1. Introduction & Scope
This Privacy Policy describes how PT Evora Vera Teknologi, a limited liability company (perseroan terbatas) incorporated under the laws of the Republic of Indonesia which owns and operates the Paymonei platform (“Paymonei”, “we”, “our”, or “us”), collects, uses, and protects personal data when you access or use the Paymonei platform and any associated websites, APIs, dashboards, or hosted services (collectively, the “Services”).
This is a single global policy. It applies wherever you access the Services from. We are incorporated in Indonesia, so Law No. 27 of 2022 on Personal Data Protection (UU PDP) applies to our processing as a baseline. Where the law of your own location gives you more, such as the EU or UK GDPR, that standard applies to you as well, and section 9 sets out the legal bases we rely on.
We are the data controller for the personal data described in this Policy. Personal data you process about your own customers through the platform is data for which you remain the controller and we act as your processor.
PT Evora Vera Teknologi is a technology company. It is not a bank, a financial services institution, a payment services provider licensed by Bank Indonesia, or a money remittance operator. Financial execution services are provided exclusively by our licensed Execution Partners on a separate contractual basis under their own regulatory frameworks.
This Policy applies to:
- Merchants: Businesses and their authorised representatives, and individuals acting in the course of a trade, business, craft, or profession, who create a Paymonei account to access our billing and workflow software. The Services are for business use and are not intended for an individual acting for personal, family, or household purposes.
- Transaction Participants: Individuals who complete a payment via a merchant’s hosted checkout link or payment page powered by Paymonei software. Data relating to these individuals is processed on behalf of the merchant.
- Visitors: Anyone browsing paymonei.com or our subdomains.
By using the Services, you confirm that you have read and understood this Policy. If you are accessing the Services on behalf of an organisation, you represent and warrant that you have authority to accept this Policy on that entity’s behalf.
This Policy is published in two languages. The Indonesian text is available at paymonei.com/legal/privacy-policy/indonesia. For data subjects in Indonesia, the Indonesian text governs, consistent with the notice obligation under UU PDP.
This Policy also covers our use of cookies and analytics, in section 5. It replaces the separate Cookie Policy that previously sat at /legal/cookie-policy.
2. Information We Collect
2.1 From Merchants
When a business registers, configures, or operates a Paymonei account, we collect:
- Account credentials: Name, business email address, password hash.
- Business profile data: Legal entity name, business registration number, registration country, registered address, nature of business, and industry type, used to configure your billing software and determine applicable features.
- Authorized representative details: Full name, role or title, and contact information of the individual registering or administering the account on behalf of the business.
- Director and beneficial owner information: Names and roles of company directors provided during account onboarding, used for platform access verification purposes as described in section 2.2 below.
- API integration data: API keys, webhook URLs, and integration event logs so that your systems can connect to our software engine.
- Dashboard usage analytics: Feature interactions, session duration, and click paths, used to improve the software product.
- Support communications: Any information you voluntarily share when contacting our support team.
2.2 Business Verification Data
To protect the integrity of our software platform and prevent misuse, we conduct identity verification on authorized representatives and directors of merchant businesses prior to enabling platform access.
As part of this process, we share the identification information you provide with our third-party verification partners, for identity verification of directors and authorized representatives.
These providers perform identity document verification and biometric liveness checks on our behalf under their own data processing terms. Biometric processing (facial comparison, liveness detection) is executed on the verification partner’s infrastructure. We retain the submitted identity information and verification records, including verification reference identifiers and, where required to satisfy regulatory audit trail obligations, copies of submitted identity documents, for the duration of the merchant relationship and for a minimum of five (5) years thereafter, in order to respond to requests from regulatory authorities, banking partners, or licensed financial execution partners.
Paymonei operates technology-layer risk controls, including transaction velocity monitoring, device and IP risk scoring, and suspicious activity pattern detection, to protect the integrity of our software platform. These controls work in concert with the regulated Anti-Money Laundering (AML), Counter-Terrorism Financing (CFT), sanctions screening, and statutory transaction monitoring obligations fulfilled by our licensed financial execution partners under their respective regulatory frameworks.
2.3 From Transaction Participants
When a transaction participant accesses a Paymonei-hosted checkout link or payment page generated by a merchant, we collect the minimum data needed to render and track the software workflow:
- Contact metadata: Name, email address, and shipping address, used to generate invoice records and confirmation emails on behalf of the merchant.
- Device and network context: IP address, browser type, operating system, referrer URL, forwarded (encrypted) to our licensed execution partners for fraud-scoring purposes.
- Session token: An encrypted, temporary identifier used solely to maintain checkout session state. It contains no financial credentials.
All payment instrument data is collected and processed entirely within the secure, regulated environments of our licensed financial execution partners. Paymonei’s software initiates and monitors payment workflow state only. We do not receive, process, or retain any payment instrument credential at any point in the transaction flow. Our partners’ payment collection environments are independently certified, regulated, and audited under their respective financial licences.
2.4 Automatically Collected Technical Data
- Server logs: Timestamped records of API requests, response codes, and event metadata for system reliability and debugging.
- Performance metrics: Latency, uptime, and error rates collected by our infrastructure monitoring tools.
- Website analytics and advertising measurement: Pages viewed, navigation paths, and interactions with our marketing site, collected through the cookies and tags described in section 5.
3. How We Use Your Information
We process personal data only for the following specific, lawful purposes. Where the GDPR applies, the right-hand column is the Article 6 basis we rely on; section 9 explains each one.
| Purpose | Lawful Basis |
|---|---|
| Registering and provisioning a merchant business account and enabling access to our software | Performance of contract (with merchant) |
| Verifying the identity of authorized business representatives during merchant onboarding | Legitimate interest (platform integrity and fraud prevention) |
| Generating invoice PDFs and tracking billing workflow status on behalf of merchants | Performance of contract (with merchant) |
| Powering the merchant’s analytics dashboard and reporting tools | Legitimate interest (product delivery) |
| Sending automated dunning, reminder, and receipt notifications on behalf of merchants | Performance of contract |
| Operating technology-layer risk controls (velocity monitoring, device scoring, suspicious pattern detection) to protect platform integrity | Legitimate interest (fraud prevention and platform security) |
| Forwarding device context (IP, user agent) to licensed execution partners for transaction fraud scoring | Legitimate interest (fraud prevention) |
| Retaining identity verification records and merchant onboarding data for regulatory audit trail purposes | Legal obligation / Legitimate interest (regulatory readiness) |
| Improving software features and fixing bugs through usage analytics | Legitimate interest (product improvement) |
| Measuring how our marketing site performs, and measuring and optimising our advertising, through the cookies and tags in section 5 | Consent, where required by applicable law |
| Communicating product updates, security notices, and support responses | Performance of contract / Legitimate interest |
| Complying with a court order, regulatory demand, banking partner inquiry, or applicable law | Legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate interest (legal protection) |
We do not use personal data for automated decision-making that produces legal or similarly significant effects without human review. We do not sell personal data.
6. Security & Retention
6.1 Security Measures
We apply industry-standard technical and organisational security controls to protect personal data from unauthorised access, disclosure, alteration, or destruction:
- All data in transit is encrypted using TLS 1.2 or higher.
- Data at rest is encrypted using AES-256.
- Access to production systems is restricted by role-based access control and multi-factor authentication.
- We conduct periodic security reviews and code audits.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for telling us promptly if you believe your account has been used without your authorisation.
Our security controls protect software data and instructions. The financial funds themselves are secured and insured by our licensed execution partners under their own regulatory requirements.
6.2 Retention Periods
| Data Category | Retention Period |
|---|---|
| Merchant account data | Duration of account + 5 years after closure |
| Director and business profile data | Duration of account + 5 years after closure (consistent with merchant account data for regulatory audit readiness) |
| Identity verification records (including submitted identity documents and verification outcomes) | Minimum 5 years after the merchant relationship ends, to support regulatory authority requests, banking partner inquiries, or legal proceedings, as stated in section 2.2 |
| Invoice and billing records | 7 years (driven by corporate tax requirements) |
| Transaction participant session data | 90 days from checkout event |
| Server log data | 30 to 90 days |
| Support communications | 3 years from last contact |
| Cookies and analytics data | As set out in section 5, by cookie |
When retention periods expire, data is securely deleted or anonymised. We do not retain personal data for longer than necessary solely on the basis of potential future litigation.
7. International Data Transfers
We operate globally. Your personal data may be processed and stored in Indonesia, where we are incorporated, and in other countries where we or the service providers named in section 4 operate, whose data protection laws may differ from those where you live. We will tell you which countries are involved in a specific case on request.
We apply regional data storage so that personal data is held close to the people it relates to and in line with applicable local data localisation requirements. Cross-region transfers happen only where technically necessary for reliability and redundancy, or where a service provider named in section 4 operates from another region. All such transfers are encrypted in transit using TLS 1.2 or higher.
Where we transfer personal data across a border, we put in place the safeguards applicable law requires. For transfers out of the EEA or the UK that includes Standard Contractual Clauses. For transfers out of Indonesia we rely on the mechanisms permitted under Law No. 27 of 2022, which are an adequate level of protection in the destination country, appropriate safeguards where it is not, or your consent.
You can ask us for details of the safeguards applied to a specific transfer by writing to [email protected].
8. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding personal data we hold about you:
- Right to access: Request a copy of the personal data we hold about you.
- Right to correction: Request that inaccurate or incomplete data be corrected.
- Right to deletion (“right to be forgotten”): Request deletion of your data, subject to our legal retention obligations. Data relating to transaction participants is held on behalf of the merchant, so deletion requests for such data may require coordination with the relevant merchant.
- Right to restrict processing: Request that we limit how we use your data in specific circumstances.
- Right to data portability: Receive a structured, machine-readable copy of data you have provided to us.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing. For cookies and analytics this is the Cookie Preferences control described in section 5.4.
Indonesia (UU PDP)
You may exercise rights in accordance with Law No. 27 of 2022 on Personal Data Protection.
EEA and UK (GDPR/UK GDPR)
If you access our services from the EEA or the UK, we process your data under the GDPR or UK GDPR and you have all rights listed above plus the right to lodge a complaint with your national supervisory authority.
To exercise any of these rights, email [email protected]. We will respond within 30 days, or within one calendar month for requests under the GDPR or UK GDPR, which may be extended where the law permits. We may need to verify your identity before acting on a request, and we will not treat you differently for exercising a right.
9. Legal Bases for Processing (GDPR)
Where the EU or UK GDPR applies, we process personal data only where we have a valid legal basis. Section 3 states which basis applies to each purpose. The bases themselves are:
- Contract: to provide the Services a merchant has signed up for and to perform our agreement with them.
- Legitimate interests: to secure, support, analyse and improve the Services, to prevent fraud and abuse, and to operate our business, where those interests are not overridden by your rights and freedoms. You can object to processing on this basis under section 8.
- Consent: where we ask for it. In practice this is the analytics and advertising cookies in section 5.3 and marketing email. You can withdraw it at any time, and withdrawing it is as easy as giving it.
- Legal obligation: to comply with applicable law and lawful requests from authorities.
Where UU PDP applies, the equivalent bases under Article 20 of Law No. 27 of 2022 are the ones we rely on, and they map to the four above.
10. Children's Privacy
The Services are not directed to children. We do not knowingly collect personal data from anyone under 18, or under the minimum age of digital consent in your jurisdiction if that is higher, and an individual registering as a Merchant must be of full age and legal capacity.
If you believe a child has provided us with personal data, write to [email protected] and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or business operations. Where changes are material, we will give at least 14 days’ advance notice by email to registered merchants and by a prominent notice on our website before the revised Policy takes effect. The effective date at the top of this page is the date of the most recent revision.
If a change adds a cookie category or materially changes how an existing one is used, we will ask for your consent again before the new use starts, as described in section 5.5.
Continuing to use the Services after a revised Policy takes effect means you accept it. If you do not agree with a revision, stop using the Services before the effective date and tell us at [email protected].
12. Contact
For any question, concern, or request relating to this Privacy Policy or our data practices, contact our privacy team. Requests to exercise a right under section 8 should go to the first address below.
This Policy is published by PT Evora Vera Teknologi, a limited liability company incorporated under the laws of the Republic of Indonesia, which owns and operates the Paymonei platform and is the data controller for the processing described here. See also our Terms of Service.