Privacy Policy
Privacy Policy
Last updated
This Privacy Policy explains how Suba Software Solutions, operating Verify Checkout, collects, uses, shares, stores, and protects information when you use our website, merchant dashboard, hosted checkout, developer API, support channels, documentation, and related services.
On this pageInformation We Collect
Verify Checkout handles merchant checkout, receiving-account assignment, and payment-verification workflows. That means privacy, security, auditability, and responsible data handling are core product requirements, not optional features.
Our privacy commitments
- We do not sell or rent personal information.
- We use service data to operate, secure, support, and improve Verify Checkout.
- We do not hold customer funds. Merchant receiving accounts stay under merchant control.
- We do not voluntarily disclose customer data to government offices without valid legal process.
1. Information We Collect
We collect only the information needed to provide, secure, maintain, support, and improve Verify Checkout. The exact information depends on how you use the website, merchant dashboard, hosted checkout, developer API, support channels, documentation, and related services.
1.1 Account And Contact Information
When you create a merchant account, sign in with Telegram, complete a workspace profile, request live access, contact support, or manage billing, we may collect account and business contact details.
- Name, business name, email address, phone number, website, support URL, product category, and country.
- Telegram user identifier, username, phone number, profile photo URL, and related authentication details supplied by Telegram sign-in.
- Login credentials, authentication details, workspace membership, and role information.
- Support messages, onboarding notes, live-mode application details, billing records, plan information, invoices, and subscription status.
1.2 Merchant Workspace And Receiving Accounts
Merchants control the destination accounts shown on hosted checkout. We store the workspace and account details needed to assign, display, and verify those destinations.
- Receiving-account labels, institution or wallet, account numbers, phone numbers, merchant codes, account-holder names, and related routing details you provide.
- Merchant logos, brand display names, authorized return domains, webhook URLs, API key metadata, and workspace configuration.
- Live-mode application status, sandbox versus live isolation records, and operational settings such as checkout expiry or review actions.
1.3 Hosted Checkout And Payer Data
When a merchant creates a checkout and a payer uses hosted checkout, we process the fields needed to show payment instructions, accept a reference, verify the transfer, and report status to the merchant.
- Checkout amount, currency, selected payment method, assigned receiving-account display details, expiry, public checkout token, and merchant-provided customer identifiers such as merchant_customer_id.
- Payment references, receipt numbers, SMS or receipt text pasted by the payer, selected bank or wallet, and provider-specific verification fields.
- Provider-returned details where available, such as amount, currency, timestamp, sender or receiver names, sender or receiver account details, reference numbers, and status messages.
- Checkout status, verification status, retry counts, review markers, request IDs, and related operational timestamps.
1.4 API, Dashboard, And Usage Data
For API and dashboard users, we collect operational records that help authenticate requests, enforce usage limits, support teams, troubleshoot errors, and make the product more reliable.
- API key metadata, key permissions, API usage counts, verification-credit usage, quotas, rate limits, request timestamps, and endpoint activity.
- Error codes, webhook delivery attempts, dashboard activity, deposit history, exports, reports, analytics, and staff activity records.
- Configuration data such as webhook URLs, return domains, receiving-account changes, and permission changes.
1.5 Device, Technical, And Log Data
We collect technical records to keep the service reliable, detect abuse, investigate incidents, and improve user experience across the website, dashboard, API, and hosted checkout.
- IP address, browser type, device type, operating system, referring URLs, pages viewed, session events, crash logs, security logs, timestamps, authentication events, and request identifiers.
- Performance, uptime, latency, queue health, provider availability, and error telemetry used for reliability and security monitoring.
1.6 Cookies And Local Storage
We may use cookies, local storage, and similar technologies for authentication, security, session management, saved preferences, analytics, service improvement, and abuse prevention.
1.7 Communications
If you contact us, request pricing, submit a form, or communicate through support channels, we may collect your name, email address, phone number, Telegram username, business details, message contents, and related support context.
2. How We Use Information
We use information for legitimate product, security, support, compliance, and reliability purposes. We do not use checkout or verification data to sell advertising profiles, and we do not sell personal information.
- Provide, operate, maintain, monitor, and improve Verify Checkout.
- Create checkouts, assign merchant receiving accounts, display payment instructions, process verification requests, and return results, status updates, history, reports, and exports.
- Authenticate users and API requests, manage merchant workspaces, enforce permissions, and secure API keys.
- Prevent the same real-world transfer from funding more than one deposit, including across merchants, without revealing another merchant's deposit details.
- Manage plans, verification credits, quotas, subscriptions, billing records, invoices, and account operations.
- Send webhooks, service notifications, support responses, security alerts, and operational messages.
- Detect, prevent, investigate, and respond to fraud, abuse, misuse, unauthorized access, duplicate payment reuse, suspicious verification activity, and security incidents.
- Measure uptime, latency, queue health, provider performance, reliability, and product quality.
- Improve user experience by analyzing aggregated or de-identified usage patterns, reducing errors, improving flows, and making the dashboard, hosted checkout, API, documentation, and support experience easier to use.
- Comply with legal, tax, accounting, audit, contractual, and recordkeeping obligations.
- Enforce our Terms of Service and protect Verify Checkout, merchants, payers, partners, and the public.
4. Data Retention
We retain information for as long as needed to provide Verify Checkout, operate checkout and verification workflows, maintain security, support billing and accounting, resolve disputes, enforce agreements, prevent fraud and duplicate payment reuse, improve reliability, and comply with legal obligations.
Checkout records, verification logs, API activity, security records, webhook logs, receiving-account history, support records, billing records, and audit records may be retained for operational, fraud-prevention, compliance, and reliability purposes.
When information is no longer needed, we may delete it, anonymize it, de-identify it, aggregate it, or restrict access according to our retention practices and legal requirements.
5. Security
Verify Checkout is built for checkout and transaction-verification workflows, so security is treated as a core operating requirement. We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, alteration, and disclosure.
- Encrypted transport for service communication where applicable.
- Authentication, session controls, Telegram sign-in, role-based access, permission-scoped API keys, and key rotation or revocation workflows.
- Infrastructure monitoring, security logging, request identifiers, rate limits, abuse detection, and operational alerts.
- Masked payment references on merchant APIs and duplicate-protection records designed not to leak another merchant's data.
- Internal access restrictions, least-privilege practices, and review of sensitive operational access.
- Recurring security reviews, dependency checks, configuration reviews, incident review practices, and reliability checks across critical request paths.
- Operational metrics and logs that help detect unusual behavior, provider failures, uptime regressions, and unauthorized access attempts.
No internet service, API, dashboard, hosted checkout, or storage system can be guaranteed to be completely secure. You are responsible for protecting your account, devices, staff access, API keys, webhook endpoints, receiving-account details, and integrations.
6. Your Responsibilities
Because Verify Checkout processes checkout, receiving-account, and verification-related data, merchants, API users, and payers must use the service responsibly and lawfully.
- Obtain any required authorization before submitting checkout, receiving-account, or verification data.
- Provide legally required notices to customers, staff, payers, or affected parties.
- Use verification results responsibly and avoid using them for unrelated profiling, harassment, or unlawful decisions.
- Limit dashboard and API access to authorized staff.
- Protect login credentials, Telegram sessions, API keys, webhook secrets, devices, and integration endpoints.
- Add only receiving accounts you own or are authorized to use, and keep those details accurate.
- Configure secure webhook URLs and authorized return domains, and review integrations that receive deposit results.
- Comply with applicable privacy, banking, payment, consumer protection, accounting, tax, employment, and data protection laws.
7. Your Choices And Rights
Depending on applicable law and your relationship with Verify Checkout, you may have rights regarding personal information we control.
- Request access to personal information.
- Request correction of inaccurate information.
- Request deletion of information.
- Object to or restrict certain processing.
- Request a copy of certain information.
- Withdraw consent where processing is based on consent.
These rights may be limited by legal, security, fraud-prevention, contractual, accounting, tax, audit, duplicate-protection, and recordkeeping requirements. To make a privacy request, contact us using the official support details on this page.
If you are a payer, the merchant that sent you the checkout may also control some identifiers, such as a merchant customer ID. We may need to coordinate with that merchant before changing or deleting related records.
8. Cookies And Analytics Choices
You may be able to control cookies through your browser settings. Blocking some cookies may affect login, dashboard functionality, API management, security features, saved preferences, analytics quality, or service performance.
Where analytics are used, they are intended to understand product reliability, user experience, and service quality. We do not use analytics to sell personal information.
9. Children's Privacy
Verify Checkout is intended for businesses, developers, operational teams, authorized merchant users, and payers completing a merchant checkout. It is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so we can review and take appropriate action.
10. International Data Processing
Your information may be processed in Ethiopia or in other countries where we, our infrastructure providers, or service providers operate. Data protection laws in those countries may differ from the laws where you are located.
Where required, we use appropriate safeguards for cross-border processing and expect service providers to process information only for authorized service purposes.
11. Third-Party Links And Services
Verify Checkout may link to third-party websites, banks, wallets, payment providers, Telegram, documentation, or integrations. We are not responsible for the privacy practices, security, content, or availability of third-party services.
12. Changes To This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the effective date or provide notice where appropriate. Continued use of Verify Checkout after the updated policy takes effect means you acknowledge the updated policy.
13. Contact Us
For privacy questions, data requests, or security-related privacy concerns, contact Verify Checkout through the official support channel below.
- Verify Checkout
- Suba Software Solutions
- Email: info@verifycheckout.et
- Website: checkout.verify.et
- Telegram: https://t.me/suba_software_solutions
- Operator: subasoftware.com
Privacy questions are reviewed in context so we can confirm identity, account authority, and any legal or security restrictions before responding.
Contact Support