Onepay Logo

Privacy Policy

Effective date: 29 September 2026

OnePay is a payment platform run by Spemai (Private) Limited, a company incorporated in Sri Lanka (company registration number PV00206829), with its registered office at 3rd Floor, 292, Richmond House, Gamsabha Junction, High Level Road, Nugegoda, Sri Lanka. In this policy, “OnePay”, “we”, “us” and “our” mean Spemai (Private) Limited and the OnePay services it operates.

In short

  • We never store full card numbers. Cards are entered on a secure, PCI DSS compliant payment page and we keep only a token and the last four digits.
  • We collect what the law requires before a business can accept card payments, plus what we need to run the Services.
  • We share data only with the banks, card networks and service providers that make payments work, and with regulators when the law requires it.
  • We do not sell personal data.
  • Records required by anti money laundering and tax law are kept for six years. Everything else is kept only as long as it is needed.
  • You can ask to see, correct or erase your data, withdraw consent, object to a use and complain to the Data Protection Authority of Sri Lanka.

This summary helps you find your way around. The numbered sections are what apply.

1. Who we are and what this policy covers

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what you can ask us to do with it. It covers the OnePay website, merchant portal, mobile app, checkout pages, payment links, APIs, plugins and SDKs, and OnePay Tap card terminals (together, the Services).

We process personal data in line with the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (the PDPA). As a participant in Sri Lanka’s payment system, we also follow the Central Bank of Sri Lanka’s Financial Consumer Protection Regulations and the security rules of the card networks.

For the personal data we collect to run OnePay, we are the controller. When a merchant uses OnePay to accept payments from its own customers, the merchant owns that customer relationship. We process those customers’ details to complete the payment on the merchant’s behalf, and to meet our own legal record keeping duties.

Please read this policy together with our Terms of Service and the Merchant Agreement that applies to you.

2. Key terms

We use these terms in the same sense as the PDPA.

TermWhat it means here
Personal dataAny information that identifies you, directly or together with other information we hold. For example, your name, NIC number, phone number or IP address.
Special categories of personal dataData the PDPA treats as more sensitive, such as financial data, biometric data and data on criminal offences. We process these only where Schedule II of the PDPA allows.
ProcessingAnything we do with personal data: collecting, storing, using, sharing, transferring or deleting it.
ControllerThe organisation that decides why and how personal data is processed.
ProcessorAn organisation that processes personal data on a controller’s instructions.
Data subjectThe person the personal data is about. That may be you.
MerchantA business or individual that uses OnePay to accept payments.
CustomerA person who pays a merchant through OnePay.
Data Protection AuthorityThe Data Protection Authority of Sri Lanka, set up under the PDPA.

3. Whose data this policy covers

This policy applies to everyone whose personal data we handle:

  • Applicants and merchants. Anyone who applies for, opens or runs a OnePay merchant account.
  • People connected to a merchant. Owners, directors, partners, beneficial owners and authorised signatories named in an application. Also team members a merchant invites to its dashboard.
  • Customers. Anyone who pays a merchant through a OnePay checkout, payment link, SMS Pay, saved card or OnePay Tap terminal.
  • Developers. Anyone who integrates with our APIs, webhooks, plugins or SDKs.
  • Visitors. Anyone who visits our websites or contacts us.
  • Partners and suppliers. Contact people at banks, resellers, vendors and advisors we work with.
  • Job applicants. People who apply to work with Spemai.

OnePay is built for businesses. If you give us personal data about someone else, such as a director or team member, please let them know and point them to this policy.

4. What we collect and how

From applicants and merchants

  • Account details. Name, email address, mobile number (verified with a one time code), password (stored only as a one way hash) and language preference.
  • Identity details. NIC or passport number, date of birth, role in the business and copies of identity documents.
  • Business details. Business name, registration number and type, address, district, what you sell and how, website, expected monthly volume, average ticket size, and names and shareholdings of owners and directors.
  • Settlement details. Bank, branch, account holder name, account number and Taxpayer Identification Number (TIN).
  • Supporting documents. Business registration certificate, company forms, partnership deed, board resolution, proof of address, bank proof and any sector licence.
  • OnePay Tap details. Terminal serial number, installation location and rental records.
  • Activity records. Sign ins, settings changes, API keys issued, refunds and payouts, with the time, the user and the IP address.

From customers who pay a merchant

  • Name, email address and phone number.
  • Billing address, where the card network or bank requires it.
  • Amount, currency, date, merchant reference and what the payment was for.
  • Payment result, card scheme, last four digits, card expiry and a payment token.
  • Device and network data used for fraud checks, such as IP address, browser and device type.

We do not store full card numbers, CVV codes or PINs. Cards are entered on a secure hosted payment page or a certified OnePay Tap terminal.

From visitors and developers

  • Web server logs: IP address, pages requested, browser and device type.
  • Cookie and analytics data, as explained in section 11.
  • For developers: API key identifiers, webhook URLs and request logs.
  • Anything you send us by email, WhatsApp, phone or contact forms.

From other sources

  • Acquiring banks and card networks, for payment results, chargebacks and fraud alerts.
  • Public registers such as the Registrar of Companies, and sanctions and watch lists, for verification.
  • Credit and fraud prevention agencies, where the law allows.

5. Why we use your data and our lawful basis

The PDPA allows personal data to be processed only on a lawful basis set out in Schedule I. Here is what we do and why.

PurposeLawful basis under the PDPA
Review an application and open a merchant account, including sharing it with our acquiring bank for approvalSteps you ask for before a contract; performance of the contract
Verify identity, ownership and bank details (KYC) and keep those recordsLegal obligation under the Financial Transactions Reporting Act, No. 6 of 2006, and Central Bank of Sri Lanka directions
Screen against sanctions lists and report suspicious transactionsLegal obligation under the Financial Transactions Reporting Act and the Prevention of Money Laundering Act, No. 5 of 2006
Process payments, refunds, payouts and settlementsPerformance of the contract
Keep a customer's card on file with a merchantThe customer's consent, given at checkout
Send service messages, such as OTPs, receipts and settlement noticesPerformance of the contract
Detect fraud and abuse, including pre transaction risk screeningLegitimate interest in running a safe payment service; legal obligation
Handle chargebacks, disputes and complaintsPerformance of the contract; legal obligation
Keep financial and tax recordsLegal obligation under the Inland Revenue Act, No. 24 of 2017
Improve our Services and understand how our site and portal are usedLegitimate interest. You can object at any time.
Send news and offers about OnePay productsYour consent. You can opt out at any time.
Respond to regulators, courts and law enforcementLegal obligation

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing we did before, and some Services may stop working without it.

We do not sell personal data. We do not let third parties use it for their own marketing.

6. How we protect your data

OnePay is ISO/IEC 27001 certified. Our information security management system covers the people, processes and technology behind the Services.

  • Card data stays out of our systems. Cards are entered on a PCI DSS compliant hosted payment page or a certified OnePay Tap terminal. We keep only a token, the scheme and the last four digits. Online card payments use 3D Secure.
  • Encryption. Data travels over TLS 1.2 or higher. Data at rest is encrypted. Identity numbers, bank account numbers and uploaded documents get an extra layer of encryption.
  • Access control. Staff access follows least privilege and needs multi factor authentication. Access is logged and reviewed.
  • Separation.Each merchant’s data is logically separated from every other merchant’s.
  • Secrets. Passwords, API keys and one time codes are stored only as hashes.
  • Monitoring. We watch for fraud and security events around the clock. Logs are masked so that card details, passwords and ID numbers never reach them.
  • Testing. We run regular vulnerability scans and penetration tests.
  • Suppliers. Every processor we use is bound by a contract that limits what they can do with your data.

No system is perfectly secure. Please keep your password and API keys private, and tell us straight away if you think your account has been misused.

7. Who we share your data with

We share personal data only when we need to, and only with the parties below.

WhoWhyWhat they receive
Acquiring banks (Seylan Bank PLC, Sampath Bank PLC, Hatton National Bank PLC, others — to confirm)To approve merchants, process card payments and settle fundsMerchant application and KYC details, transaction data
Card networks (Visa, Mastercard and others)To authorise, clear and settle card paymentsTransaction and card token data
Payment partners and wallet providers (e.g. LankaPay — to confirm)To process non card payment methodsTransaction data
Cloud hosting and infrastructure (Azure, AWS, GCP)To host the platform securelyEncrypted data stored on their systems
SMS, email and messaging providersTo send OTPs, receipts and service messagesPhone number or email, and the message
OnePay Tap terminal supplierTo deliver, install and support terminalsMerchant contact and location details
Analytics providers (e.g. Google Analytics)To understand site and portal useUsage data and cookie identifiers
Professional advisors and auditorsLegal, audit and ISO 27001 certification workWhat each engagement needs, under confidentiality
Regulators and authoritiesWhen the law, a court order or a regulatory direction requires itWhat the request lawfully covers

Regulators and authorities include the Central Bank of Sri Lanka, the Financial Intelligence Unit, the Inland Revenue Department, the Data Protection Authority, the courts and the police. Where the law allows, we will tell you about a request.

Group companies and investors. We may share data within the Spemai group where needed to run the Services. We do not share merchant or customer personal data with our investors.

Business changes. If Spemai is involved in a merger, acquisition or sale of assets, personal data may move to the new owner. They will be bound by this policy or one that gives you the same protection. We will tell you before that happens.

Merchants.When you pay a merchant, the merchant receives your payment details so it can fulfil your order. The merchant’s own privacy policy governs how it uses them.

8. Where your data is kept

Our core platform and databases are hosted at a location and with a provider to be confirmed. Some of our service providers, such as email, analytics and cloud security services, operate outside Sri Lanka.

Section 26 of the PDPA allows personal data to leave Sri Lanka only where it stays protected. When we transfer data abroad, we:

  • use providers bound by contracts that limit their use of the data to providing their service;
  • encrypt data in transit and at rest;
  • choose providers with recognised security certifications; and
  • follow any adequacy decisions, binding instruments or directions the Data Protection Authority issues.

Card payment data processed by our Sri Lankan acquiring banks stays within their licensed systems.

9. How long we keep it

We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires. Then we delete it or anonymise it.

DataHow long we keep itWhy
Merchant KYC records and documents6 years after the merchant relationship endsFinancial Transactions Reporting Act
Transaction, refund, fee and settlement records6 years after the end of the relevant yearFinancial Transactions Reporting Act; Inland Revenue Act
Account activity and audit logs6 yearsFraud prevention, disputes and legal obligations
Chargeback and dispute recordsUntil resolved, then 6 yearsCard network rules; legal claims
Saved card tokensUntil the customer or merchant removes the card, or the account closesCustomer consent
Documents removed before an application is submittedDeleted straight awayNot needed
Rejected applications2 years (to confirm)Fraud prevention; responding to queries
Marketing preferencesUntil you opt out, then a suppression recordSo we respect your choice
Operational system logs30 days (to confirm)Security and troubleshooting

When a merchant account closes, we keep only what the law requires and delete the rest. You can ask us to confirm when that is done.

10. Your rights under the PDPA

The PDPA gives you clear rights over your personal data. You can ask us to:

  • Access your data. Confirm whether we process it and give you a copy (section 13).
  • Withdraw consent. Stop processing that relies on your consent, such as a saved card or marketing messages (section 14).
  • Object. Object to processing based on our legitimate interests (section 14).
  • Correct your data. Fix data that is wrong or complete data that is missing (section 15).
  • Erase your data. Delete it where we are not legally required to keep it (section 16). KYC and transaction records must stay for their legal retention period. We will tell you what we can and cannot erase, and why.
  • Review automated decisions. Ask for a person to review a decision made only by automated means that significantly affects you (section 18). Our fraud tools may flag or hold a transaction, but a person reviews any decision to reject an application or close an account.

How to make a request

Email our Data Protection Officer at privacy@onepay.lk from the email address on your account. We may ask you to prove your identity first, so we do not share your data with the wrong person.

We will reply within 21 working days, as the PDPA requires. If we need to refuse a request, we will explain why. We do not charge for a reasonable request.

If you are a customer of a merchant, please contact the merchant first, as they own your relationship. If your request is about our own records, or the merchant asks us to act, we will help directly.

11. Cookies and similar tools

Cookies are small files your browser stores when you visit a website. We use them in three ways.

TypeWhat it doesCan you turn it off?
EssentialKeeps you signed in, secures checkout and prevents fraudNo. The Services need them to work.
AnalyticsShows us which pages are used and where people get stuckYes
MarketingMeasures our own ads on our public websiteYes

Analytics and marketing cookies run only on our public website and merchant portal. They never run on checkout or payment pages, so they never see what you type there.

You can manage cookies through our cookie banner or your browser settings. Blocking non essential cookies will not stop you from using OnePay.

12. Fraud monitoring, AI and children

Fraud monitoring

To keep payments safe, we screen transactions before and after they happen. Our tools look at things like transaction amount, merchant category, device and location patterns. They may hold a payment or a settlement for review. A trained person makes the final call on any action that seriously affects a merchant, such as rejecting an application or closing an account. You can ask for a human review at any time.

AI features

Some OnePay features use AI, such as insights in the merchant dashboard. We only use your data for these features to serve you. We do not use merchant or customer personal data to train third party AI models.

Children

OnePay merchant accounts are for adults. You must be 18 or over to open one. We do not knowingly collect personal data from children through our merchant Services. Merchants are responsible for any age rules that apply to what they sell. If you think we hold a child’s data by mistake, contact us and we will delete it.

13. Data breaches

If a breach puts your personal data at risk, we will act fast to contain it. We will notify the Data Protection Authority as section 23 of the PDPA and its rules require, and tell affected people without undue delay. We will also inform the Central Bank of Sri Lanka and our acquiring banks where their rules require it.

14. Changes to this policy

We update this policy when our Services or the law change. The effective date at the top will show the latest version. If a change reduces your rights or adds a new use of your data, we will email account holders before it takes effect. Earlier versions are available on request.

15. Contact us

Data Protection Officer

Spemai (Private) Limited

3rd Floor, 292, Richmond House, Gamsabha Junction, High Level Road, Nugegoda, Sri Lanka.

Email: info@onepay.lk | info@spemai.com

Phone: +94 11 702 1540