Business Credit Card Authorized Users and Account Roles
Business-card issuers do not describe one universal process for additional users. Their captured materials name different collection fields, verification events, retention criteria, sharing categories, and account roles, while Regulation Z supplies a narrower federal boundary for card issuance and unauthorized use.
Not legal advice. This page is research, not compliance guidance.
What does each issuer collect and verify when another user is added?
The three issuers publish role-specific fields for adding another user, but they do not describe one universal verification workflow: American Express ties an Additional Card request to a verification statement, while the Chase and Capital One verification records name application, account-access, login, or later-interaction events.
American Express's Additional Card material, captured October 4, 2026, says the request needs the additional user's legal name, address, date of birth, and Social Security number or ITIN, with a telephone route when the person has neither identifier. At that request, American Express says it obtains, verifies, and records information about the Additional Card Member. The material names the event and the requested fields, but it does not publish the matching source, algorithm, or pass-or-fail criteria used for verification.
Chase's employee-card guide, captured October 4, 2026, says a card request will typically ask for the employee's first name, last name, mailing address, date of birth, and Social Security number. Its separate business-card application guide lists business name, address, type, Tax Identification Number, annual revenue, years in business, and employee count for most applications. Chase's online privacy policy, last updated September 2023, separately names access to account information as an example of an identity-verification event. These records describe different workflows; they do not establish one procedure for every employee card or authorized user.
Capital One Business's employee-card page, captured October 4, 2026, names full name, date of birth, and phone number for adding an employee. Its account-manager article, published September 17, 2026, names personal and contact information, Social Security number, and date of birth when adding an account manager. Capital One's business-card application guide, dated March 3, 2026, separately says an application may typically include some or all listed contact, entity, applicant, tax, operational, financial, and ownership or controller information. Its online privacy policy, effective May 5, 2026, names application, login, account access, and later online or telephone interactions as identity or account-verification events. Those events should not be rewritten as one additional-card check.
Collection and verification therefore remain separate. A form field shows what an issuer says it requests for the named workflow. A verification statement shows the event at which the issuer says information is checked, confirmed, or authenticated. Neither record proves presence, travel, ownership, wrongdoing, or the method used for an unstated verification step.
- American Express: an Additional Card request names additional-user fields and a verification event, but not the matching method or decision criteria.
- Chase: the employee-card guide names qualified request fields, while the verification cell separately names account access; the records do not establish one procedure for every employee card.
- Capital One: the employee-card and account-manager records name role-specific fields, while the verification cell separately names application, login, account access, and later interactions.
What does each issuer retain, and for how long?
The captured issuer clauses use event- or purpose-based retention criteria rather than one shared fixed period, and the federal two-year compliance-record rule does not supply a universal duration for every business-card record.
American Express's Online Privacy Statement, effective March 26, 2026, says covered Online Information is kept only as long as needed to deliver products and services, subject to legal, regulatory, litigation, and regulatory-investigation reasons for keeping it longer. The clause also describes reasonable steps to destroy or permanently de-identify personal information when it is no longer needed. This is an event-based criterion for the information covered by that statement, not a fixed period and not a promise that every account, charge, application, or additional-user record follows the same lifecycle.
Chase's California disclosure, last updated December 2025 and captured October 4, 2026, ties retention to an ongoing relationship or the need to serve the purposes in the disclosure. It also names applicable limitation periods, retention required by law or a policy established under law, and legal claims. That scope is personal information within the California disclosure and its stated exclusions. The record does not establish one deletion date for every Chase business-card applicant, authorized user, transaction, or account.
Capital One's online privacy policy, effective May 5, 2026, says collected personal information is retained as long as reasonably necessary for the policy's purposes and consistently with its retention policies and applicable law. The cited policy record also names service, compliance or audit, complaint or troubleshooting, and legal-claim factors. It publishes no fixed duration in the captured clause, so the result is a criterion rather than a number.
Section 1026.25(a) of Regulation Z generally requires a creditor to retain evidence of compliance for two years after a required disclosure or action. The cited rule record also preserves the business-purpose boundary: sections 1026.12(a) and (b) are the narrow exceptions that apply regardless of card purpose, while other provisions do not become generally applicable to business-purpose cards on that basis. The two-year rule must therefore remain separate from the issuers' broader applicant, user, transaction, and account-record criteria; it cannot be used to assign every such record a two-year lifetime.
What role does each set of terms create?
The captured terms assign different contractual roles: American Express names the Basic Card Member, Company, and Additional or Employee Card Member; Chase distinguishes the responsible party from an authorized user; and Capital One distinguishes the primary account holder, account manager, and authorized user.
American Express's Business Gold Card Member Agreement dated June 30, 2026, assigns roles to the Basic Card Member, the Company, and Additional or Employee Card Members. The cited agreement record says the Basic Card Member and Company are each individually responsible for the account, including payment of charges, and it preserves the agreement's boundaries for charges, additional cards, and approval to replace the Basic Card Member. Those are allocations in the cited agreement; they are not a universal rule for every American Express product or a statutory-liability conclusion.
The Ink Business Preferred with Ultimate Rewards Program Agreement, whose PDF metadata was modified October 16, 2025, distinguishes the party responsible for that account from an authorized user and assigns the responsible party responsibility for points use. A separate Chase employee-card record addresses business responsibility. The labels should not be compressed into a statement that every authorized user is a joint obligor, guarantor, owner, or employee. These product-specific terms establish only the roles and controls they actually name.
Capital One's account-manager material, dated September 17, 2026, distinguishes three roles. It describes an account manager as one of the account-user roles a small-business owner can assign to an employee with a Capital One Business employee card, and the cited record separately preserves the controls or responsibility associated with account manager, authorized user, and primary account holder. An account manager's controls are not evidence that the person owns the business, guarantees the account, or has the same responsibility as the primary account holder.
Contractual responsibility and statutory liability answer different questions. An issuer agreement can allocate payment, account-management, card-use, or rewards-program responsibility among named roles. Regulation Z can set a condition or limit for unauthorized-use liability. Neither source should silently supply a role the other source does not name. This page therefore does not decide whether a particular employee, household member, client representative, account manager, or additional cardholder is liable for a charge.
How can account data be shared or linked?
The cited issuer policies name permitted recipient categories or linkage contexts, not a record that a particular person's information was transferred to any named recipient.
American Express's Business Card Privacy Notice, effective May 1, 2026, names everyday-business, service-provider marketing, business-partner, and co-brand sharing contexts and states an associated opt-out boundary. The record is limited to the vendor's stated business-card sharing surface. It does not show that information about a particular Basic Card Member, Company, employee, or additional user was disclosed in any specific instance.
Chase's online privacy policy names service providers, affiliates, companies offering requested co-branded services, corporate-transaction parties, and recipients connected to legal requirements, fraud, security, emergencies, or protection of rights and property. Those are policy-authorized categories and purposes. The list does not prove that a particular record moved, that a co-brand company received every category of information, or that an authorized user's account activity was joined to an outside profile.
Capital One's online privacy policy, effective May 5, 2026, lists recipient categories and purposes, aggregate or de-identified sharing, and boundaries for its United States audience and services not supplied by Capital One. The policy excludes co-branded partners' own services from its coverage. That boundary matters: a Capital One statement does not become a statement about another company's system merely because the two appear in the same customer journey.
Sharing, linkage, collection, verification, retention, public visibility, and legal access remain separate verbs. A policy can authorize a category of disclosure without documenting an actual transfer. A linked service can create an account relationship without proving presence, travel, ownership, wrongdoing, or access by the public.
What does Regulation Z establish—and what does it not?
The cited Regulation Z provisions address card issuance and unauthorized-use liability regardless of card purpose, but they do not make every consumer-credit rule apply to business-purpose cards or decide every contractual consequence for an additional user.
Section 1026.12(a) says its card-issuance restriction applies regardless of whether a card is intended for business, commercial, agricultural, or another purpose. The captured official interpretation also preserves the companion boundary: sections 1026.12(a) and (b) apply to business-purpose cards, but that exception does not bring the rest of Regulation Z into the business-purpose account. This page therefore does not use a consumer-credit provision outside that boundary as a universal business-card rule.
For unauthorized-use liability, one captured condition is that the issuer provide a means to identify the cardholder or authorized user. The cited rule record preserves signature, image, biometric, electronic, and mechanical examples. That condition is not a description of how American Express, Chase, or Capital One verifies an employee during an application or login. The issuer records and the federal condition describe different events and must remain separate.
When an issuer seeks to impose liability after a cardholder claims unauthorized use, the official interpretation says the issuer must conduct a reasonable investigation and may reasonably request the cardholder's cooperation. That is a claim-triggered investigation rule. It does not establish that every additional user was screened by a particular method when added, nor does it prove that a transaction was authorized, fraudulent, or attributable to a named person.
The captured limitations also preserve the general business-purpose exclusion, the narrow authorized-use exception, and a ten-card capacity boundary for a higher-liability agreement. Those rules do not decide the terms of every issuer agreement or the status of every Basic Card Member, Company, responsible party, employee, additional cardholder, account manager, authorized user, joint obligor, or guarantor. Any conclusion about a particular account requires the governing agreement and applicable law, not a role label taken from this comparison.
The source-bounded method used across the Travel and Mobility research hub keeps each statement with its provider or authority, product or provision, jurisdiction, effective or capture date, and stated limitation. It does not combine the three issuer systems into one account process or extend Regulation Z beyond the cited provisions.
Frequently asked questions
What information can an issuer request for an employee or additional cardholder?
The captured American Express Additional Card material names the additional user's legal name, address, date of birth, and Social Security number or ITIN. Chase's employee-card guide names first name, last name, mailing address, date of birth, and Social Security number. Capital One Business records separately name fields for adding an employee and for adding an account manager.
Does collecting an additional user's information mean the issuer verified it?
No. Collection identifies requested fields; verification requires a separately documented checking, confirmation, or authentication event. American Express names verification at an Additional Card request, while the captured Chase and Capital One records name other account or application events within their stated scope.
How long do business-card issuers say they retain user and account information?
The captured American Express, Chase, and Capital One clauses use need-, relationship-, purpose-, law-, or claim-based criteria rather than one shared fixed period. Each clause applies only to the information and jurisdictional scope named by its source.
Is an authorized user responsible for the business card account?
A role label alone does not answer that question. The captured issuer terms assign different controls and contractual responsibilities to Basic Card Members, companies, responsible parties, primary account holders, account managers, employees, and authorized users; they do not supply an individualized statutory-liability conclusion.
Does Regulation Z apply to unauthorized use of a business-purpose credit card?
The cited Regulation Z provisions for card issuance and unauthorized-use liability apply regardless of card purpose, while the captured official interpretation keeps other provisions outside that business-purpose exception. The rule does not decide every contractual or statutory consequence for a particular business-card account.