There’s a few ways you could do it, so just one way would be like:
You have the seed phrase for one of these configured wallets that have a minimum balance of Algo, and maybe even the tokens in there as well to avoid extra steps.
You encrypt each seed phrase with a fixed and very secret seed phrase using AES or fernet.
With this encrypted message, you can freely put it on a card or over email without worrying about anyone looking at it since it’s encrypted. Then when someone wants access to that wallet, they just feed this encrypted message to your app/website/program and it spits out the seed phrase for that wallet. You could also use any of the available SDKs to also present the wallet address.
If you wanted to rekey, they would just create some arbitrary wallet on any app and you can skip the presentation of the seed phrase and address for less friction and you would just send a one-time transaction on your end to rekey to their new wallet.
I’m not entirely sure if wallet apps will just recognize the rekey and display the new assets and Algorand balance even though they only have their initial wallet there or if it just allows the initial wallet to spend on the rekeyed wallets behalf—I don’t usually mess with rekeys often at all but if it’s the latter then you might just have to display the seed phrase to them to import.
I mean technically if someone knows they can just take that encrypted message to your website then it’s counterintuitive and you might as well just put the seed phrase on there. But you can take extra measures like the scratch-off and maybe a proof of retail purchase where the card activates first. Or only give them to people who do some bare minimum verification or KYC? Again, just ideas.