Legal

Privacy Policy

Effective date: 8 July 2026Questions: [email protected]
On this page

1. Introduction & Scope

This Privacy Policy describes how PT Evora Vera Teknologi, a limited liability company (perseroan terbatas) incorporated under the laws of the Republic of Indonesia which owns and operates the Paymonei platform (“Paymonei”, “we”, “our”, or “us”), collects, uses, and protects personal data when you access or use the Paymonei platform and any associated websites, APIs, dashboards, or hosted services (collectively, the “Services”).

This is a single global policy. It applies wherever you access the Services from. We are incorporated in Indonesia, so Law No. 27 of 2022 on Personal Data Protection (UU PDP) applies to our processing as a baseline. Where the law of your own location gives you more, such as the EU or UK GDPR, that standard applies to you as well, and section 9 sets out the legal bases we rely on.

We are the data controller for the personal data described in this Policy. Personal data you process about your own customers through the platform is data for which you remain the controller and we act as your processor.

PT Evora Vera Teknologi is a technology company. It is not a bank, a financial services institution, a payment services provider licensed by Bank Indonesia, or a money remittance operator. Financial execution services are provided exclusively by our licensed Execution Partners on a separate contractual basis under their own regulatory frameworks.

This Policy applies to:

  • Merchants: Businesses and their authorised representatives, and individuals acting in the course of a trade, business, craft, or profession, who create a Paymonei account to access our billing and workflow software. The Services are for business use and are not intended for an individual acting for personal, family, or household purposes.
  • Transaction Participants: Individuals who complete a payment via a merchant’s hosted checkout link or payment page powered by Paymonei software. Data relating to these individuals is processed on behalf of the merchant.
  • Visitors: Anyone browsing paymonei.com or our subdomains.

By using the Services, you confirm that you have read and understood this Policy. If you are accessing the Services on behalf of an organisation, you represent and warrant that you have authority to accept this Policy on that entity’s behalf.

This Policy is published in two languages. The Indonesian text is available at paymonei.com/legal/privacy-policy/indonesia. For data subjects in Indonesia, the Indonesian text governs, consistent with the notice obligation under UU PDP.

This Policy also covers our use of cookies and analytics, in section 5. It replaces the separate Cookie Policy that previously sat at /legal/cookie-policy.

2. Information We Collect

2.1 From Merchants

When a business registers, configures, or operates a Paymonei account, we collect:

  • Account credentials: Name, business email address, password hash.
  • Business profile data: Legal entity name, business registration number, registration country, registered address, nature of business, and industry type, used to configure your billing software and determine applicable features.
  • Authorized representative details: Full name, role or title, and contact information of the individual registering or administering the account on behalf of the business.
  • Director and beneficial owner information: Names and roles of company directors provided during account onboarding, used for platform access verification purposes as described in section 2.2 below.
  • API integration data: API keys, webhook URLs, and integration event logs so that your systems can connect to our software engine.
  • Dashboard usage analytics: Feature interactions, session duration, and click paths, used to improve the software product.
  • Support communications: Any information you voluntarily share when contacting our support team.

2.2 Business Verification Data

To protect the integrity of our software platform and prevent misuse, we conduct identity verification on authorized representatives and directors of merchant businesses prior to enabling platform access.

As part of this process, we share the identification information you provide with our third-party verification partners, for identity verification of directors and authorized representatives.

These providers perform identity document verification and biometric liveness checks on our behalf under their own data processing terms. Biometric processing (facial comparison, liveness detection) is executed on the verification partner’s infrastructure. We retain the submitted identity information and verification records, including verification reference identifiers and, where required to satisfy regulatory audit trail obligations, copies of submitted identity documents, for the duration of the merchant relationship and for a minimum of five (5) years thereafter, in order to respond to requests from regulatory authorities, banking partners, or licensed financial execution partners.

Paymonei operates technology-layer risk controls, including transaction velocity monitoring, device and IP risk scoring, and suspicious activity pattern detection, to protect the integrity of our software platform. These controls work in concert with the regulated Anti-Money Laundering (AML), Counter-Terrorism Financing (CFT), sanctions screening, and statutory transaction monitoring obligations fulfilled by our licensed financial execution partners under their respective regulatory frameworks.

2.3 From Transaction Participants

When a transaction participant accesses a Paymonei-hosted checkout link or payment page generated by a merchant, we collect the minimum data needed to render and track the software workflow:

  • Contact metadata: Name, email address, and shipping address, used to generate invoice records and confirmation emails on behalf of the merchant.
  • Device and network context: IP address, browser type, operating system, referrer URL, forwarded (encrypted) to our licensed execution partners for fraud-scoring purposes.
  • Session token: An encrypted, temporary identifier used solely to maintain checkout session state. It contains no financial credentials.

All payment instrument data is collected and processed entirely within the secure, regulated environments of our licensed financial execution partners. Paymonei’s software initiates and monitors payment workflow state only. We do not receive, process, or retain any payment instrument credential at any point in the transaction flow. Our partners’ payment collection environments are independently certified, regulated, and audited under their respective financial licences.

2.4 Automatically Collected Technical Data

  • Server logs: Timestamped records of API requests, response codes, and event metadata for system reliability and debugging.
  • Performance metrics: Latency, uptime, and error rates collected by our infrastructure monitoring tools.
  • Website analytics and advertising measurement: Pages viewed, navigation paths, and interactions with our marketing site, collected through the cookies and tags described in section 5.

3. How We Use Your Information

We process personal data only for the following specific, lawful purposes. Where the GDPR applies, the right-hand column is the Article 6 basis we rely on; section 9 explains each one.

PurposeLawful Basis
Registering and provisioning a merchant business account and enabling access to our softwarePerformance of contract (with merchant)
Verifying the identity of authorized business representatives during merchant onboardingLegitimate interest (platform integrity and fraud prevention)
Generating invoice PDFs and tracking billing workflow status on behalf of merchantsPerformance of contract (with merchant)
Powering the merchant’s analytics dashboard and reporting toolsLegitimate interest (product delivery)
Sending automated dunning, reminder, and receipt notifications on behalf of merchantsPerformance of contract
Operating technology-layer risk controls (velocity monitoring, device scoring, suspicious pattern detection) to protect platform integrityLegitimate interest (fraud prevention and platform security)
Forwarding device context (IP, user agent) to licensed execution partners for transaction fraud scoringLegitimate interest (fraud prevention)
Retaining identity verification records and merchant onboarding data for regulatory audit trail purposesLegal obligation / Legitimate interest (regulatory readiness)
Improving software features and fixing bugs through usage analyticsLegitimate interest (product improvement)
Measuring how our marketing site performs, and measuring and optimising our advertising, through the cookies and tags in section 5Consent, where required by applicable law
Communicating product updates, security notices, and support responsesPerformance of contract / Legitimate interest
Complying with a court order, regulatory demand, banking partner inquiry, or applicable lawLegal obligation
Establishing, exercising, or defending legal claimsLegitimate interest (legal protection)

We do not use personal data for automated decision-making that produces legal or similarly significant effects without human review. We do not sell personal data.

4. How We Share Information

We do not sell, rent, or trade personal data. We share data only with the following categories of recipients, for the purposes stated:

RecipientPurpose
Licensed Financial Execution Partners
Payment institutions, banks, and regulated financial service providers
To route payment workflow instructions and enable transaction execution under their own regulatory licences.
Identity Verification PartnersTo verify the identity of business representatives during merchant onboarding for platform access control purposes.
Fraud Prevention & Risk Signal ProvidersTo share device and network context signals (IP address, user agent, device fingerprint) for fraud scoring, threat intelligence, and platform abuse prevention.
Cloud Infrastructure & Technology ProvidersTo host, operate, and maintain our software infrastructure.
Analytics and Advertising Providers
Google Analytics, Meta Pixel
To measure how our website and product are used, and to measure and optimise our advertising. Named in full, with what each collects, in section 5.
Affiliated Group EntitiesTo deliver technology development and platform management services as our authorized technology partner, under an intra-group data sharing agreement.
Legal & Governmental AuthoritiesWhere required by a court order, subpoena, governmental inquiry, regulatory demand, or applicable law. We notify affected merchants where legally permitted.
Prospective Buyers or AcquirersIn the event of a merger, acquisition, or asset sale, data may be disclosed to advisers and transferred to new owners. Merchants will be notified before data becomes subject to a different privacy policy.

All third-party providers we engage are required to apply data protection standards consistent with this Policy and are bound by appropriate data processing agreements.

4.1 Licensed Financial Execution Partners

When a merchant or transaction participant initiates a payment workflow through our software, we transmit the minimum necessary data (session context, device metadata, and invoice reference) to our licensed third-party financial institution partners who are independently regulated to provide payment execution and settlement services. These partners process payment credentials and fund movement under their own regulatory licences and privacy frameworks.

Paymonei operates technology-layer risk monitoring that works in concert with our licensed partners’ regulated AML/CFT obligations, sanctions screening, and statutory transaction monitoring. Both layers collectively maintain platform security and compliance integrity.

We contractually require all such partners to apply data protection standards no less protective than those described in this Policy.

4.2 Identity Verification Partners

We share authorized representative and director identity information with verification providers during merchant onboarding, for platform access control purposes. We share only the required information to complete verification. We retain the verification outcome and reference identifier.

4.3 Cloud Infrastructure & Service Providers

We use the following categories of third-party providers to operate our software infrastructure:

  • Cloud hosting
  • Database: Managed database providers
  • Monitoring & observability: Logging and error tracking tools
  • Email delivery: Transactional email providers (for invoice dispatch)

All providers are bound by data processing agreements and, where applicable, standard contractual clauses.

4.4 Analytics and Advertising Providers

Our marketing website loads Google Analytics 4 and the Meta Pixel. These are third parties that receive data about your visit and process it for their own purposes as well as ours. What they set, and how to switch them off, is in section 5.

4.5 Intra-Group Processing

Our affiliated entities operate within the same group. Data is shared between them solely to deliver and support the Paymonei software product. Both entities apply the data protection standards described in this Policy and are bound by a formal intra-group data sharing agreement.

4.6 Legal Disclosure

We may disclose personal data to competent authorities, courts, or regulators where we are required to do so by applicable law, a valid legal order, or where we have a good-faith belief that disclosure is necessary to prevent harm. We will notify affected users where legally permitted to do so.

4.7 Business Transfers

In the event of a merger, acquisition, or sale of substantially all assets, personal data may be transferred as part of that transaction. We will inform users via notice on our website or by email before data is transferred and becomes subject to a different privacy policy.

5. Cookies & Analytics

This section covers cookies and similar technologies across paymonei.com, the Paymonei merchant dashboard, and hosted payment pages powered by our software. It replaces the separate Cookie Policy that previously sat at /legal/cookie-policy; that address now redirects here.

5.1 What cookies are

Cookies are small text files placed on your device by a website when you visit it, letting the site remember information about your visit. We also use browser local storage and session storage, which work similarly. Everything in this section applies to those too.

  • Session cookies expire when you close your browser. Persistent cookies stay for a set duration.
  • First-party cookies are set by Paymonei. Third-party cookies are set by external services we load, which operate under their own privacy policies.

5.2 Strictly necessary

Required for the platform to function: authentication, session state, and security. These cannot be switched off without breaking the product, and no consent is required for them.

CookiePurposeSet byDuration
sessionMaintains your authenticated merchant sessionapp.paymonei.comSession
csrf_tokenPrevents unauthorised cross-site form submissionsapp.paymonei.comSession
pm_consentRecords your cookie choices so you are not asked again on every visitpaymonei.com12 months

The first two are set by the merchant dashboard at app.paymonei.com when you sign in there, not by this marketing website.

5.3 Analytics and advertising

We use two third-party services on paymonei.com, and we name them rather than describing them in the abstract:

  • Google Analytics 4, to understand how the site and product are used so we can improve them. Google processes this data as described in its own privacy policy.
  • Meta Pixel, to measure which of our advertising leads to signups, and to build audiences for advertising on Facebook and Instagram. This is cross-site advertising technology, and Meta processes the data for its own purposes as well as ours.

We also set one first-party cookie of our own for attribution, so that a signup can be credited to the campaign that produced it without appending tracking parameters to every link on the site.

CookiePurposeSet byDuration
_ga, _ga_<id>Distinguishes visitors and maintains session state for Google AnalyticsGoogleUp to 2 years
_fbpIdentifies a browser to Meta for advertising measurement and audience buildingMeta3 months
_fbcStores the click identifier from a Meta ad, so a later signup can be attributed to itMeta3 months
pm_attrOur own first-touch attribution record. Holds the campaign parameters the visit arrived with (utm_*, gclid, fbclid), the landing path, and the referrer. Written only once and only when an advertising parameter is present, so an organic visit leaves no cookie. Contains no name, address, or account data.paymonei.com90 days

5.4 Your choices

On your first visit we ask before setting anything in section 5.3. You can accept, decline, or open Choose what to allow and decide category by category. Declining takes exactly as much effort as accepting, and you can change that decision at any time through Cookie Preferences in the site footer. Declining has no effect on your ability to use the platform.

If your browser sends a Global Privacy Control signal, we read it and treat it as a rejection of everything in section 5.3, without asking you again.

You can also control cookies outside our site:

Blocking all cookies in your browser will prevent you from signing in to the merchant dashboard, because the session cookie in section 5.2 is required for it to work.

5.5 Retention and withdrawal

Your choice is recorded for 12 months, after which we ask again. We also ask again if we add a category or materially change how an existing one is used.

When you withdraw consent, we stop loading the services in section 5.3 and clear the cookies we can reach from our own domain. Cookies set on a third party’s domain have to be cleared through that party’s controls or your browser, which the links above cover.

6. Security & Retention

6.1 Security Measures

We apply industry-standard technical and organisational security controls to protect personal data from unauthorised access, disclosure, alteration, or destruction:

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256.
  • Access to production systems is restricted by role-based access control and multi-factor authentication.
  • We conduct periodic security reviews and code audits.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for telling us promptly if you believe your account has been used without your authorisation.

Our security controls protect software data and instructions. The financial funds themselves are secured and insured by our licensed execution partners under their own regulatory requirements.

6.2 Retention Periods

Data CategoryRetention Period
Merchant account dataDuration of account + 5 years after closure
Director and business profile dataDuration of account + 5 years after closure (consistent with merchant account data for regulatory audit readiness)
Identity verification records (including submitted identity documents and verification outcomes)Minimum 5 years after the merchant relationship ends, to support regulatory authority requests, banking partner inquiries, or legal proceedings, as stated in section 2.2
Invoice and billing records7 years (driven by corporate tax requirements)
Transaction participant session data90 days from checkout event
Server log data30 to 90 days
Support communications3 years from last contact
Cookies and analytics dataAs set out in section 5, by cookie

When retention periods expire, data is securely deleted or anonymised. We do not retain personal data for longer than necessary solely on the basis of potential future litigation.

7. International Data Transfers

We operate globally. Your personal data may be processed and stored in Indonesia, where we are incorporated, and in other countries where we or the service providers named in section 4 operate, whose data protection laws may differ from those where you live. We will tell you which countries are involved in a specific case on request.

We apply regional data storage so that personal data is held close to the people it relates to and in line with applicable local data localisation requirements. Cross-region transfers happen only where technically necessary for reliability and redundancy, or where a service provider named in section 4 operates from another region. All such transfers are encrypted in transit using TLS 1.2 or higher.

Where we transfer personal data across a border, we put in place the safeguards applicable law requires. For transfers out of the EEA or the UK that includes Standard Contractual Clauses. For transfers out of Indonesia we rely on the mechanisms permitted under Law No. 27 of 2022, which are an adequate level of protection in the destination country, appropriate safeguards where it is not, or your consent.

You can ask us for details of the safeguards applied to a specific transfer by writing to [email protected].

8. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding personal data we hold about you:

  • Right to access: Request a copy of the personal data we hold about you.
  • Right to correction: Request that inaccurate or incomplete data be corrected.
  • Right to deletion (“right to be forgotten”): Request deletion of your data, subject to our legal retention obligations. Data relating to transaction participants is held on behalf of the merchant, so deletion requests for such data may require coordination with the relevant merchant.
  • Right to restrict processing: Request that we limit how we use your data in specific circumstances.
  • Right to data portability: Receive a structured, machine-readable copy of data you have provided to us.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing. For cookies and analytics this is the Cookie Preferences control described in section 5.4.

Indonesia (UU PDP)

You may exercise rights in accordance with Law No. 27 of 2022 on Personal Data Protection.

EEA and UK (GDPR/UK GDPR)

If you access our services from the EEA or the UK, we process your data under the GDPR or UK GDPR and you have all rights listed above plus the right to lodge a complaint with your national supervisory authority.

To exercise any of these rights, email [email protected]. We will respond within 30 days, or within one calendar month for requests under the GDPR or UK GDPR, which may be extended where the law permits. We may need to verify your identity before acting on a request, and we will not treat you differently for exercising a right.

10. Children's Privacy

The Services are not directed to children. We do not knowingly collect personal data from anyone under 18, or under the minimum age of digital consent in your jurisdiction if that is higher, and an individual registering as a Merchant must be of full age and legal capacity.

If you believe a child has provided us with personal data, write to [email protected] and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or business operations. Where changes are material, we will give at least 14 days’ advance notice by email to registered merchants and by a prominent notice on our website before the revised Policy takes effect. The effective date at the top of this page is the date of the most recent revision.

If a change adds a cookie category or materially changes how an existing one is used, we will ask for your consent again before the new use starts, as described in section 5.5.

Continuing to use the Services after a revised Policy takes effect means you accept it. If you do not agree with a revision, stop using the Services before the effective date and tell us at [email protected].

12. Contact

For any question, concern, or request relating to this Privacy Policy or our data practices, contact our privacy team. Requests to exercise a right under section 8 should go to the first address below.

Privacy & cookie inquiries

Paymonei

[email protected]

Legal & data protection

Paymonei

[email protected]

This Policy is published by PT Evora Vera Teknologi, a limited liability company incorporated under the laws of the Republic of Indonesia, which owns and operates the Paymonei platform and is the data controller for the processing described here. See also our Terms of Service.