Onepay Logo

OnePay Privacy Policy

Effective date: 29 September 2026

1. Who we are and what this policy covers

OnePay is a payment platform run by Spemai (Private) Limited, a company incorporated in Sri Lanka (company registration number PV00206829), with its registered office at 3rd Floor, 292, Richmond House, Gamsabha Junction, High Level Road, Nugegoda, Sri Lanka. In this policy, “OnePay”, “we”, “us” and “our” mean Spemai (Private) Limited and the OnePay services it operates.

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what you can ask us to do with it. It covers the OnePay website, merchant portal, mobile app, checkout pages, payment links, APIs, plugins and SDKs, and OnePay Tap card terminals (together, the Services).

We process personal data in line with the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (the PDPA). As a participant in Sri Lanka’s payment system, we also follow the Central Bank of Sri Lanka’s Financial Consumer Protection Regulations and the security rules of the card networks.

For the personal data we collect to run OnePay, we are the controller. When a merchant uses OnePay to accept payments from its own customers, the merchant owns that customer relationship. We process those customers’ details to complete the payment on the merchant’s behalf, and to meet our own legal record keeping duties.

Please read this policy together with our Terms of Service and the Merchant Agreement that applies to you.

In short

This summary helps you find your way around. The numbered sections are what apply.

2. Key terms

We use these terms in the same sense as the PDPA.

TermWhat it means here
Personal dataAny information that identifies you, directly or together with other information we hold. For example, your name, NIC number, phone number or IP address.
Special categories of personal dataData the PDPA treats as more sensitive, such as financial data, biometric data and data on criminal offences. We process these only where Schedule II of the PDPA allows.
ProcessingAnything we do with personal data: collecting, storing, using, sharing, transferring or deleting it.
ControllerThe organisation that decides why and how personal data is processed.
ProcessorAn organisation that processes personal data on a controller’s instructions.
Data subjectThe person the personal data is about. That may be you.
MerchantA business or individual that uses OnePay to accept payments.
CustomerA person who pays a merchant through OnePay.
Data Protection AuthorityThe Data Protection Authority of Sri Lanka, set up under the PDPA.

3. Whose data this policy covers

This policy applies to everyone whose personal data we handle:

OnePay is built for businesses. If you give us personal data about someone else, such as a director or team member, please let them know and point them to this policy.

4. What we collect and how

From applicants and merchants

From customers who pay a merchant

We do not store full card numbers, CVV codes or PINs. Cards are entered on a secure hosted payment page or a certified OnePay Tap terminal.

From visitors and developers

From other sources

5. Why we use your data and our lawful basis

The PDPA allows personal data to be processed only on a lawful basis set out in Schedule I. Here is what we do and why.

PurposeLawful basis under the PDPA
Review an application and open a merchant account, including sharing it with our acquiring bank for approvalSteps you ask for before a contract; performance of the contract
Verify identity, ownership and bank details (KYC) and keep those recordsLegal obligation under the Financial Transactions Reporting Act, No. 6 of 2006, and Central Bank of Sri Lanka directions
Screen against sanctions lists and report suspicious transactionsLegal obligation under the Financial Transactions Reporting Act and the Prevention of Money Laundering Act, No. 5 of 2006
Process payments, refunds, payouts and settlementsPerformance of the contract
Keep a customer's card on file with a merchantThe customer's consent, given at checkout
Send service messages, such as OTPs, receipts and settlement noticesPerformance of the contract
Detect fraud and abuse, including pre transaction risk screeningLegitimate interest in running a safe payment service; legal obligation
Handle chargebacks, disputes and complaintsPerformance of the contract; legal obligation
Keep financial and tax recordsLegal obligation under the Inland Revenue Act, No. 24 of 2017
Improve our Services and understand how our site and portal are usedLegitimate interest. You can object at any time.
Send news and offers about OnePay productsYour consent. You can opt out at any time.
Respond to regulators, courts and law enforcementLegal obligation

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing we did before, and some Services may stop working without it.

We do not sell personal data. We do not let third parties use it for their own marketing.

6. How we protect your data

OnePay is ISO/IEC 27001 certified. Our information security management system covers the people, processes and technology behind the Services.

No system is perfectly secure. Please keep your password and API keys private, and tell us straight away if you think your account has been misused.

7. Who we share your data with

We share personal data only when we need to, and only with the parties below.

WhoWhyWhat they receive
Acquiring banks (Seylan Bank PLC, Sampath Bank PLC, Hatton National Bank PLC, others — to confirm)To approve merchants, process card payments and settle fundsMerchant application and KYC details, transaction data
Card networks (Visa, Mastercard and others)To authorise, clear and settle card paymentsTransaction and card token data
Payment partners and wallet providers (e.g. LankaPay — to confirm)To process non card payment methodsTransaction data
Cloud hosting and infrastructure (Azure, AWS, GCP)To host the platform securelyEncrypted data stored on their systems
SMS, email and messaging providersTo send OTPs, receipts and service messagesPhone number or email, and the message
OnePay Tap terminal supplierTo deliver, install and support terminalsMerchant contact and location details
Analytics providers (e.g. Google Analytics)To understand site and portal useUsage data and cookie identifiers
Professional advisors and auditorsLegal, audit and ISO 27001 certification workWhat each engagement needs, under confidentiality
Regulators and authoritiesWhen the law, a court order or a regulatory direction requires itWhat the request lawfully covers

Regulators and authorities include the Central Bank of Sri Lanka, the Financial Intelligence Unit, the Inland Revenue Department, the Data Protection Authority, the courts and the police. Where the law allows, we will tell you about a request.

Group companies and investors. We may share data within the Spemai group where needed to run the Services. We do not share merchant or customer personal data with our investors.

Business changes. If Spemai is involved in a merger, acquisition or sale of assets, personal data may move to the new owner. They will be bound by this policy or one that gives you the same protection. We will tell you before that happens.

Merchants.When you pay a merchant, the merchant receives your payment details so it can fulfil your order. The merchant’s own privacy policy governs how it uses them.

8. Where your data is kept

Our core platform and databases are hosted at a location and with a provider to be confirmed. Some of our service providers, such as email, analytics and cloud security services, operate outside Sri Lanka.

Section 26 of the PDPA allows personal data to leave Sri Lanka only where it stays protected. When we transfer data abroad, we:

Card payment data processed by our Sri Lankan acquiring banks stays within their licensed systems.

9. How long we keep it

We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires. Then we delete it or anonymise it.

DataHow long we keep itWhy
Merchant KYC records and documents6 years after the merchant relationship endsFinancial Transactions Reporting Act
Transaction, refund, fee and settlement records6 years after the end of the relevant yearFinancial Transactions Reporting Act; Inland Revenue Act
Account activity and audit logs6 yearsFraud prevention, disputes and legal obligations
Chargeback and dispute recordsUntil resolved, then 6 yearsCard network rules; legal claims
Saved card tokensUntil the customer or merchant removes the card, or the account closesCustomer consent
Documents removed before an application is submittedDeleted straight awayNot needed
Rejected applications2 years (to confirm)Fraud prevention; responding to queries
Marketing preferencesUntil you opt out, then a suppression recordSo we respect your choice
Operational system logs30 days (to confirm)Security and troubleshooting

When a merchant account closes, we keep only what the law requires and delete the rest. You can ask us to confirm when that is done.

10. Your rights under the PDPA

The PDPA gives you clear rights over your personal data. You can ask us to:

How to make a request

Email our Data Protection Officer at privacy@onepay.lk from the email address on your account. We may ask you to prove your identity first, so we do not share your data with the wrong person.

We will reply within 21 working days, as the PDPA requires. If we need to refuse a request, we will explain why. We do not charge for a reasonable request.

If you are a customer of a merchant, please contact the merchant first, as they own your relationship. If your request is about our own records, or the merchant asks us to act, we will help directly.

11. Cookies and similar tools

Cookies are small files your browser stores when you visit a website. We use them in three ways.

TypeWhat it doesCan you turn it off?
EssentialKeeps you signed in, secures checkout and prevents fraudNo. The Services need them to work.
AnalyticsShows us which pages are used and where people get stuckYes
MarketingMeasures our own ads on our public websiteYes

Analytics and marketing cookies run only on our public website and merchant portal. They never run on checkout or payment pages, so they never see what you type there.

You can manage cookies through our cookie banner or your browser settings. Blocking non essential cookies will not stop you from using OnePay.

12. Fraud monitoring, AI and children

Fraud monitoring

To keep payments safe, we screen transactions before and after they happen. Our tools look at things like transaction amount, merchant category, device and location patterns. They may hold a payment or a settlement for review. A trained person makes the final call on any action that seriously affects a merchant, such as rejecting an application or closing an account. You can ask for a human review at any time.

AI features

Some OnePay features use AI, such as insights in the merchant dashboard. We only use your data for these features to serve you. We do not use merchant or customer personal data to train third party AI models.

Children

OnePay merchant accounts are for adults. You must be 18 or over to open one. We do not knowingly collect personal data from children through our merchant Services. Merchants are responsible for any age rules that apply to what they sell. If you think we hold a child’s data by mistake, contact us and we will delete it.

13. Data breaches

If a breach puts your personal data at risk, we will act fast to contain it. We will notify the Data Protection Authority as section 23 of the PDPA and its rules require, and tell affected people without undue delay. We will also inform the Central Bank of Sri Lanka and our acquiring banks where their rules require it.

14. Changes to this policy

We update this policy when our Services or the law change. The effective date at the top will show the latest version. If a change reduces your rights or adds a new use of your data, we will email account holders before it takes effect. Earlier versions are available on request.

15. Contact us

Data Protection Officer
Spemai (Private) Limited
3rd Floor, 292, Richmond House, Gamsabha Junction, High Level Road, Nugegoda, Sri Lanka.
Email: info@onepay.lk | info@spemai.com
Phone: +94 11 702 1540