We handle your payment data like it's ours.

Oyaka reads data from your gateway, processor and alert provider. Here is exactly what we see, what we store and how we protect it.

What we never store

  • Full card numbers or security codes
  • Bank account or routing numbers
  • Your customers' passwords or logins

We match records using the last four digits of a card, the amount and the date. That keeps full card data out of our systems entirely.

What we do store

  • Transaction amounts, dates and IDs
  • Chargeback and alert details
  • Fees, deposits and the evidence you submit
  • Your API keys, encrypted and never shown again

Encrypted everywhere

Data is encrypted in transit (TLS 1.2 or newer) and at rest. API keys get an extra layer of encryption with keys managed in AWS.

Read-only where possible

We ask for the narrowest access each system allows. Refunds and dispute submissions only happen when someone on your team clicks the button.

Every action logged

Every refund, dispute and settings change is recorded with who did it and when. Owners can review the full history.

Two-factor sign-in

Required for every user, with roles so only the right people can move money.

Your data stays separate

Every record is tied to one merchant account, and every request is checked against it. Disconnect and export at any time.

Hosted on AWS in the US

Private networks, daily backups kept for 14 days, and monitoring that alerts our team to failures.

Compliance

SOC 2 Type I audit planned for [DATE]. Need our security questionnaire answered or a data processing agreement? We'll send them.

Contact security