Specify only the buyer controls your checkout documents
Specify a control only when the checkout you run documents what the buyer does and what the order stores. WooCommerce's advanced settings show two different presentations of the same terms page: a checkbox the buyer ticks on the shortcode checkout, and an agreement message with links on the block checkout. Its accounts settings describe guest checkout and account creation. Neither document describes an identity or age check, and neither says that accepting terms establishes who the buyer is or that a provider will process the account. Stripe's hosted Checkout custom-fields document allows up to three text, numeric, or dropdown fields and says not to collect sensitive data in them. You can match a control to the checkout that is live. The provider confirms its account requirements; separately assess the business’s buyer controls and applicable obligations. Support for a control remains unverified until current documentation or written vendor confirmation establishes the behavior for the installed version.
For: An owner or authorized representative of a business that sells peptides for laboratory research use only and needs to describe the buyer controls its checkout can actually run.
Updated 2026-09-21
A control is a documented behavior, not a label
Write the purpose in the words of the product document, then write the owner: your store, the checkout software, or the provider. A research-use acknowledgment means the buyer accepts text you supply. It does not become an identity check because you title the row that way. If the document does not say what happens when the buyer skips the control, that result is unknown. Do not fill it in.
This page does not measure whether a step is failing, and it does not decide whether a wallet button can be offered. It asks a narrower question: which controls does this checkout's current documentation say it can run?
The same terms page is not the same control on both WooCommerce checkouts
WooCommerce's advanced settings say you select a Terms and conditions page in page setup. On the checkout shortcode, the terms appear inline, the buyer can open them, and the buyer ticks a checkbox to accept. On the block checkout, the documented message is that by proceeding the buyer agrees to the terms and privacy policy, with links when those pages are set. You can edit that block message in the block editor. Those are two controls. Name the one installed on the store before you specify a checkbox.
The text of the terms page is yours. The checkout document describes how that page is presented. It does not say the presentation verifies a laboratory, a business, or any other buyer status. Prism's features page includes differences between pages and checkout among the policy items a review can look at, inside an agreed scope. The review is informational. It is not a certification that the control meets a provider's rule.
An account setting is not an identity check
WooCommerce's accounts and privacy settings include a choice to allow checkout without an account, and separate choices for creating an account during or after checkout. Guest orders are not tied to a WordPress user. That is an access setting. The document does not describe a check of the buyer's identity or age, and it does not say an account proves the buyer is purchasing for laboratory research.
Specify an identity or age control only when the product you use has current documentation that names the check, the party that operates it, and the result written to the order. If you cannot open that documentation, leave the row blank. Do not describe the terms checkbox or the guest-checkout setting as that product.
A hosted-checkout field collects an answer. It does not verify one
Stripe's hosted Checkout document on custom fields says you can add up to three fields. Text and numeric fields have character limits, a dropdown can offer up to 200 options, and fields are required unless you mark them optional. The collected values are available after payment. The same document says not to use custom fields for personal, protected, or sensitive data, or information restricted by law. It does not say a field verifies identity, age, or research use.
That document is for Stripe-hosted Checkout. Stripe also documents an embedded Checkout page and a Payment Element. Do not copy the three-field limit onto a checkout whose document you have not opened. A provider-requested statement belongs in this worksheet only when the provider's written request names it and the live checkout has a documented place to collect it.
What you can specify, and what no control here can decide
You can specify the live checkout, the control its documentation describes, who operates it, and the value the order stores. When the documentation you have read does not establish the desired behavior, mark it unverified and seek current documentation or written vendor confirmation. You cannot decide that the control makes the business eligible for processing. The provider decides whether it requires a statement and whether the store meets its rules.
Prism can discuss the website question in a consultation. Scope, fees, and terms are discussed before work. The contact form asks for the website, the products, and the question. It does not submit a processing application. Whether your block checkout still shows the default agreement sentence, and whether a provider will accept that sentence, are unknown until you look at the live page and the provider's request.
Buyer-control specification
Complete each row from the checkout that is live and from a document you opened. If current documentation or written vendor confirmation does not establish the control, write unverified. Do not rename a checkbox as an identity check. Worksheet entries are not submitted by this worksheet or saved by this site. Use only non-sensitive summaries; do not enter credentials, government identifiers, card or bank-account numbers, private receipt links, or customer details.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Buyer-control specification. The last column is for temporary notes.
Control
Behavior the current document describes
What that behavior does not establish
Where you confirm it
Your specification
Checkout that is live
Behavior the current document describesName the product and the presentation you run, such as WooCommerce shortcode checkout, WooCommerce block checkout, or Stripe-hosted Checkout. The terms control differs across the two WooCommerce presentations.
What that behavior does not establishA theme screenshot, by itself, does not identify which checkout product is active.
Where you confirm itThe admin screen or integration document that shows the live checkout.
Research-use or terms acceptance
Behavior the current document describesOn the WooCommerce shortcode, the buyer ticks a checkbox to accept the terms page you selected. On the block checkout, the documented text is an agreement message with links. Stripe-hosted Checkout can collect up to three custom fields.
What that behavior does not establishAcceptance of your text does not verify who the buyer is, and it is not a provider approval.
Where you confirm itThe exact control on the live checkout, or unverified until current documentation or written vendor confirmation establishes its behavior.
Account or guest access
Behavior the current document describesWooCommerce can allow checkout without an account, and it can offer account creation during or after checkout. Guest orders are not tied to a WordPress user.
What that behavior does not establishAn account setting is not an identity or age check, and it does not establish laboratory use.
Where you confirm itThe setting that is enabled, and where you read it.
Identity or age check
Behavior the current document describesSpecify this only when a current product document says the control checks identity or age and records a result. The WooCommerce terms and account documents opened for this page do not say that.
What that behavior does not establishA terms checkbox, an agreement message, or a custom text field is not that check.
Where you confirm itThe product document, the operator, and the stored result. Otherwise leave this blank.
Statement a provider required in writing
Behavior the current document describesUse the provider's request for the wording and the checkout document for the place it can be collected. A custom field on Stripe-hosted Checkout is limited to the field types and the three-field cap in that document.
What that behavior does not establishA statement you would like to show is not a provider requirement. A field is not evidence the provider accepted the business.
Where you confirm itThe request, the field, and the value the order stores.
Value saved with the order
Behavior the current document describesRecord only the field or order note the checkout document says is kept after acceptance or payment.
What that behavior does not establishA control that displays text but does not store a result cannot later prove the buyer accepted it.
Where you confirm itThe stored field name, or unknown.
These are temporary notes. Leaving or reloading this page may clear them. The consultation form does not include these entries.
Limits
A Prism consultation can help you organize the facts and discuss the website or processing question. The payment provider decides eligibility, pricing, reserves, and whether an account is opened or closed.
No control on this page establishes processing eligibility, buyer identity, or that a catalog is limited to laboratory research.
Do not send identity documents, card numbers, or customer records through the consultation form.
WooCommerce advanced settings — checked 2026-09-21. The shortcode checkout shows terms inline with a checkbox to accept. The block checkout shows an agreement message with links, which can be edited in the block editor.
WooCommerce accounts and privacy — checked 2026-09-21. Guest checkout can be enabled so buyers check out without an account. Account creation during or after checkout is a separate setting. Guest orders are not tied to a WordPress user.
Stripe hosted Checkout custom fields — checked 2026-09-21. Hosted Checkout custom fields are limited to three, support text, numeric, and dropdown types, are required unless marked optional, and Stripe says not to use them for sensitive data or information restricted by law.
Prism features — checked 2026-09-21. A website review can include store policies and differences between pages and checkout. Findings are informational and are not a legal opinion or a compliance certification.
Prism solutions — checked 2026-09-21. Prism can review public website content within an agreed scope or help with a provider's website questions. The provider decides whether the response meets its requirements.
Prism contact — checked 2026-09-21. The form asks for the website, the products, and the question. Follow-up is by email. The request does not submit a processing application.
Request a consultation
Describe the business and this specific question. Prism follows up by email to discuss fit and scope. An inquiry is not a processing application or an approval.