording and is recorded with every authorization. Leave it blank and the line is left out; it is never guessed from your company name. This is the same setting as the one on the Stripe integration page.
Save
Saves the wording and the billed-by line together. Nothing reaches your clients until you click it; typing alone only updates the preview on this page.
What your client sees
The exact block your client sees above the card form in the client portal, not a copy of it. When the wording box is empty it renders the built-in default sentence; the statement line underneath is read live from your own Stripe account and cannot be edited here.
What the card networks expect this to say
The three things a saved-card disclosure needs to cover: that you may charge the card, how the amount is worked out, and how the client ends it. The built-in wording covers all three; writing your own means covering all three yourself, since your text is never checked.
After typing your own wording
The preview, now with your own wording
The same preview, now showing a typed sentence. The {company} token was swapped for the real company name and a Billed by line was added; everything else in the typed sentence renders exactly as typed. No Save was needed for the preview to update.
Why it works this way
A saved card's authorization is never rewritten after the fact: each authorization stores its own snapshot, the exact sentence the client read at the moment they read it, so changing the wording here never touches a card someone already saved. New wording only applies to the next person who saves a card. If a client is on the add-card page at the exact moment you save a change, their attempt is refused rather than recorded against a sentence they never saw. That refusal is a client-portal screen this settings page cannot picture, since seeing it needs a live Stripe-connected save: the client portal shows "The authorization wording changed while this page was open. Reload the page and read it again before saving a card."
The card number itself never touches this settings page or the client portal's own server code: the card form is Stripe's own hosted frame, so it goes straight from your client's browser to Stripe and nowhere else, and there is no field anywhere in the product for a raw card number, expiry or security code. What comes back to the portal instead is a reference to the card Stripe is holding, plus its network, last four digits, and expiry date, which is what the card list shows you. Because of that, Stripe itself validates the integration for the lighter SAQ A questionnaire path, so this feature does not put you in scope for a PCI questionnaire; taking card numbers by phone or on paper elsewhere in your business is a separate matter this page does not change.
Other ways to do this
Stripe integration page
Open Integrations > Stripe and edit the Billed-by identity line there instead.
Questions this page answers
What is this page for?
It holds the sentence your clients read and agree to before they save a card on file with you. That sentence is your authorization to keep the card and charge it, so it is yours to write - this is where you make it say what your business actually does. The preview below the box is the real block your client sees, not an approximation of it.
What happens if I leave the box empty?
Your clients read the built-in wording, which is what we recommend unless you have a reason not to. It already covers the three things card networks expect a saved-card disclosure to cover - that you may charge the card, how the amount is decided, and how the client ends it - and it is translated into each client’s own language automatically. Write your own and you take that on yourself: your text is shown exactly as typed, in every language, and is never checked or translated for you.
If I change the wording, what happens to clients who already saved a card?
Nothing changes for them, and nothing is rewritten behind them. Every authorization we record keeps a copy of the exact sentence that person read, so a card saved last year is still evidenced by last year’s words. New wording applies to the next person who saves a card. If someone is sitting on the card page at the moment you save a change, their attempt is refused with a note asking them to reload and read it again - better a second read than a record of consent to a sentence they never saw.
Where does the card number actually go?
Straight from your client’s browser to Stripe, and nowhere else. The card form is Stripe’s own hosted frame, so this portal never receives, processes or stores a card number, expiry or security code - there is no field for one anywhere in it. What comes back is a reference to the card Stripe is holding, plus its network, last four digits and expiry date, which is what the card list shows you. Those are not card data in the sense any of this is about.
Does this put me in scope for a PCI questionnaire?
Not for this. Because the card form is hosted by Stripe and the number never reaches this system, the integration is the kind Stripe validates for you: Stripe confirms SAQ A eligibility for its hosted integrations, so no questionnaire is expected of you on account of this feature. Your own obligations elsewhere are still yours - if you take card numbers over the phone or on paper anywhere else in your business, that is a separate matter and this page does not change it.
Was this helpful?