The legal pages your SaaS needs before applying for payments
Updated August 2026 · practical guidance, not legal advice
When a payment platform reviews your site, missing legal pages are one of the fastest ways to fail — not because reviewers read every clause, but because their absence is a signal: businesses that intend to stick around have them, and businesses that intend to disappear don't. Most indie landing pages don't have them. Adding three pages took the product behind our rejection teardown an afternoon and was one of the four changes that got it approved.
Terms of service
The minimum a reviewer expects to find:
- Who is selling — your business or personal trading name, matching what you put in the payment application.
- What is being sold — the product, the plan(s), and what "use" means.
- Acceptable use — what customers may not do with the product. For anything touching email or messaging, this is where you state the anti-spam position explicitly.
- Termination and liability — plain-language versions are fine.
Privacy policy
- What you collect (account email, analytics, payment metadata) and why.
- Who processes it for you — name your actual subprocessors (hosting, email provider, analytics, the payment platform itself).
- Retention and deletion — what happens when a user asks to be removed.
- If you serve EU users, the GDPR basics: legal basis, data rights, a contact for requests. Templates abound; accuracy about what you actually collect matters more than legal ornamentation.
Refund policy
The page reviewers care about most, because refunds are the alternative to chargebacks — and chargebacks hit their account when they're your merchant of record.
- A concrete window and rule: "14 days, no questions asked" beats three paragraphs of conditions.
- How to request one — an email address that works.
- Consistency: the policy must match what your terms and your checkout page say. Contradictions between pages read as bait-and-switch.
Check your own copy in 30 seconds. The free Audeza scanner flags the phrases payment platforms treat as risk signals — and suggests safer wording. No signup.
Run the free checkThe mistakes that read as red flags
- Template artifacts: "[Company Name]" placeholders, a different company's name left in, US-state law clauses on an EU business. Reviewers see hundreds of these; unedited templates signal carelessness.
- Orphan pages: legal pages that exist but aren't linked from the footer. If the reviewer can't find them, they don't exist.
- Mismatch with the product: terms describing a mobile app when you sell a web API, or a refund policy for physical goods.
- No contact route: every page should lead to a real email on your own domain.
Legal pages are one item on the reviewer's list — the copy itself is the bigger one. See the vocabulary guide and the full pre-application checklist.