legal

Privacy Policy

What we collect, why we collect it, and how we use it when you use SkyPay — so you (and your customers) can review it in one place.

Last updated: October 8, 2026

1. Introduction

SkyPay is a Nepal payment gateway product operated by Skybase Innovations Pvt. Ltd. (“we”, “us”, or “our”), based in Pokhara, Nepal. This Privacy Policy explains how we collect, use, disclose, and protect information when you use SkyPay, including:

  • Our marketing and documentation site at skypay.dev
  • The merchant dashboard and checkout at app.skypay.dev
  • The SkyPay Business mobile app and Flutter SDK (skypay_sdk)
  • Our APIs, webhooks, and support channels

This policy applies to merchants, developers, end customers who pay through SkyPay checkout, and website visitors. We use personal information to provide and improve SkyPay. We do not sell your personal information.

For company information about the operator, see skybase.com.np.

2. Information We Collect

Depending on how you use SkyPay, we collect the categories below. You may choose not to provide certain information; that may prevent you from registering or using some features (for example Live payments require KYC).

2.1 Account information of merchants

When you create or manage a SkyPay merchant account, we collect:

  • Name, email address, and phone number
  • Password (stored hashed; we never store it in plain text)
  • Account type (individual or business), business/organization name, business type, and optional legal registration details you provide
  • Profile avatar (if you upload one)
  • Workspace preference (Live or Test mode)
  • Login timestamps and last login IP address

2.2 Know Your Customer (KYC) information

To unlock Live payments and meet compliance needs, we may collect identity and business verification information you submit, such as:

  • Identity details — full name, date of birth, nationality, citizenship or passport number, address, city, country, and contact details
  • Business details — registered name, type, registration number, address, VAT/PAN where provided, website, and related business profile information
  • Supporting documents you upload — for example identity document images, business registration, bank statements, tax documents, or other files required for verification
  • Verification status, review notes, and related compliance flags

We collect only what is needed for account verification and Live access. We do not use KYC documents for advertising.

2.3 Settlement and bank details

When you request settlements or configure payout details, we may collect bank name, account holder name, account number, branch, and related settlement references and notes needed to process payouts.

2.4 Payment and transaction data

When payments are created or processed through SkyPay, we collect:

  • Transaction metadata — amounts, currency, order/reference codes, payment status, mode (Manual, API, or Assisted), timestamps, and fee/commission breakdowns where applicable
  • Payment method / provider selected (for example eSewa, Khalti, Connect IPS, Fonepay, or manual bank transfer)
  • Success and failure redirect URLs you configure
  • Provider transaction or reference IDs returned by payment rails
  • Whether the payment is a Test/sandbox or Live transaction

Payment instrument secrets (full card numbers, wallet PINs, OTP codes, and similar) are handled by the relevant payment provider. SkyPay does not store those secrets. We may store encrypted merchant API credentials you connect for API Mode, and configuration needed to run Manual or Assisted checkout.

2.5 End-customer information

If a merchant collects customer details through SkyPay (for example on an order or checkout form), we may process information such as customer name, email, phone, address, city, and order notes. Merchants decide what they ask customers for. Where we process that data to provide checkout and order tools, the merchant remains responsible for telling their customers why it is collected and for using it lawfully.

2.6 API, webhook, and product usage

  • API keys (secrets hashed; prefixes and usage metadata retained)
  • Webhook endpoint URLs, encrypted signing secrets, subscribed events, and delivery logs
  • Connected payment-provider settings and preferences
  • Products, orders, and prepaid balance / statement activity in your account

2.7 Device, log, and technical data

  • IP address, browser or app client type, and request timestamps
  • Device push token (FCM) when you enable notifications in the Business app
  • Agreement acceptance records (including IP address, user agent, and content hash) when you accept SkyPay agreements
  • Payment and system diagnostic logs (including request/response metadata needed to debug and secure payments)

2.8 Communications

Emails, OTPs, in-app notifications, and messages you send to support (for example via [email protected]), plus related metadata needed to respond and keep an audit trail of service notices.

We do not operate SkyPay as an advertising or AdMob-focused product. We do not collect information for the purpose of serving interest-based ads through SkyPay. Our public website does not use third-party advertising or visitor analytics pixels.

3. How We Use Information

We use the information we collect to:

  • Create and manage merchant accounts, authentication, and access controls
  • Provide checkout, payment verification, webhooks, dashboard, SDKs, and the Business app
  • Complete KYC review and unlock Live payment features
  • Process settlements, balance top-ups, and related financial records
  • Send transactional notices (for example payment status) via email or push notification
  • Detect, prevent, and investigate fraud, abuse, and security incidents
  • Provide customer and developer support
  • Improve reliability, performance, documentation, and product features
  • Comply with applicable laws, regulations, accounting needs, and lawful requests

4. How We Share Information

We may share information only as needed to operate SkyPay:

  • Payment providers and banks — when you or your customers use a method such as eSewa, Khalti, Connect IPS, Fonepay, or bank transfer, those providers process data under their own policies
  • Service providers — hosting, email delivery, push-notification infrastructure, and similar vendors who process data only on our instructions
  • Merchants — end-customer and payment data related to that merchant’s transactions, so they can fulfill orders and reconcile payments
  • Legal and safety — when required by law, regulation, court order, or to protect rights, security, and integrity of SkyPay and our users

We do not sell personal information to advertisers or data brokers.

5. Payment Providers and Third Parties

SkyPay routes and orchestrates payments across Nepal payment rails. When a specific method is used, information may be processed by that provider. Customers and merchants may also be subject to the policies of the payment method they choose. SkyPay does not control how independent providers handle data on their platforms.

6. Cookies and Similar Technologies

We use cookies and similar technologies for essential purposes such as session authentication, security, and remembering preferences (for example theme or UI settings). They are not used by SkyPay to run third-party advertising networks.

You can control cookies through your browser settings. Disabling certain cookies may limit access to authenticated areas such as the merchant dashboard.

7. Data Retention

We retain information for as long as needed to provide SkyPay, meet legal and accounting obligations, resolve disputes, and enforce our agreements. Account, KYC, and transaction records may be kept for longer periods where required for fraud prevention, audit, tax, or regulatory compliance (often several years for financial records). When retention is no longer necessary, we take steps to delete or anonymize data where practicable.

8. Security

We use commercially reasonable safeguards appropriate to a payment service — including encryption of sensitive merchant credentials at rest, hashed API keys and passwords, and access controls. No method of transmission over the Internet or electronic storage is 100% secure. Please use strong passwords, protect your API keys, and always verify payments on your server before fulfilling orders.

9. Your Choices and Account Deletion

  • You can update profile details from your SkyPay dashboard.
  • You can disable push notifications in the Business app or device settings.
  • To permanently delete your merchant account, follow Delete account.

10. Links to Other Sites

Our Service may contain links to third-party sites or services (including payment providers and the Skybase company website). If you follow an external link, you leave SkyPay’s control. We strongly advise you to review the privacy policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.

11. Children’s Privacy

SkyPay is not directed to anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we learn that a child under 13 has provided us with personal information, we will take steps to delete that information from our systems. If you are a parent or guardian and believe your child has provided personal information to us, please contact us at [email protected].

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes are effective when posted on this page. We encourage you to review this page periodically. The “Last updated” date at the top of this page will reflect the latest revision.

13. Contact Us

Questions about this Privacy Policy or what we collect: