{
  "cells": {
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "American Express's current Additional Card page says a request requires the additional user's legal name, address, date of birth, and SSN or ITIN, with a telephone route when the user has neither identifier.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Additional Card Membership\",\"multi_record_provenance\":\"This cell is supported by 5 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"section\":\"What information will you need to provide about the Additional Card Member to request an Additional Card?\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You need the Additional Card Member’s legal name, address, date of birth, and Social Security Number (SSN) or International Tax Identification Number (ITIN) to request to add them to your account as an Additional Card Member. If the Additional Card Member does not have an SSN or ITIN, please call the number on the back of your Card.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "At an Additional Card request, American Express says it obtains, verifies, and records information about the additional user; the requester confirms the relationship, accuracy, and consent for identity verification.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Additional Card Membership\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":null,\"sections\":[\"Why do we need information about your Additional Card Member?\",\"Terms & Conditions\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "To help the United States government fight terrorism and money laundering, American Express obtains, verifies, and records information about Additional Card Members. Therefore, we will ask for your Additional Card Member’s name, address, date of birth, and other personal information.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "American Express states an event-based rule for covered Online Information rather than a fixed duration, with legal, regulatory, litigation, and investigation exceptions.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"American Express Online Privacy Statement\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: March 26, 2026\",\"section\":\"How do we keep and safeguard your information?\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We take reasonable steps to securely destroy or permanently de-identify Personal Information when we no longer need it. We will keep your Online Information only as long as we must to deliver our products and services, unless we are required by law or regulation or for litigation and regulatory investigations to keep it.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/us/company/privacy-center/online-privacy-disclosures/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The June 2026 Business Gold agreement defines the Basic Card Member, Company, and Additional/Employee Card Member roles, assigns account and charge responsibility, and states the approval boundary for replacing the Basic Card Member.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Business Gold Card Member Agreement\",\"multi_record_provenance\":\"This cell is supported by 4 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"part\":\"Part 2 of 3\",\"published_revision\":\"As of: 06/30/2026\",\"sections\":[\"Definitions\",\"Joint and Several Liability\",\"Additional Card Members\",\"Replacing the Basic Card Member\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "That means that both the Basic Card Member and the Company are each individually responsible for the Account, including but not limited to the obligation to pay all charges. We may seek payment from either or both the Basic Card Member and the Company.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/content/dam/amex/en-us/company/legal/cardmember-agreements/public-site-2026-q2-pdf-cmas/sbs-small-business/business-gold-06-30-2026.pdf",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-amex-membership-rewards.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The May 2026 Business Card Privacy Notice identifies everyday-business, service-provider marketing, business-partner, and co-brand sharing contexts and states the associated opt-out boundary.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"American Express Business Card Privacy Notice\",\"multi_record_provenance\":\"This cell is supported by 6 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective Date: May 1, 2026\",\"sections\":[\"How We May Share Your Information\",\"Choices Available to You\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "This Section describes how we may share information that identifies you or your business:",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-amex-membership-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.americanexpress.com/content/dam/amex/us/company/privacy-center/online-privacy-disclosures/Business_Card_Privacy_Notice_2026.05.01.pdf",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One Business's March 2026 application guide says a business-card application may typically call for the listed contact, entity, applicant, tax, operational, financial, and ownership/controller information.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"How to apply for and get a business credit card\",\"multi_record_provenance\":\"This cell is supported by 5 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"March 3, 2026\",\"section\":\"Step 3: Gather what you need to apply\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Typically, this may include some or all of the following: Contact information (business mailing address and phone number) Legal name of your business Your Social Security number (SSN) and legal name (if you’re a sole proprietor ) How long your business has been in operation Your role in the business Federal tax ID number (TIN) Industry type (the North American Industry Classification System [NAICS] code) Legal structure (corporation, partnership , nonprofit, LLC or cooperative) Annual revenue Total monthly expenses List of beneficial owners or business controllers (for corporations and partnerships)",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/learn-grow/business-resources/applying-for-business-credit-card/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One's May 2026 policy names application, login, account-access, and later online or phone interactions as identity or account-verification events.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Online Privacy Policy\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Effective May 5, 2026\",\"section\":\"How does Capital One use this information? — Verifying your identity\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verifying your identity , such as conducting identity verification when you apply for our products or services, authenticating your login credentials, verifying your location to allow access to your accounts, and storing security questions for subsequent verification online or over the phone.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One's May 2026 policy uses a reasonably-necessary criterion and lists service, compliance/audit, complaint/troubleshooting, and legal-claim factors; it publishes no fixed duration in this clause.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Online Privacy Policy\",\"published_revision\":\"Effective May 5, 2026\",\"section\":\"Data retention and security\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The personal information we collect will be retained for as long as reasonably necessary for the purposes set out in this Privacy Policy and consistent with our retention policies, in accordance with applicable laws.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One Business's September 2026 account-manager page distinguishes the account manager, authorized user, and primary account holder and states each role's controls or responsibility.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Business account managers: Delegate tasks\",\"multi_record_provenance\":\"This cell is supported by 3 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"September 17, 2026\",\"sections\":[\"What is a Capital One Business account manager?\",\"What other role types are available?\",\"FAQ\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "An account manager is one of two account user roles that small-business owners (SBOs) can assign to employees who have a Capital One Business employee card .",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/learn-grow/business-resources/capital-one-account-manager/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-capital-one-rewards.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Capital One's May 2026 policy lists seven recipient categories, their stated examples or purposes, aggregate/de-identified sharing, and the policy's U.S.-audience scope and non-Capital-One exclusions.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Capital One Online Privacy Policy\",\"published_revision\":\"Effective May 5, 2026\",\"sections\":[\"What this policy covers\",\"What this policy does not cover\",\"How does Capital One share this information?\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We share information in a variety of contexts. For example, we may share information about you with:",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-capital-one-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.identity.data_collected": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's business-card application guide lists business identity, address, structure, tax, revenue, operating-history, and employee-count fields used for most applications.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"How to Fill Out a Business Credit Card Application\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"section\":\"How to fill out a business credit card application\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Here are some details you’ll need for most business credit card applications: Business name : If you’re a sole proprietor without a formal business name, you may include your name as the company name. Business address : Legal business location (can be home address). Business type : This will usually be a sole proprietorship, LLC or corporation. Tax Identification Number : If you don't have an EIN, use your personal SSN (Social Security number). Annual business revenue : The amount of money your business makes per year. Years in business : How long your business has been operating. Number of employees : How many employees you have (if you're the only employee, you can write “one”).",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.data_collected",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/personal/credit-cards/education/basics/how-to-fill-out-business-credit-card-application",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.identity.verification_events": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's online privacy policy names access to account information as an example identity-verification event.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Chase Online Privacy Policy\",\"multi_record_provenance\":\"This cell is supported by 15 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Last updated September 2023\",\"section\":\"Use of Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verifying your identity (such as when you access your account information);",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "identity.verification_events",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.retention.rule": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's December 2025 California disclosure ties retention to an ongoing relationship or stated-purpose need, applicable limitation periods, legal retention requirements, and legal claims.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"California Consumer Privacy Act Disclosure and Notice at Collection\",\"published_revision\":\"Last updated December 2025\",\"section\":\"Retention of Personal Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We will retain copies of your personal information in a form that permits identification only for as long as: We maintain an ongoing relationship with you (e.g., while you are still receiving services from us); or Your personal information is necessary in connection with purposes set out in this disclosure plus: The duration of any applicable limitation period under applicable law; and where required by applicable law or a retention policy established in accordance with applicable law",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "retention.rule",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/digital/resources/privacy-security/privacy/ca-consumer-privacy-act",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.roles_and_responsibility": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The Ink Business Preferred Ultimate Rewards agreement distinguishes the responsible party from an authorized user and assigns the responsible party responsibility for points use.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Ink Business Preferred with Ultimate Rewards Program Agreement\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"sections\":[\"Important information about the program and this agreement\",\"How you can use your points\",\"Combine points with other Chase cards with Ultimate Rewards\",\"Transfer points to frequent travel programs\",\"Other important information you should know\"]}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "“you” and “your” mean the party or parties responsible",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "roles_and_responsibility",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/inkbusinesspreferred/rewardsagreement",
      "table": "grain"
    },
    "grain:m_points_program#vendor-us.issuer-chase-ultimate-rewards.sharing_or_linkage": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Chase's policy names service providers, affiliates, co-brand companies, corporate-transaction parties, and legal or protective recipients.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"Chase Online Privacy Policy\",\"multi_record_provenance\":\"This cell is supported by 2 accepted records; the row citation is the first record and every record citation is preserved in value_json.\",\"published_revision\":\"Last updated September 2023\",\"section\":\"Disclosure of Information\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We may share the information we collect from and about you with our affiliates and other third parties as described below. In particular, we may share your information with: Chase third-party service providers; Chase affiliated websites and businesses in an effort to bring you improved service across our family of products and services, when permissible under relevant laws and regulations; Other companies to bring you co-branded services, products or programs that you have requested; Third parties or affiliates in connection with a corporate transaction, such as a sale, consolidation or merger of Chase businesses; and Other third parties to comply with legal requirements such as the demands of applicable subpoenas and court orders; to verify or enforce our terms of use, our other rights, or other applicable policies; to address fraud, security or technical issues; to respond to an emergency; or otherwise to protect the rights, property or security of our customers or third parties.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "sharing_or_linkage",
        "grain": "m_points_program",
        "jurisdiction": "vendor-us",
        "row_key": "issuer-chase-ultimate-rewards"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": null,
      "source_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-bank-cip.rule.identity_elements": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The minimum identifying information is name, date of birth for an individual, address, and an identification number, subject to stated exceptions including a filed-but-not-yet-issued taxpayer identification number.",
      "fetch_event_id": null,
      "pinpoint": "31 CFR 1020.220(a)(2)(i)(A); eCFR current through 2026-10-01",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "( A ) In general. The CIP must contain procedures for opening an account that specify the identifying information that will be obtained from each customer. Except as permitted by paragraphs (a)(2)(i)(B) and (C) of this section, the bank must obtain, at a minimum, the following information from the customer prior to opening an account: ( 1 ) Name; ( 2 ) Date of birth, for an individual; ( 3 ) Address, which shall be: ( i ) For an individual, a residential or business street address; ( ii ) For an individual who does not have a residential or business street address, an Army Post Office (APO) or Fleet Post Office (FPO) box number, or the residential or business street address of next of kin or of another contact individual; or ( iii ) For a person other than an individual (such as a corporation, partnership, or trust), a principal place of business, local office, or other physical location; and ( 4 ) Identification number, which shall be: ( i ) For a U.S. person, a taxpayer identification number; or ( ii ) For a non-U.S. person, one or more of the following: A taxpayer identification number; passport number and country of issuance; alien identification card number; or number and country of issuance of any other government-issued document evidencing nationality or residence and bearing a photograph or similar safeguard. Note to paragraph ( a )(2)( i )(A)( 4 )( ii ): When opening an account for a foreign business or enterprise that does not have an identification number, the bank must request alternative government-issued documentation certifying the existence of the business or enterprise.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.identity_elements",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-bank-cip"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-bank-cip.rule.limitations": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "For a non-individual customer, authority or control-person information is a risk-based fallback used only when documentary and non-documentary methods cannot verify the customer's identity. Separately, the appropriate regulator and Secretary may exempt a bank or account type by order or regulation under the stated standard.",
      "fetch_event_id": null,
      "pinpoint": "31 CFR 1020.220(a)(2)(ii)(C); eCFR current through 2026-10-01",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "( C ) Additional verification for certain customers. The CIP must address situations where, based on the bank's risk assessment of a new account opened by a customer that is not an individual, the bank will obtain information about individuals with authority or control over such account, including signatories, in order to verify the customer's identity. This verification method applies only when the bank cannot verify the customer's true identity using the verification methods described in paragraphs (a)(2)(ii)(A) and (B) of this section.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.limitations",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-bank-cip"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-bank-cip.rule.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Identifying information is retained for five years after account closure, or for a credit-card account after closure or dormancy; document, method/result, and discrepancy records are retained for five years after creation.",
      "fetch_event_id": null,
      "pinpoint": "31 CFR 1020.220(a)(3)(ii); eCFR current through 2026-10-01",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "( ii ) Retention of records. The bank must retain the information in paragraph (a)(3)(i)(A) of this section for five years after the date the account is closed or, in the case of credit card accounts, five years after the account is closed or becomes dormant. The bank must retain the information in paragraphs (a)(3)(i)(B) , (C) , and (D) of this section for five years after the record is made.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.retention",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-bank-cip"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-bank-cip.rule.scope": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "A covered bank must maintain a written Customer Identification Program appropriate for its size and type of business as part of its anti-money-laundering program; owning a bank does not by itself subject a holding company to this bank CIP rule.",
      "fetch_event_id": null,
      "pinpoint": "31 CFR 1020.220(a)(1); eCFR current through 2026-10-01",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "( 1 ) In general. A bank required to have an anti-money laundering compliance program under the regulations implementing 31 U.S.C. 5318(h) , 12 U.S.C. 1818(s) , or 12 U.S.C. 1786(q)(1) must implement a written Customer Identification Program (CIP) appropriate for the bank's size and type of business that, at a minimum, includes each of the requirements of paragraphs (a)(1) through (5) of this section. The CIP must be a part of the anti-money laundering compliance program.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.scope",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-bank-cip"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-bank-cip.rule.verification": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The CIP uses risk-based documentary or non-documentary verification within a reasonable time after account opening; for a credit-card account, required identifying information may be acquired from a third-party source before credit is extended.",
      "fetch_event_id": null,
      "pinpoint": "31 CFR 1020.220(a)(2)(ii); eCFR current through 2026-10-01",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "( ii ) Customer verification. The CIP must contain procedures for verifying the identity of the customer, using information obtained in accordance with paragraph (a)(2)(i) of this section, within a reasonable time after the account is opened. The procedures must describe when the bank will use documents, non-documentary methods, or a combination of both methods as described in this paragraph (a)(2)(ii) .",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.verification",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-bank-cip"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-legal-entity-cdd.rule.identity_elements": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "For each in-scope beneficial owner, the rule requires name, date of birth, address, and Social Security number or another government identification number; beneficial owners comprise any 25-percent-or-more equity owners and one control person.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"CDD Rule Consolidated FAQs\",\"question\":\"B.7\",\"revision_date\":\"2026-05-06\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "As with CIP for individual customers, covered financial institutions must collect from the legal entity customer the name, date of birth, address, and social security number or other government identification number (passport number or other similar information in the case of foreign persons) for individuals who own 25% or more of the equity interest of the legal entity (if any), and an individual with significant responsibility to control/manage the legal entity.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.identity_elements",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-legal-entity-cdd"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.fincen.gov/system/files/2026-05/CDD-Rule-Consolidated-FAQs.pdf",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-legal-entity-cdd.rule.limitations": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "FIN-2026-R001 is optional and leaves the rule's account exemptions and other BSA/AML duties intact. The regulation itself exempts specified accounts, including qualifying point-of-sale commercial private-label credit up to $50,000.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"31 CFR 1010.230\",\"ecfr_current_through\":\"2026-10-01\",\"section\":\"1010.230(h)(1)(i)\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Covered financial institutions are exempt from the requirements to identify and verify the identity of the beneficial owner(s) set forth in paragraphs (a) and (b)(1) and (2) of this section only to the extent the financial institution opens an account for a legal entity customer that is: ( i ) At the point-of-sale to provide credit products, including commercial private label credit cards, solely for the purchase of retail goods and/or services at these retailers, up to a limit of $50,000;",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.limitations",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-legal-entity-cdd"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-legal-entity-cdd.rule.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "Identification records are retained for five years after account closure; verification records are retained for five years after the record is made. FIN-2026-R001 separately requires a record of any verbal or written confirmation used to rely on prior information.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"31 CFR 1010.230\",\"ecfr_current_through\":\"2026-10-01\",\"section\":\"1010.230(i)(2)\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "A covered financial institution must retain the records made under paragraph (i)(1)(i) of this section for five years after the date the account is closed, and the records made under paragraph (i)(1)(ii) of this section for five years after the record is made.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.retention",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-legal-entity-cdd"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-legal-entity-cdd.rule.scope": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "31 CFR 1010.230 applies to listed covered financial institutions and legal-entity customers, subject to the rule's customer exclusions and account exemptions; FIN-2026-R001 supplies discretionary relief from repeating beneficial-owner identification and verification at every later account opening.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"CDD Rule Consolidated FAQs\",\"question\":\"A.5\",\"revision_date\":\"2026-05-06\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "For purposes of the CDD Rule, covered financial institutions are federally regulated banks and\nfederally insured credit unions, mutual funds, brokers or dealers in securities, futures commission\n\n\n                                                    1\n\f                                 F I N C E N         G U I D A N C E\n\nmerchants, and introducing brokers in commodities.",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.scope",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-legal-entity-cdd"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.fincen.gov/system/files/2026-05/CDD-Rule-Consolidated-FAQs.pdf",
      "table": "grain"
    },
    "grain:m_points_rule#US-federal.rule-legal-entity-cdd.rule.verification": {
      "additional_sources": null,
      "capture_date": "2026-10-04",
      "claim_type": null,
      "display": "The base rule requires risk-based identity verification for each identified beneficial owner. Under FIN-2026-R001, repeat identification and verification may be limited to the first account, a reliability concern, or a risk-based ongoing-CDD need; confirmation of prior information is allowed only under the order's stated conditions.",
      "fetch_event_id": null,
      "pinpoint": "{\"document\":\"31 CFR 1010.230\",\"ecfr_current_through\":\"2026-10-01\",\"section\":\"1010.230(b)(2)\"}",
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verify the identity of each beneficial owner identified to the covered financial institution, according to risk-based procedures to the extent reasonable and practicable. At a minimum, these procedures must contain the elements required for verifying the identity of customers that are individuals under § 1020.220(a)(2) of this chapter (for banks); § 1023.220(a)(2) of this chapter (for brokers or dealers in securities); § 1024.220(a)(2) of this chapter (for mutual funds); or § 1026.220(a)(2) of this chapter (for futures commission merchants or introducing brokers in commodities); provided, that in the case of documentary verification, the financial institution may use photocopies or other reproductions of the documents listed in paragraph (a)(2)(ii)(A)( 1 ) of § 1020.220 of this chapter (for banks); § 1023.220 of this chapter (for brokers or dealers in securities); § 1024.220 of this chapter (for mutual funds); or § 1026.220 of this chapter (for futures commission merchants or introducing brokers in commodities).",
      "readiness": "ready",
      "reason_code": null,
      "ref": {
        "cell_key": "rule.verification",
        "grain": "m_points_rule",
        "jurisdiction": "US-federal",
        "row_key": "rule-legal-entity-cdd"
      },
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": null,
      "source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230",
      "table": "grain"
    },
    "privacy#US-federal.boi.boi.fields_collected": {
      "additional_sources": null,
      "capture_date": "2026-09-30",
      "claim_type": null,
      "display": "Initial reports collect reporting-company name, trade name, address, jurisdiction, TIN, and beneficial-owner/company-applicant identifying information.",
      "fetch_event_id": "aa9bb837-bae1-56c1-a199-82a74249bd28",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "An initial report of a reporting company shall include the following information:</P>\n<P>(i) For the reporting company:</P>\n<P>(A) The full legal name of the reporting company;</P>",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": "78b1b4c3e8e2849462811c8961fe3964f7e99adaefb9137a73a4ab7e8046f650",
      "source_url": "https://www.ecfr.gov/api/versioner/v1/full/2026-09-25/title-31.xml?part=1010&section=1010.380",
      "table": "privacy"
    },
    "privacy#US-federal.boi.boi.public_access": {
      "additional_sources": null,
      "capture_date": "2026-09-30",
      "claim_type": null,
      "display": "BOI reported to FinCEN is confidential except for authorized disclosures in 31 CFR 1010.955.",
      "fetch_event_id": "8a83f489-7c1f-574b-b15e-47e25e994b59",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Except as authorized in paragraphs (b), (c), and (d) of this section, information reported to FinCEN pursuant to § 1010.380 is confidential and shall not be disclosed",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": "c737c9a912e2f5a5ccc0fe5d10f3f2532d6522dbbb8d4ce3fe8e047a8c994f37",
      "source_url": "https://www.ecfr.gov/api/versioner/v1/full/2026-09-25/title-31.xml?part=1010&section=1010.955",
      "table": "privacy"
    },
    "privacy#US-federal.boi.boi.regime_status": {
      "additional_sources": null,
      "capture_date": "2026-09-30",
      "claim_type": null,
      "display": "Federal BOI rule effective for foreign reporting companies; U.S. companies and U.S. persons exempt under the 2026 final rule.",
      "fetch_event_id": "d5f620b8-41e8-548f-8ea1-1d20f5619f5e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The final rule became effective on August 14, 2026.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S1",
      "source_sha256": "eeff5f70c024e71cc8c396565d8d59a434609464944a7221708f529f6cd0fb63",
      "source_url": "https://www.fincen.gov/boi",
      "table": "privacy"
    }
  },
  "class": "USE-CASE",
  "content_file_sha256": "5efb74ef2b10cc01cfb845c1d371e7bb6da1c2011b7a110d2b6a50dd364fdd70",
  "figure_slots": [],
  "generator": "page-generator/1",
  "held": {
    "cells": [],
    "counts": {
      "gap": 0,
      "no_quote": 0,
      "unconfirmed": 0,
      "unresolved": 0
    },
    "is_held": false
  },
  "last_updated": "2026-10-04",
  "route": "/travel-mobility/business-card-kyc-and-public-records/",
  "schema": "pp-page-sources.v1",
  "tables": {
    "bank-cip-requirements": {
      "field_definitions": {
        "rule.identity_elements": "The identifying information the accepted federal rule record requires within its stated scope.",
        "rule.limitations": "The exemptions, non-individual-customer boundaries, and failure-to-verify conditions stated by the accepted federal rule record.",
        "rule.retention": "The record categories, periods, and event-based endpoints stated by the accepted federal rule record.",
        "rule.scope": "The covered institution, customer, account, and event boundaries stated by the accepted federal rule record.",
        "rule.verification": "The verification standard, timing, methods, and credit-card timing provision stated by the accepted federal rule record."
      },
      "last_updated": "2026-10-04",
      "matrix_id": "m_points_rule:bank-cip-requirements",
      "row_header": "Rule",
      "rows": [
        {
          "cells": {
            "rule.identity_elements": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
              "cell_locator": "US-federal.rule-bank-cip.rule.identity_elements",
              "publish_status": "publish_ready",
              "source_field": "rule.identity_elements",
              "value": "The minimum identifying information is name, date of birth for an individual, address, and an identification number, subject to stated exceptions including a filed-but-not-yet-issued taxpayer identification number."
            },
            "rule.limitations": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
              "cell_locator": "US-federal.rule-bank-cip.rule.limitations",
              "publish_status": "publish_ready",
              "source_field": "rule.limitations",
              "value": "For a non-individual customer, authority or control-person information is a risk-based fallback used only when documentary and non-documentary methods cannot verify the customer's identity. Separately, the appropriate regulator and Secretary may exempt a bank or account type by order or regulation under the stated standard."
            },
            "rule.retention": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
              "cell_locator": "US-federal.rule-bank-cip.rule.retention",
              "publish_status": "publish_ready",
              "source_field": "rule.retention",
              "value": "Identifying information is retained for five years after account closure, or for a credit-card account after closure or dormancy; document, method/result, and discrepancy records are retained for five years after creation."
            },
            "rule.scope": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
              "cell_locator": "US-federal.rule-bank-cip.rule.scope",
              "publish_status": "publish_ready",
              "source_field": "rule.scope",
              "value": "A covered bank must maintain a written Customer Identification Program appropriate for its size and type of business as part of its anti-money-laundering program; owning a bank does not by itself subject a holding company to this bank CIP rule."
            },
            "rule.verification": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
              "cell_locator": "US-federal.rule-bank-cip.rule.verification",
              "publish_status": "publish_ready",
              "source_field": "rule.verification",
              "value": "The CIP uses risk-based documentary or non-documentary verification within a reasonable time after account opening; for a credit-card account, required identifying information may be acquired from a third-party source before credit is extended."
            }
          },
          "jurisdiction": "US-federal",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220",
          "row_id": "rule-bank-cip",
          "state": "rule-bank-cip"
        }
      ],
      "scope_label": "1 rules"
    },
    "issuer-collection-and-verification-table": {
      "field_definitions": {
        "identity.data_collected": "Identity or account data the accepted issuer record states is collected within its named workflow, product, jurisdiction, and revision.",
        "identity.verification_events": "The documented event, requested information, method, actor, and scope in which the accepted issuer record states that verification occurs."
      },
      "last_updated": "2026-10-04",
      "matrix_id": "m_points_program:issuer-collection-and-verification-table",
      "row_header": "Program",
      "rows": [
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "American Express's current Additional Card page says a request requires the additional user's legal name, address, date of birth, and SSN or ITIN, with a telephone route when the user has neither identifier."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "At an Additional Card request, American Express says it obtains, verifies, and records information about the additional user; the requester confirms the relationship, accuracy, and consent for identity verification."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.americanexpress.com/en-us/benefits/additional-card/learn-more/",
          "row_id": "issuer-amex-membership-rewards",
          "state": "issuer-amex-membership-rewards"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.capitalone.com/learn-grow/business-resources/applying-for-business-credit-card/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "Capital One Business's March 2026 application guide says a business-card application may typically call for the listed contact, entity, applicant, tax, operational, financial, and ownership/controller information."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "Capital One's May 2026 policy names application, login, account-access, and later online or phone interactions as identity or account-verification events."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.capitalone.com/learn-grow/business-resources/applying-for-business-credit-card/",
          "row_id": "issuer-capital-one-rewards",
          "state": "issuer-capital-one-rewards"
        },
        {
          "cells": {
            "identity.data_collected": {
              "cell_citation_url": "https://www.chase.com/personal/credit-cards/education/basics/how-to-fill-out-business-credit-card-application",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.identity.data_collected",
              "publish_status": "publish_ready",
              "source_field": "identity.data_collected",
              "value": "Chase's business-card application guide lists business identity, address, structure, tax, revenue, operating-history, and employee-count fields used for most applications."
            },
            "identity.verification_events": {
              "cell_citation_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.identity.verification_events",
              "publish_status": "publish_ready",
              "source_field": "identity.verification_events",
              "value": "Chase's online privacy policy names access to account information as an example identity-verification event."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.chase.com/personal/credit-cards/education/basics/how-to-fill-out-business-credit-card-application",
          "row_id": "issuer-chase-ultimate-rewards",
          "state": "issuer-chase-ultimate-rewards"
        }
      ],
      "scope_label": "3 programs"
    },
    "issuer-retention-sharing-and-roles-table": {
      "field_definitions": {
        "retention.rule": "The duration or criterion, record category, trigger, exception, product, jurisdiction, and revision stated by the accepted issuer record.",
        "roles_and_responsibility": "The account role, control boundary, and stated contractual responsibility in the accepted issuer record.",
        "sharing_or_linkage": "The documented recipient, purpose, or linked context stated by the accepted issuer record without an inference that a transfer occurred."
      },
      "last_updated": "2026-10-04",
      "matrix_id": "m_points_program:issuer-retention-sharing-and-roles-table",
      "row_header": "Program",
      "rows": [
        {
          "cells": {
            "retention.rule": {
              "cell_citation_url": "https://www.americanexpress.com/us/company/privacy-center/online-privacy-disclosures/",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "American Express states an event-based rule for covered Online Information rather than a fixed duration, with legal, regulatory, litigation, and investigation exceptions."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.americanexpress.com/content/dam/amex/en-us/company/legal/cardmember-agreements/public-site-2026-q2-pdf-cmas/sbs-small-business/business-gold-06-30-2026.pdf",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "The June 2026 Business Gold agreement defines the Basic Card Member, Company, and Additional/Employee Card Member roles, assigns account and charge responsibility, and states the approval boundary for replacing the Basic Card Member."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.americanexpress.com/content/dam/amex/us/company/privacy-center/online-privacy-disclosures/Business_Card_Privacy_Notice_2026.05.01.pdf",
              "cell_locator": "vendor-us.issuer-amex-membership-rewards.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "The May 2026 Business Card Privacy Notice identifies everyday-business, service-provider marketing, business-partner, and co-brand sharing contexts and states the associated opt-out boundary."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.americanexpress.com/us/company/privacy-center/online-privacy-disclosures/",
          "row_id": "issuer-amex-membership-rewards",
          "state": "issuer-amex-membership-rewards"
        },
        {
          "cells": {
            "retention.rule": {
              "cell_citation_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "Capital One's May 2026 policy uses a reasonably-necessary criterion and lists service, compliance/audit, complaint/troubleshooting, and legal-claim factors; it publishes no fixed duration in this clause."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.capitalone.com/learn-grow/business-resources/capital-one-account-manager/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "Capital One Business's September 2026 account-manager page distinguishes the account manager, authorized user, and primary account holder and states each role's controls or responsibility."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
              "cell_locator": "vendor-us.issuer-capital-one-rewards.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "Capital One's May 2026 policy lists seven recipient categories, their stated examples or purposes, aggregate/de-identified sharing, and the policy's U.S.-audience scope and non-Capital-One exclusions."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.capitalone.com/privacy/online-privacy-policy/",
          "row_id": "issuer-capital-one-rewards",
          "state": "issuer-capital-one-rewards"
        },
        {
          "cells": {
            "retention.rule": {
              "cell_citation_url": "https://www.chase.com/digital/resources/privacy-security/privacy/ca-consumer-privacy-act",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.retention.rule",
              "publish_status": "publish_ready",
              "source_field": "retention.rule",
              "value": "Chase's December 2025 California disclosure ties retention to an ongoing relationship or stated-purpose need, applicable limitation periods, legal retention requirements, and legal claims."
            },
            "roles_and_responsibility": {
              "cell_citation_url": "https://www.chase.com/inkbusinesspreferred/rewardsagreement",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.roles_and_responsibility",
              "publish_status": "publish_ready",
              "source_field": "roles_and_responsibility",
              "value": "The Ink Business Preferred Ultimate Rewards agreement distinguishes the responsible party from an authorized user and assigns the responsible party responsibility for points use."
            },
            "sharing_or_linkage": {
              "cell_citation_url": "https://www.chase.com/digital/resources/privacy-security/privacy/online-privacy-policy",
              "cell_locator": "vendor-us.issuer-chase-ultimate-rewards.sharing_or_linkage",
              "publish_status": "publish_ready",
              "source_field": "sharing_or_linkage",
              "value": "Chase's policy names service providers, affiliates, co-brand companies, corporate-transaction parties, and legal or protective recipients."
            }
          },
          "jurisdiction": "vendor-us",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.chase.com/digital/resources/privacy-security/privacy/ca-consumer-privacy-act",
          "row_id": "issuer-chase-ultimate-rewards",
          "state": "issuer-chase-ultimate-rewards"
        }
      ],
      "scope_label": "3 programs"
    },
    "legal-entity-cdd-requirements": {
      "field_definitions": {
        "rule.identity_elements": "The ownership-prong, control-prong, and identifying fields stated by the accepted federal rule record.",
        "rule.limitations": "The relief, base-rule, exemption, and continuing-obligation boundaries stated by the accepted federal rule record.",
        "rule.retention": "The identification, verification, later-account, and confirmation-record periods stated by the accepted federal rule record.",
        "rule.scope": "The institution, customer, account-opening, exclusion, and exemption boundaries stated by the accepted federal rule record.",
        "rule.verification": "The verification mechanics and conditions for using previously obtained information stated by the accepted federal rule record."
      },
      "last_updated": "2026-10-04",
      "matrix_id": "m_points_rule:legal-entity-cdd-requirements",
      "row_header": "Rule",
      "rows": [
        {
          "cells": {
            "rule.identity_elements": {
              "cell_citation_url": "https://www.fincen.gov/system/files/2026-05/CDD-Rule-Consolidated-FAQs.pdf",
              "cell_locator": "US-federal.rule-legal-entity-cdd.rule.identity_elements",
              "publish_status": "publish_ready",
              "source_field": "rule.identity_elements",
              "value": "For each in-scope beneficial owner, the rule requires name, date of birth, address, and Social Security number or another government identification number; beneficial owners comprise any 25-percent-or-more equity owners and one control person."
            },
            "rule.limitations": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230",
              "cell_locator": "US-federal.rule-legal-entity-cdd.rule.limitations",
              "publish_status": "publish_ready",
              "source_field": "rule.limitations",
              "value": "FIN-2026-R001 is optional and leaves the rule's account exemptions and other BSA/AML duties intact. The regulation itself exempts specified accounts, including qualifying point-of-sale commercial private-label credit up to $50,000."
            },
            "rule.retention": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230",
              "cell_locator": "US-federal.rule-legal-entity-cdd.rule.retention",
              "publish_status": "publish_ready",
              "source_field": "rule.retention",
              "value": "Identification records are retained for five years after account closure; verification records are retained for five years after the record is made. FIN-2026-R001 separately requires a record of any verbal or written confirmation used to rely on prior information."
            },
            "rule.scope": {
              "cell_citation_url": "https://www.fincen.gov/system/files/2026-05/CDD-Rule-Consolidated-FAQs.pdf",
              "cell_locator": "US-federal.rule-legal-entity-cdd.rule.scope",
              "publish_status": "publish_ready",
              "source_field": "rule.scope",
              "value": "31 CFR 1010.230 applies to listed covered financial institutions and legal-entity customers, subject to the rule's customer exclusions and account exemptions; FIN-2026-R001 supplies discretionary relief from repeating beneficial-owner identification and verification at every later account opening."
            },
            "rule.verification": {
              "cell_citation_url": "https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230",
              "cell_locator": "US-federal.rule-legal-entity-cdd.rule.verification",
              "publish_status": "publish_ready",
              "source_field": "rule.verification",
              "value": "The base rule requires risk-based identity verification for each identified beneficial owner. Under FIN-2026-R001, repeat identification and verification may be limited to the first account, a reliability concern, or a risk-based ongoing-CDD need; confirmation of prior information is allowed only under the order's stated conditions."
            }
          },
          "jurisdiction": "US-federal",
          "last_checked": "2026-10-04",
          "official_source_url": "https://www.fincen.gov/system/files/2026-05/CDD-Rule-Consolidated-FAQs.pdf",
          "row_id": "rule-legal-entity-cdd",
          "state": "rule-legal-entity-cdd"
        }
      ],
      "scope_label": "1 rules"
    }
  },
  "template": "matrix",
  "tier": "T1",
  "warnings": []
}
