MaruPay provides a business-to-business payment and settlement service that lets online services (“merchants”) accept Korean gift voucher payments. This policy explains what information we process when merchants and their teams use our website, console and API, and when a merchant's users complete a payment on the MaruPay payment screen.
For merchant account data, we decide how that information is used. For payment data about a merchant's users, we process it to provide the service to that merchant, and the merchant remains responsible for its relationship with its users.
Information we process
- Merchant account data: business contact details, work email addresses of console users, role assignments, sign-in and two-factor settings, API key metadata and webhook endpoint configuration.
- Payment data: the references a merchant sends when it creates a payment (such as an order ID and the merchant's own customer reference), amounts, status history, and the information needed to confirm that a payment was received and to match it to a request.
- Settlement data: per-transaction settlement records and the review history of payments that needed an operator's decision.
- Technical data: IP addresses, browser and device information, and logs of requests to the console and API, including webhook delivery attempts and responses.
- Communications: messages you send us, for example through a sales or support inquiry.
We ask merchants to send only the references they need to identify an order and a customer in their own systems.
How we use information
- To provide the service: creating payments, showing the payment screen, confirming receipt, matching receipts to payment requests, delivering webhooks and keeping settlement records.
- To review merchants before activation and to keep the service secure, including detecting and investigating misuse.
- To support merchants and answer inquiries.
- To meet legal obligations and to establish, exercise or defend legal claims.
- To maintain and improve the reliability of the service.
We don't sell personal information, and we don't use payment data for advertising.
International processing
Merchants and their users may be in different countries, and our service providers may process information outside the country where it was collected. When that happens, we rely on contractual and technical safeguards appropriate to the information involved.
Retention
We keep merchant account data for as long as the account is active and for a reasonable period afterwards. Payment and settlement records are kept for as long as needed for settlement, dispute handling and record-keeping obligations. Settlement records are append-only: corrections are added as new entries rather than by editing earlier ones. Technical logs are kept for a limited period and then deleted or aggregated.
Security
We protect information with measures that include signed webhooks, scoped and rotatable API keys, two-factor sign-in, optional IP allowlists and least-privilege access for our own staff. See the Security page for details.
Your choices and rights
Depending on where you are, you may have rights to access, correct, delete or restrict the use of your personal information, or to object to certain processing. Console users can update much of their account information directly. For other requests, contact us.
If you paid a merchant through MaruPay, please contact that merchant first: it holds the relationship with you and can tell us what to do. We'll help the merchant respond.
Changes to this policy
We'll update this page when our practices change and revise the date at the top. If a change is significant, we'll notify merchants through the console or by email before it takes effect.
Questions about this page?
Contact us: [email protected]