Privacy Policy
1. Introduction
Paye ("we", "our", or "us") is dedicated to protecting your privacy. This Privacy Policy describes how we collect, use, and handle information when you use our developer-centric API routing infrastructure and services (the "Services").
2. Information We Collect
To provide our proxying and routing services, we collect information necessary to authenticate developers, configure integrations, and route transaction requests:
- Account Information: Names, email addresses, and account credentials when you register for an account.
- API Keys and Gateway Credentials: Original merchant gateway API keys (e.g., Paystack, Flutterwave) provided by you to allow Paye to communicate with those gateways on your behalf.
- Transaction Data: Meta-information about transaction requests routed through our API (e.g., amount, currency, email address, transaction reference, gateway provider, and response metrics).
3. Data Protection and Routing
Because Paye is an API proxy layer, we take the security of your transit data and credentials extremely seriously:
- AES-GCM Encryption: All gateway API keys and secrets provided to the dashboard are encrypted at rest using industry-standard AES-GCM encryption.
- Proxy Transit: Original credentials are only decrypted temporarily in memory at the proxy layer during active routing requests to upstream gateways, and are never logged or stored in plaintext.
- Transaction Payload Logging: We log payload sizes, status codes, and provider response times for auditing and troubleshooting, but we do not store sensitive payment card details or merchant bank information.
4. How We Use Information
We use the information we collect solely for the following purposes:
- To route API payment requests to the designated African payment gateways.
- To authenticate API calls and prevent unauthorized account access.
- To display transaction logs and status codes on your dashboard.
- To troubleshoot integration problems and improve proxy performance.
5. Data Retention
We retain account metadata and transaction log history as long as your account is active, or as needed to comply with legal obligations, resolve disputes, and enforce our agreements. If you delete a gateway integration, the associated credentials are instantly and permanently purged from our database.
6. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or regulatory requirements. We will notify you of any material changes by posting the updated policy on our website.
7. Contact Us
If you have any questions or concerns about this Privacy Policy, please reach out to us at legal@paye.africa.