ePayFrançaisEnglish

Privacy policy

What the ePay counter receives when you pay, what it deliberately never keeps, and who it is passed to. Short version: enough to prove the payment happened, and nothing that could be used to spend your money.

1. Who is responsible

The operator named below decides how payment data is handled at the counter. The shop you are paying is responsible for its own handling of the same payment on its side.

ePay is a service of Arise Labs Ventures. Payment data is handled in accordance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA).

Operator
Arise Labs Ventures
Established in
Alberta, Canada
Data requests
privacy@ariselabs.co

2. What is recorded

A record is written for every payment attempt. It holds:

  • the ePay payment reference, plus the shop’s own order reference and description;
  • the amount, the currency, the payment method and the provider that executed it;
  • the payer details supplied with the payment — name, phone number, email — where the shop passed them or you entered them;
  • the status of the attempt, so the payment can be reconciled and proven later;
  • the shop’s original payment request and the provider’s response, kept as received so the payment can be proven later — with any payer secret already removed.

3. What is never kept

Visa, MasterCard and Amex payments are completed on the payment provider’s own hosted page. The card number, the expiry date and the security code are entered there and never reach the counter.

A PayCard prepaid card is the exception, and it is worth being plain about it: its card number and PIN are entered on the counter itself, then passed to PayCard to execute the payment. Neither is stored — both are removed before the payment record is written and before anything is logged.

Where a payment method collects a PIN or a one-time code — a mobile-money wallet, or a PayCard prepaid card — that value is removed before the payment record is written, before it is logged, and before the outcome is passed on to the shop. The field stays visible in the record with its value replaced by a redaction marker — the secret itself is never stored and nothing can read it back.

4. Why it is used

Only to execute the payment you asked for, to tell the shop the outcome, to reconcile and prove payments afterwards, to investigate a failed or disputed payment, and to meet accounting and anti-fraud obligations. Payment data is not sold, and it is not used to profile you or to target advertising.

5. Who it is shared with

The shop you paid, so it can match the payment to your order. The outcome is sent to the shop’s notification address. Where the shop has registered a notification key, it is sent as a signed message: an HMAC-SHA256 signature computed with a key only that shop holds, so it can verify the confirmation genuinely came from the gateway. A shop that has registered no key receives the same outcome unsigned.

The payment provider executing the payment — your mobile-money aggregator, or the card processor — receives what it needs to carry it out, and handles it under its own privacy policy.

Beyond that, data is disclosed only where the law requires it.

6. Security

Traffic to the counter is encrypted in transit. Payer secrets are stripped at the moment of writing rather than protected after the fact, and outbound notifications are signed for every shop that has registered a notification key, so that shop can tell a genuine payment confirmation from a forged one.

7. How long it is kept

Payer personal data — phone number, email address, name, identifiers passed back by the provider — is kept for 90 days from the moment a payment reaches its final state. After that it is deleted, or the record is anonymised.

The anonymised record of the payment itself — amount, currency, date, reference — is kept beyond that where reconciliation, accounting or the law require it. It can no longer identify you.

8. Your rights

You can ask what is held about a payment, ask for a correction, and ask for deletion where no legal retention duty stands in the way. Write to the address below with the ePay reference of the payment. A request about your order, your account with a shop or a refund has to go to the shop — they hold that, we do not.

If you are not satisfied with how a request was handled, you can take it to the Office of the Privacy Commissioner of Canada.

9. Accountable individual

The operator designates an individual accountable for compliance with this policy, as PIPEDA's first principle requires. They are reachable at the address below, which is the point of contact for any question or complaint about payment data.

Data requests
privacy@ariselabs.co

10. Cookies

The counter sets one cookie, and only if you change the language: it stores the language code you picked, for a year, so the next page comes up in the same language. There is no analytics, advertising or tracking cookie.