The short version
MATCH (Member Alert to Control High-risk Merchants) is Mastercard's database of merchants terminated by an acquiring bank. It lists your business name, tax ID, URL, and the personal names and SSNs of the principals - so opening a new LLC does not get around it. Entries stay for 5 years from the listing date. Only the acquirer that listed you can remove you early, and they almost never do.
The workable answer for a peptide merchant is not fighting the list - it's moving to payment rails MATCH doesn't govern: ACH, crypto, and P2P. More on that below.
What MATCH is and who can actually see it
MATCH is a database Mastercard operates for the acquiring side of the card industry. Its older name - the Terminated Merchant File, or TMF - still gets used interchangeably, and you'll hear underwriters say "TMF'd" to mean listed. When an acquiring bank or its processor terminates a merchant account for cause, card network rules require them to add the merchant to MATCH within days of the termination decision.
Who sees it matters more than what it says. MATCH is not public. You cannot look yourself up. Consumers can't see it, competitors can't see it, and Google can't index it. The only parties with query access are acquiring banks, their processors, and payment facilitators - which is exactly the audience you least want reading it, because every one of them checks it during underwriting. When you apply for a peptide merchant account, a MATCH inquiry runs against your business name, tax ID, address, URL, and each principal's name and SSN before a human ever reads your application.
One scoping note: MATCH is a card-network mechanism. It governs Visa and Mastercard acquiring (Visa contributes to and queries the same file under its own rules). It does not govern ACH, bank wires, cryptocurrency, or P2P transfers - a fact that turns out to be the entire survival strategy for a listed peptide merchant.
The reason codes that hit peptide merchants
Every MATCH entry carries a numbered reason code, and the code shapes how future underwriters read you. The full set runs from 01 to 14; three account for nearly every peptide listing we've seen:
| Code | Name | Why peptide merchants get it |
|---|---|---|
| 10 | Violation of Standards | The catch-all for prohibited business type. Selling research peptides on a card account underwritten as "supplements" or "lab supplies" is a standards violation the moment the acquirer notices. This is the most common peptide code by a wide margin. |
| 04 | Excessive Chargebacks | Crossing the network monitoring thresholds - roughly 1.5% chargeback-to-transaction ratio with 100+ chargebacks in a month puts you in Mastercard's ECM program, and termination usually follows. |
| 13 | Illegal Transactions | The acquirer concluded the sales themselves were unlawful. Rarer, but it appears when a compliance review decides the products were unapproved drugs being sold for human use. This is the code you least want, and the best argument for a storefront that reads clean. |
Code 10 deserves the extra paragraph because of how it usually happens. Almost no peptide store gets a card account by saying "research peptides" on the application - mainstream processors decline the category outright, which is why the aggregators keep shutting peptide stores down mid-flight. So owners describe the business as something adjacent, the account gets approved, volume runs for a few months, and then a periodic web review or a chargeback dispute puts a human on the website. The termination letter arrives, the reserve gets held 90-180 days, and the MATCH entry goes in - often without the word MATCH ever appearing in the letter. Misrepresenting the business on the application is precisely what code 10 exists to record.
How to find out if you're actually on it
Since you can't query MATCH yourself, you confirm it one of three ways, in order of directness:
- Ask the acquirer that terminated you. The processor that shut you down knows whether it filed a MATCH entry and under which code. Put the question in writing to their risk or compliance contact: "Was this merchant reported to MATCH, and under what reason code?" They are not obligated to answer, but many will, and a written answer is the single most useful document you can carry into any future application.
- Apply through a high-risk broker and ask for the decline reason. High-risk agents run MATCH checks early because a hit kills most placements. A broker who wants your business later will usually tell you "you're MATCH'd, code 10" straight - it costs them nothing and builds trust.
- Read the pattern. If every application dies at underwriting within days - not weeks - across multiple unrelated acquirers, and each decline is unexplained, you are almost certainly listed. Clean high-risk files get counteroffers and reserve demands; MATCH'd files get silence.
One warning: a small industry of "MATCH removal services" advertises to exactly the person reading this page. Most charge $1,500-$5,000 to send the same letter you could send yourself, to an acquirer with no obligation to act on it. Before paying anyone, understand what removal actually requires - which is the next section.
The 5-year clock and the rare removal paths
Entries purge automatically 5 years from the date the acquirer added them. Not from your termination date, not from your last transaction - from the filing date, which can trail the shutdown by days or weeks. After the purge, new MATCH inquiries stop returning the entry, and you underwrite as a fresh (still high-risk) applicant.
Early removal is real but narrow. Mastercard's own rules recognize essentially two paths:
- Listed in error. The acquirer added you when the facts didn't support the code - wrong entity, mistaken identity, or a termination that didn't actually meet the reporting standard. Only the listing acquirer can correct it; Mastercard will not remove an entry on a merchant's request, and no other bank can touch another bank's filing. If you have a genuine error case, put it to the acquirer in writing with documentation and ask them to file the correction.
- Code 12 (PCI non-compliance) after remediation. The one code with a defined cure: demonstrate PCI DSS compliance and the listing acquirer can remove it. Almost never the peptide scenario.
Notice what's not on the list: "I've cleaned up the site," "I've changed my business model," "it's been three years." None of those are removal grounds. For a code 10 or 13 entry that was accurately filed, the honest answer is that you wait out the clock. Anyone selling you a guaranteed removal for an accurate listing is selling you something.
Operating while listed: rails the card networks can't reach
Here's the part that matters operationally: MATCH only controls access to card acquiring. A listed merchant can still run a storefront at full capability on rails the card networks don't govern - and in this category, most of the healthy stores run on exactly these rails whether they're listed or not, because card processing for peptides is fragile even with a clean file.
- ACH / e-check. Bank-to-bank transfers underwritten by ACH processors and ODFIs, not card acquirers. MATCH status is generally not part of ACH underwriting. Settlement runs 1-3 business days; returns exist but there is no chargeback network and no equivalent of the ECM program.
- Cryptocurrency. A BTC/USDC option with a clear on-screen payment flow converts better than most owners expect for a research-supply audience, and no card network sits anywhere in the transaction.
- P2P rails - Zelle, Venmo, Cash App. Workable at real volume if you run them deliberately: dedicated business handles, payment instructions generated per-order, and automated matching of inbound payments to orders so nothing sits unconfirmed. The failure mode is manual reconciliation, not the rail itself. We wrote up the whole operating pattern in the P2P payments guide.
Two things make this setup durable rather than duct tape. First, the store itself has to be owned infrastructure - your domain, your code, your database - because a MATCH'd operator on a hosted platform is one policy sweep away from losing the storefront on top of the processing. Second, the manual rails need software doing the work cards used to do: order-coded payment references, automated payment confirmation, expiry windows that restore inventory when an order goes unpaid. That's a build problem, and it's a solved one. If you want to know how much of it your current site already gets wrong, the free 60-second audit reads your storefront the way a processor's risk analyst would and shows you on screen.
Coming back clean - what the next application has to look like
Whether you're waiting out the 5 years or applying through a high-risk acquirer that will consider a disclosed MATCH hit (a few will, at a price - expect 8-12% effective rates and a 10% rolling reserve), the next application succeeds or fails on the same file:
- Disclose the listing. Underwriters see it anyway. An application that discloses code, date, and circumstances reads as a merchant who learned; one that hides it reads as a repeat of the behavior that earned code 10.
- A site that survives a read-through. Research-use-only positioning enforced everywhere - no dosing content, no human-use language, no health claims, disclaimers and age-gating actually implemented rather than pasted in a footer. This is what the underwriter's web review looks for, and it's the piece you control completely.
- Clean chargeback math. Six-plus months of dispute ratios from your ACH and P2P history, documented. It's the strongest evidence that code 04 history (if that's your code) is behind you.
- Honest merchant category. The move that gets people listed is describing the business as something it isn't. The second application has to be accurate even though accuracy narrows the field - that's the trade.
None of this guarantees an approval. It changes the odds, and it means the store keeps earning on manual rails while the odds improve.
Questions, answered straight
Can I just open a new LLC and apply fresh?
No - and trying makes it worse. MATCH entries include the principals' personal names and SSNs, so the new entity matches on you, the person. Underwriters treat a fresh LLC over a listed principal as attempted evasion, which reads like the behavior behind code 10 and can burn the relationship with an acquirer that might otherwise have considered a disclosed application.
Does MATCH affect my personal credit?
No. MATCH is not a consumer credit bureau and never appears on a credit report. It affects exactly one thing: your ability to get card acquiring. Banking, lending, and every non-card payment rail are outside it.
Will Stripe or Square shutting me down put me on MATCH?
Sometimes, not always. Aggregators terminate huge volumes of accounts for policy reasons and only file MATCH entries when the facts meet a reporting code - a quiet "we can't support your business" closure often files nothing, while a termination citing prohibited products or misrepresentation often does. The only way to know is to ask them in writing. Either way the practical next step is the same: rails that don't run a MATCH check.
Can a lawyer get me off MATCH?
Only in the error case. A lawyer can pressure the listing acquirer to correct a factually wrong entry, and a demand letter sometimes moves a bank that ignored you. For an accurate code 10 or 13 entry there is no legal mechanism to compel removal - Mastercard's rules leave it to the listing acquirer's discretion, full stop. Spend the money on infrastructure instead.
Is Visa's list separate?
Visa participates in the same industry file for practical purposes - acquirers query one system during underwriting and both networks' rules require reporting terminated merchants. You should assume any card application, either network, sees the entry for the full 5 years.
This is general information for store operators, not legal advice. Nothing here is a guarantee of processor approval or MATCH removal.
STONEGATE SYSTEMS