OnePay Privacy Policy
Effective date: 29 September 2026
1. Who we are and what this policy covers
OnePay is a payment platform run by Spemai (Private) Limited, a company incorporated in Sri Lanka (company registration number PV00206829), with its registered office at 3rd Floor, 292, Richmond House, Gamsabha Junction, High Level Road, Nugegoda, Sri Lanka. In this policy, “OnePay”, “we”, “us” and “our” mean Spemai (Private) Limited and the OnePay services it operates.
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what you can ask us to do with it. It covers the OnePay website, merchant portal, mobile app, checkout pages, payment links, APIs, plugins and SDKs, and OnePay Tap card terminals (together, the Services).
We process personal data in line with the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (the PDPA). As a participant in Sri Lanka’s payment system, we also follow the Central Bank of Sri Lanka’s Financial Consumer Protection Regulations and the security rules of the card networks.
For the personal data we collect to run OnePay, we are the controller. When a merchant uses OnePay to accept payments from its own customers, the merchant owns that customer relationship. We process those customers’ details to complete the payment on the merchant’s behalf, and to meet our own legal record keeping duties.
Please read this policy together with our Terms of Service and the Merchant Agreement that applies to you.
In short
- We never store full card numbers. Cards are entered on a secure, PCI DSS compliant payment page and we keep only a token and the last four digits.
- We collect what the law requires before a business can accept card payments, plus what we need to run the Services.
- We share data only with the banks, card networks and service providers that make payments work, and with regulators when the law requires it.
- We do not sell personal data.
- Records required by anti money laundering and tax law are kept for six years. Everything else is kept only as long as it is needed.
- You can ask to see, correct or erase your data, withdraw consent, object to a use and complain to the Data Protection Authority of Sri Lanka.
This summary helps you find your way around. The numbered sections are what apply.
2. Key terms
We use these terms in the same sense as the PDPA.
| Term | What it means here |
|---|---|
| Personal data | Any information that identifies you, directly or together with other information we hold. For example, your name, NIC number, phone number or IP address. |
| Special categories of personal data | Data the PDPA treats as more sensitive, such as financial data, biometric data and data on criminal offences. We process these only where Schedule II of the PDPA allows. |
| Processing | Anything we do with personal data: collecting, storing, using, sharing, transferring or deleting it. |
| Controller | The organisation that decides why and how personal data is processed. |
| Processor | An organisation that processes personal data on a controller’s instructions. |
| Data subject | The person the personal data is about. That may be you. |
| Merchant | A business or individual that uses OnePay to accept payments. |
| Customer | A person who pays a merchant through OnePay. |
| Data Protection Authority | The Data Protection Authority of Sri Lanka, set up under the PDPA. |
3. Whose data this policy covers
This policy applies to everyone whose personal data we handle:
- Applicants and merchants. Anyone who applies for, opens or runs a OnePay merchant account.
- People connected to a merchant. Owners, directors, partners, beneficial owners and authorised signatories named in an application. Also team members a merchant invites to its dashboard.
- Customers. Anyone who pays a merchant through a OnePay checkout, payment link, SMS Pay, saved card or OnePay Tap terminal.
- Developers. Anyone who integrates with our APIs, webhooks, plugins or SDKs.
- Visitors. Anyone who visits our websites or contacts us.
- Partners and suppliers. Contact people at banks, resellers, vendors and advisors we work with.
- Job applicants. People who apply to work with Spemai.
OnePay is built for businesses. If you give us personal data about someone else, such as a director or team member, please let them know and point them to this policy.
4. What we collect and how
From applicants and merchants
- Account details. Name, email address, mobile number (verified with a one time code), password (stored only as a one way hash) and language preference.
- Identity details. NIC or passport number, date of birth, role in the business and copies of identity documents.
- Business details. Business name, registration number and type, address, district, what you sell and how, website, expected monthly volume, average ticket size, and names and shareholdings of owners and directors.
- Settlement details. Bank, branch, account holder name, account number and Taxpayer Identification Number (TIN).
- Supporting documents. Business registration certificate, company forms, partnership deed, board resolution, proof of address, bank proof and any sector licence.
- OnePay Tap details. Terminal serial number, installation location and rental records.
- Activity records. Sign ins, settings changes, API keys issued, refunds and payouts, with the time, the user and the IP address.
From customers who pay a merchant
- Name, email address and phone number.
- Billing address, where the card network or bank requires it.
- Amount, currency, date, merchant reference and what the payment was for.
- Payment result, card scheme, last four digits, card expiry and a payment token.
- Device and network data used for fraud checks, such as IP address, browser and device type.
We do not store full card numbers, CVV codes or PINs. Cards are entered on a secure hosted payment page or a certified OnePay Tap terminal.
From visitors and developers
- Web server logs: IP address, pages requested, browser and device type.
- Cookie and analytics data, as explained in section 11.
- For developers: API key identifiers, webhook URLs and request logs.
- Anything you send us by email, WhatsApp, phone or contact forms.
From other sources
- Acquiring banks and card networks, for payment results, chargebacks and fraud alerts.
- Public registers such as the Registrar of Companies, and sanctions and watch lists, for verification.
- Credit and fraud prevention agencies, where the law allows.
5. Why we use your data and our lawful basis
The PDPA allows personal data to be processed only on a lawful basis set out in Schedule I. Here is what we do and why.
| Purpose | Lawful basis under the PDPA |
|---|---|
| Review an application and open a merchant account, including sharing it with our acquiring bank for approval | Steps you ask for before a contract; performance of the contract |
| Verify identity, ownership and bank details (KYC) and keep those records | Legal obligation under the Financial Transactions Reporting Act, No. 6 of 2006, and Central Bank of Sri Lanka directions |
| Screen against sanctions lists and report suspicious transactions | Legal obligation under the Financial Transactions Reporting Act and the Prevention of Money Laundering Act, No. 5 of 2006 |
| Process payments, refunds, payouts and settlements | Performance of the contract |
| Keep a customer's card on file with a merchant | The customer's consent, given at checkout |
| Send service messages, such as OTPs, receipts and settlement notices | Performance of the contract |
| Detect fraud and abuse, including pre transaction risk screening | Legitimate interest in running a safe payment service; legal obligation |
| Handle chargebacks, disputes and complaints | Performance of the contract; legal obligation |
| Keep financial and tax records | Legal obligation under the Inland Revenue Act, No. 24 of 2017 |
| Improve our Services and understand how our site and portal are used | Legitimate interest. You can object at any time. |
| Send news and offers about OnePay products | Your consent. You can opt out at any time. |
| Respond to regulators, courts and law enforcement | Legal obligation |
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing we did before, and some Services may stop working without it.
We do not sell personal data. We do not let third parties use it for their own marketing.
6. How we protect your data
OnePay is ISO/IEC 27001 certified. Our information security management system covers the people, processes and technology behind the Services.
- Card data stays out of our systems. Cards are entered on a PCI DSS compliant hosted payment page or a certified OnePay Tap terminal. We keep only a token, the scheme and the last four digits. Online card payments use 3D Secure.
- Encryption. Data travels over TLS 1.2 or higher. Data at rest is encrypted. Identity numbers, bank account numbers and uploaded documents get an extra layer of encryption.
- Access control. Staff access follows least privilege and needs multi factor authentication. Access is logged and reviewed.
- Separation.Each merchant’s data is logically separated from every other merchant’s.
- Secrets. Passwords, API keys and one time codes are stored only as hashes.
- Monitoring. We watch for fraud and security events around the clock. Logs are masked so that card details, passwords and ID numbers never reach them.
- Testing. We run regular vulnerability scans and penetration tests.
- Suppliers. Every processor we use is bound by a contract that limits what they can do with your data.
No system is perfectly secure. Please keep your password and API keys private, and tell us straight away if you think your account has been misused.
7. Who we share your data with
We share personal data only when we need to, and only with the parties below.
| Who | Why | What they receive |
|---|---|---|
| Acquiring banks (Seylan Bank PLC, Sampath Bank PLC, Hatton National Bank PLC, others — to confirm) | To approve merchants, process card payments and settle funds | Merchant application and KYC details, transaction data |
| Card networks (Visa, Mastercard and others) | To authorise, clear and settle card payments | Transaction and card token data |
| Payment partners and wallet providers (e.g. LankaPay — to confirm) | To process non card payment methods | Transaction data |
| Cloud hosting and infrastructure (Azure, AWS, GCP) | To host the platform securely | Encrypted data stored on their systems |
| SMS, email and messaging providers | To send OTPs, receipts and service messages | Phone number or email, and the message |
| OnePay Tap terminal supplier | To deliver, install and support terminals | Merchant contact and location details |
| Analytics providers (e.g. Google Analytics) | To understand site and portal use | Usage data and cookie identifiers |
| Professional advisors and auditors | Legal, audit and ISO 27001 certification work | What each engagement needs, under confidentiality |
| Regulators and authorities | When the law, a court order or a regulatory direction requires it | What the request lawfully covers |
Regulators and authorities include the Central Bank of Sri Lanka, the Financial Intelligence Unit, the Inland Revenue Department, the Data Protection Authority, the courts and the police. Where the law allows, we will tell you about a request.
Group companies and investors. We may share data within the Spemai group where needed to run the Services. We do not share merchant or customer personal data with our investors.
Business changes. If Spemai is involved in a merger, acquisition or sale of assets, personal data may move to the new owner. They will be bound by this policy or one that gives you the same protection. We will tell you before that happens.
Merchants.When you pay a merchant, the merchant receives your payment details so it can fulfil your order. The merchant’s own privacy policy governs how it uses them.
8. Where your data is kept
Our core platform and databases are hosted at a location and with a provider to be confirmed. Some of our service providers, such as email, analytics and cloud security services, operate outside Sri Lanka.
Section 26 of the PDPA allows personal data to leave Sri Lanka only where it stays protected. When we transfer data abroad, we:
- use providers bound by contracts that limit their use of the data to providing their service;
- encrypt data in transit and at rest;
- choose providers with recognised security certifications; and
- follow any adequacy decisions, binding instruments or directions the Data Protection Authority issues.
Card payment data processed by our Sri Lankan acquiring banks stays within their licensed systems.
9. How long we keep it
We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires. Then we delete it or anonymise it.
| Data | How long we keep it | Why |
|---|---|---|
| Merchant KYC records and documents | 6 years after the merchant relationship ends | Financial Transactions Reporting Act |
| Transaction, refund, fee and settlement records | 6 years after the end of the relevant year | Financial Transactions Reporting Act; Inland Revenue Act |
| Account activity and audit logs | 6 years | Fraud prevention, disputes and legal obligations |
| Chargeback and dispute records | Until resolved, then 6 years | Card network rules; legal claims |
| Saved card tokens | Until the customer or merchant removes the card, or the account closes | Customer consent |
| Documents removed before an application is submitted | Deleted straight away | Not needed |
| Rejected applications | 2 years (to confirm) | Fraud prevention; responding to queries |
| Marketing preferences | Until you opt out, then a suppression record | So we respect your choice |
| Operational system logs | 30 days (to confirm) | Security and troubleshooting |
When a merchant account closes, we keep only what the law requires and delete the rest. You can ask us to confirm when that is done.
10. Your rights under the PDPA
The PDPA gives you clear rights over your personal data. You can ask us to:
- Access your data. Confirm whether we process it and give you a copy (section 13).
- Withdraw consent. Stop processing that relies on your consent, such as a saved card or marketing messages (section 14).
- Object. Object to processing based on our legitimate interests (section 14).
- Correct your data. Fix data that is wrong or complete data that is missing (section 15).
- Erase your data. Delete it where we are not legally required to keep it (section 16). KYC and transaction records must stay for their legal retention period. We will tell you what we can and cannot erase, and why.
- Review automated decisions. Ask for a person to review a decision made only by automated means that significantly affects you (section 18). Our fraud tools may flag or hold a transaction, but a person reviews any decision to reject an application or close an account.
How to make a request
Email our Data Protection Officer at privacy@onepay.lk from the email address on your account. We may ask you to prove your identity first, so we do not share your data with the wrong person.
We will reply within 21 working days, as the PDPA requires. If we need to refuse a request, we will explain why. We do not charge for a reasonable request.
If you are a customer of a merchant, please contact the merchant first, as they own your relationship. If your request is about our own records, or the merchant asks us to act, we will help directly.
11. Cookies and similar tools
Cookies are small files your browser stores when you visit a website. We use them in three ways.
| Type | What it does | Can you turn it off? |
|---|---|---|
| Essential | Keeps you signed in, secures checkout and prevents fraud | No. The Services need them to work. |
| Analytics | Shows us which pages are used and where people get stuck | Yes |
| Marketing | Measures our own ads on our public website | Yes |
Analytics and marketing cookies run only on our public website and merchant portal. They never run on checkout or payment pages, so they never see what you type there.
You can manage cookies through our cookie banner or your browser settings. Blocking non essential cookies will not stop you from using OnePay.
12. Fraud monitoring, AI and children
Fraud monitoring
To keep payments safe, we screen transactions before and after they happen. Our tools look at things like transaction amount, merchant category, device and location patterns. They may hold a payment or a settlement for review. A trained person makes the final call on any action that seriously affects a merchant, such as rejecting an application or closing an account. You can ask for a human review at any time.
AI features
Some OnePay features use AI, such as insights in the merchant dashboard. We only use your data for these features to serve you. We do not use merchant or customer personal data to train third party AI models.
Children
OnePay merchant accounts are for adults. You must be 18 or over to open one. We do not knowingly collect personal data from children through our merchant Services. Merchants are responsible for any age rules that apply to what they sell. If you think we hold a child’s data by mistake, contact us and we will delete it.
13. Data breaches
If a breach puts your personal data at risk, we will act fast to contain it. We will notify the Data Protection Authority as section 23 of the PDPA and its rules require, and tell affected people without undue delay. We will also inform the Central Bank of Sri Lanka and our acquiring banks where their rules require it.
14. Changes to this policy
We update this policy when our Services or the law change. The effective date at the top will show the latest version. If a change reduces your rights or adds a new use of your data, we will email account holders before it takes effect. Earlier versions are available on request.
15. Contact us
Data Protection Officer
Spemai (Private) Limited
3rd Floor, 292, Richmond House, Gamsabha Junction, High Level Road, Nugegoda, Sri Lanka.
Email: info@onepay.lk | info@spemai.com
Phone: +94 11 702 1540