1. Introduction
PayVia ("PayVia", "we", "our", or "us"), operated by Asia Digital, is committed to protecting your privacy and being transparent about how we handle personal data. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights and choices you have.
This policy applies to two audiences:
- Developers - businesses and individuals who register for a PayVia account to manage payments and subscriptions for their applications
- End-users / subscribers - the individuals whose data is processed through PayVia on behalf of a developer (typically the developer's own customers using their Chrome extension or SaaS product)
Please read this policy together with our Terms of Service.
2. Controller & Processor Roles
PayVia plays two distinct roles depending on the data in question, under the meaning of the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent data protection laws:
- Data Controller - for developer account data, including registration details, dashboard usage, project configuration, billing (if applicable), and communications with us. We decide the purposes and means of processing this data.
- Data Processor - for end-user / subscriber data that developers send to PayVia in order for us to provide the Services on their behalf. In that relationship, the developer is the data controller and determines what end-user data flows into PayVia, for what purposes, and for how long. PayVia processes end-user data only under the developer's documented instructions as set out in our Terms of Service and Data Processing Addendum.
If you are an end-user and want to exercise data subject rights in relation to your subscription, you should contact the developer whose application you use. We will assist that developer in responding to your request where appropriate.
3. How to Contact Us About Privacy
For any privacy-related question, request, or complaint, please contact us:
- Email: payvia@asia-digital.online (subject line "Privacy Request")
- Operator: Asia Digital, Israel
- Website contact form: payvia.site/contact
We do not currently have a formally appointed Data Protection Officer (DPO) because our core activities do not legally require one, but privacy requests are handled by our privacy team at the address above. EU and UK users also retain the right to lodge a complaint with their local supervisory authority; see Section 13.
4. Information We Collect
4.1 Developer Account Data
- Registration information: email address, password (bcrypt-hashed - never stored in plain text), display name, and any additional fields you provide at signup
- Google Sign-In data: if you choose to sign in with Google, we receive your Google user ID, email address, and display name from Google Identity Services. We do not access your Google contacts, calendar, Gmail, Drive, or any other Google service, and we do not retain your Google access or refresh tokens after authentication completes
- Payment provider credentials: PayPal Client ID and Client Secret, Tranzila terminal credentials, and any related configuration you enter. Sensitive portions are encrypted at rest using ASP.NET Data Protection
- Project data: project names, descriptions, logos, plans, tiers, pricing, trial settings, webhook URLs, license cache secrets, and other project configuration
- API keys & OAuth data: we issue API keys (stored only in hashed form after creation), OAuth authorization codes (short-lived), OAuth access and refresh tokens, and client IDs for MCP integrations
- Support & communications: messages, attachments, and contact form submissions you send to us, including email threads
4.2 End-User / Subscriber Data (Processor Role)
When a developer uses PayVia, we process the following data about their end-users, strictly on the developer's behalf and under their instructions:
- Customer identifiers: email address, external user ID as provided by the developer, display name (optional)
- Subscription data: plan selection, tier, subscription status, trial status, trial expiry, cancellation timestamp, current period end, renewal history
- Payment metadata: payment provider subscription ID, payment timestamps, amounts, currency, and failure reasons. We do not receive or store cardholder data - all raw card data is handled exclusively by PCI-DSS compliant payment providers (PayPal, Tranzila)
- License validation logs: timestamp, action type (
LICENSE_CHECK, LICENSE_RESET, LICENSE_CANCEL), result (ACTIVE, INACTIVE, RESET, CANCELED), matching plan IDs, and customer identifier, stored as extension audit logs - Webhook events: raw payloads from payment providers (for example,
BILLING.SUBSCRIPTION.ACTIVATED, PAYMENT.SALE.COMPLETED) stored for idempotent processing and debugging
4.3 Automatically Collected Data
- Usage data: pages viewed, features used, API calls made, timestamps, and interaction patterns within the dashboard
- Device information: browser type and version, operating system, screen resolution, language preference, user agent string
- Network data: IP address, approximate location derived from IP (country/region level only - we do not perform precise geolocation)
- Session data: session identifiers, JWT tokens, cookie consent preferences, and login timestamps
- Error & diagnostic data: stack traces, error codes, and request metadata captured when something goes wrong, used to debug and improve the Services
5. How We Use Your Information
- Service delivery: to provide, maintain, and operate the PayVia platform, process subscriptions, validate licenses, deliver webhooks, and route transactions through your payment provider
- Authentication & account security: to verify your identity, issue and rotate tokens, detect unusual sign-in activity, and protect your account
- Communications: to send essential service notifications, security alerts, policy updates, and account-related messages. We will not send you marketing emails without your consent
- Customer support: to respond to your questions, troubleshoot issues, and investigate reported incidents
- Audit & compliance: to maintain audit logs for license validation, payment processing, webhook events, and dashboard actions for debugging, fraud detection, and regulatory compliance
- Security & fraud prevention: to detect, prevent, and respond to abuse, account takeover, credential stuffing, fraudulent chargebacks, and violations of our Terms of Service
- Service improvement: to understand usage patterns, measure feature adoption, and improve the reliability, performance, and usefulness of the Services (using aggregated and de-identified data wherever possible)
- Legal compliance: to comply with applicable laws, tax obligations, law enforcement requests, court orders, and to establish, exercise, or defend legal claims
6. Legal Bases for Processing (GDPR / UK GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6(1) of the GDPR / UK GDPR:
- Performance of a contract (Art. 6(1)(b)): to provide the Services you signed up for, including account creation, payment orchestration, subscription management, license validation, and customer support
- Legitimate interests (Art. 6(1)(f)): to secure our platform, prevent fraud and abuse, maintain audit logs, improve the Services, and conduct routine business administration. We balance our legitimate interests against your rights and freedoms
- Consent (Art. 6(1)(a)): for non-essential cookies, optional analytics, marketing communications (where applicable), and any processing where consent is the appropriate basis. You can withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, anti-money-laundering, and other laws that require us to keep certain records or respond to lawful requests
- Vital interests or public interest (Art. 6(1)(d) & (e)): in rare cases, to protect the vital interests of a person or in the public interest
For end-user / subscriber data that we process as a processor on behalf of developers, the lawful basis is determined by the developer as the controller. Developers are responsible for obtaining appropriate consent and providing privacy notices to their own users.
7. How We Share Information
We may share your information with the following categories of recipients:
- Payment providers (PayPal, Tranzila): to route transactions, create and cancel subscriptions, and process refunds on your behalf. Each provider has its own privacy policy and terms
- Google (only during Sign-In): if you choose to sign in with Google, we send no personal data to Google beyond what the Google Identity Services SDK requires to authenticate you. We do not share data with Google for advertising or profiling
- Infrastructure & service providers (sub-processors): our hosting, email, and operational partners. See Section 8 for the current sub-processor list
- Professional advisers: our lawyers, accountants, and auditors under confidentiality obligations
- Law enforcement & regulators: when required by valid legal process, such as a court order or subpoena, or when we believe in good faith that disclosure is necessary to comply with law, protect our rights, prevent imminent harm, or investigate fraud or abuse
- Successors in interest: in connection with a merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to confidentiality and with notice where required
- Your own end-user data back to you (the developer): PayVia returns aggregated and individual subscriber data to the developer who owns the relevant project, through the dashboard and API
We do not sell, rent, trade, or "share" (as defined by the California CPRA) your personal information for cross-context behavioral advertising or for monetary or other valuable consideration.
8. Sub-processors
We use the following sub-processors to help us deliver the Services. Each sub-processor is bound by a data processing agreement that requires them to protect your data and use it only for the purposes we direct:
| Sub-processor | Purpose | Location |
|---|
| PayPal | Payment processing, subscription lifecycle, webhooks | United States / Global |
| Tranzila | Payment processing (primarily Israeli market) | Israel |
| Google LLC | Google Sign-In (Identity Services) | United States |
| MTA Cloud | Production API hosting (IIS / Windows Server) | Israel |
| Vercel | Dashboard frontend hosting and edge delivery | United States / Global CDN |
| Anthropic | Optional AI-powered support tools (processed only on developer request) | United States |
This list may change as we evolve our infrastructure. Material changes to our sub-processor list will be announced on this page and, for existing customers, by email or in-dashboard notice at least fourteen (14) days before the change takes effect, so that you can raise any concerns.
9. Data Storage, Security & Technical Measures
We implement appropriate technical and organizational measures to protect your data, including:
- Password storage: passwords are hashed using bcrypt with a per-user salt and are never stored in plain text
- API keys & OAuth secrets: API keys are hashed after generation; OAuth client secrets are stored securely and are never shown in plain text after issuance
- Transport encryption: all traffic between clients and PayVia is encrypted over TLS (HTTPS), using modern cipher suites
- Encryption at rest: sensitive credentials (Tranzila tokens, PayPal Client Secrets) are encrypted at rest using ASP.NET Data Protection; encryption keys are managed separately from the database
- License cache anti-tamper: license validation responses include an HMAC-SHA256 signature generated with a per-project secret, so that tampering with a cached response is detectable
- Access controls: access to production systems is restricted to authorized personnel, protected by strong authentication, and logged for audit purposes
- Backups: we take regular database backups and store encryption key backups separately to ensure that encrypted data can be recovered
- Monitoring & logging: we monitor the Services for security events, anomalies, and abuse, using Windows Event Log and application-level audit trails
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will respond as described in Section 11.
10. Data Retention
We retain data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law. Typical retention periods are:
| Data category | Retention period |
|---|
| Account profile data | Life of the account; deleted within 30 days after account closure |
| Transaction & payment records | Up to 7 years, as required by tax and financial regulations |
| Extension audit logs (license checks) | 12 months from creation |
| Webhook event payloads | 90 days |
| Database backups | Up to 90 days before being overwritten or deleted |
| Server logs & diagnostics | Up to 30 days |
| Support & email correspondence | Up to 3 years after last contact |
| Aggregated & de-identified statistics | Indefinitely (no longer personal data) |
When personal data is no longer needed, we delete or anonymize it in accordance with our internal data retention schedule.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, as required by Article 33 of the GDPR. If the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly, without undue delay, in accordance with Article 34. We will describe the nature of the breach, the categories and approximate number of people affected, the likely consequences, and the measures we have taken or propose to take in response.
12. Cookies & Local Storage
We use a small number of cookies and browser storage mechanisms. You can manage your preferences through our cookie consent banner on first visit, or at any time by clearing your browser storage. Cookies we use fall into these categories:
| Category | Purpose | Consent |
|---|
| Essential | Authentication (JWT), session management, CSRF protection, cookie-consent state | Always active; cannot be disabled |
| Functional | Remembering your preferences (theme, language) | Opt-in |
| Analytics | Understanding how visitors use the dashboard so we can improve it | Opt-in |
| Marketing | Attribution for referrals and promotional campaigns | Opt-in |
Cookie consent is remembered for twelve (12) months, after which you will be prompted again. You may also change your preferences at any time through your browser settings. We currently do not respond to browser "Do Not Track" signals, because there is no common industry standard for interpreting them.
SDK Local Storage (End-Users)
The PayVia SDK stores a license validation cache on end-user devices, using Chrome extension storage (chrome.storage.local) or browser localStorage. Cached data includes subscription status, tier information, plan IDs, an isTrial flag, a timestamp, and an HMAC signature used to detect tampering. No personal identifiers beyond the customer ID are stored. The cache has a seven (7) day TTL and an additional thirty (30) day offline grace window. It is used strictly to validate licenses when the device is offline or when the network is unreachable.
13. Your Privacy Rights
Subject to your jurisdiction, you may have some or all of the following rights regarding your personal data:
- Right of access (GDPR Art. 15): request a copy of the personal data we hold about you, together with information about how we process it
- Right to rectification (Art. 16): ask us to correct inaccurate or incomplete data
- Right to erasure / "right to be forgotten" (Art. 17): request deletion of your account and associated personal data, subject to legal retention obligations
- Right to restriction of processing (Art. 18): ask us to limit how we use your data in certain circumstances
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format (CSV export is available for subscriber data)
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: withdraw any consent you have previously given, at any time, without affecting the lawfulness of prior processing
- Right not to be subject to automated decision-making (Art. 22): we do not make solely automated decisions that produce legal or similarly significant effects about you
- Right to lodge a complaint: complain to your local data protection supervisory authority (for EU/UK residents). We would, however, appreciate the chance to resolve your concerns directly first
To exercise your rights, email us at payvia@asia-digital.online. We will respond within thirty (30) days, or explain any delay if the request is complex. We may need to verify your identity before fulfilling certain requests.
If you are an end-user of a developer that uses PayVia, please contact that developer first - they are the controller of your subscription data and are best positioned to handle your request.
14. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA") provides you with specific rights regarding your personal information:
- Right to know what personal information we collect, use, disclose, and (if applicable) sell or share
- Right to delete personal information we have collected from you, subject to certain exceptions
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information. PayVia does not sell personal information and does not share it for cross-context behavioral advertising. Therefore, we do not need to provide a "Do Not Sell or Share My Personal Information" link
- Right to limit use of sensitive personal information. We do not use sensitive personal information for any purpose beyond providing the Services you requested
- Right to non-discrimination for exercising any of the above rights
Categories of personal information we have collected in the past 12 months: "Identifiers" (email, account ID), "Commercial information" (subscription and billing history), "Internet or other electronic network activity information" (usage logs, device info), and "Professional or employment information" (company name, role, where provided). We collect this information for the purposes described in Section 5 and disclose it as described in Section 7.
To exercise your CCPA rights, email payvia@asia-digital.online. You may also designate an authorized agent to make a request on your behalf, subject to our verification of the agent's authority.
15. Other US State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other US states with comprehensive privacy laws have additional rights, including the right to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. PayVia does not engage in targeted advertising, sell personal data, or perform profiling that produces legal or similarly significant effects. To exercise rights under your state's law, contact us using the details in Section 3.
16. Children's Privacy
PayVia is a B2B service intended for developers aged 18 and older. The Services are not directed to children, and we do not knowingly collect personal information from children under 16 (or the higher age required by applicable local law). If you are a parent or legal guardian and believe that a child has provided us with personal information, please contact us and we will take reasonable steps to delete it. Developers using PayVia must ensure that their own applications comply with applicable children's privacy laws, including the US Children's Online Privacy Protection Act (COPPA) and the UK Age-Appropriate Design Code.
17. International Data Transfers
PayVia is operated from Israel, and our primary production infrastructure is located in Israel. Some of our sub-processors are located in the United States and other countries. This means that your personal data may be transferred to, stored in, or processed in countries whose data protection laws differ from those of your country of residence.
We rely on the following mechanisms to lawfully transfer personal data internationally:
- Adequacy decision (Israel): Israel has been recognized by the European Commission as providing an adequate level of data protection, so transfers from the EU/EEA to Israel do not require additional safeguards
- Standard Contractual Clauses (SCCs): for transfers to sub-processors in countries without an adequacy decision, we use the EU Commission's Standard Contractual Clauses (2021/914) and, where applicable, the UK International Data Transfer Addendum and the Swiss addendum
- EU-US Data Privacy Framework (DPF): where a US sub-processor is certified under the DPF, we also rely on that certification
- Supplementary measures: we apply appropriate technical measures (encryption in transit and at rest, access controls) and organizational measures to protect transferred data
You may request a copy of the relevant transfer safeguards by contacting us at the address in Section 3.
18. Google User Data (Limited Use Disclosure)
PayVia's use and transfer of information received from Google APIs, through the Google Sign-In feature, adhere to the Google API Services User Data Policy, including the Limited Use requirements:
- We use Google user data (ID, email, display name) only to create or log into your PayVia account, and to match your Google identity to an existing account if the email addresses match
- We do not use Google user data to serve ads, for retargeting, or for credit-worthiness determinations
- We do not transfer Google user data to third parties, except as necessary to provide the Services, comply with law, or in connection with a business transfer, and only under appropriate confidentiality terms
- We do not allow humans to read Google user data unless: (a) we have your explicit consent, (b) it is necessary for security purposes (such as investigating abuse), (c) it is required by law, or (d) the data is aggregated and used for internal operations in line with applicable policies
- You may revoke PayVia's access to your Google account at any time via your Google account permissions page
19. Automated Decision-Making
PayVia does not make decisions based solely on automated processing that produce legal or similarly significant effects about you, within the meaning of GDPR Article 22. We use automated tooling for routine tasks like spam detection, rate limiting, and fraud screening, but human review is available where such tooling materially affects your account.
20. Third-Party Links
The Services may contain links to third-party websites or services (for example PayPal, Tranzila, Google, or an external blog post). We are not responsible for the privacy practices of those third parties. We encourage you to review their own privacy policies before providing them with your information.
21. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our sub-processors, applicable law, or the Services themselves. Material changes will be communicated at least fourteen (14) days in advance via email to your registered account address and through a prominent notice in the dashboard. Non-material updates will be reflected in the "Last updated" date at the top of this page. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
22. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at payvia@asia-digital.online or visit our contact page.