Privacy Policy
Last updated: 01/07/2026
1. Introduction
This Privacy Policy explains how Quickpay.ge and Landingpage.ge (together, the "Services", "Platform", "we", "us") collect, use, and protect personal data belonging to merchants, their customers, and website visitors. By using the Services, you agree to the practices described here.
2. What We Collect
Merchant account data: name, email, phone, business details, brand information, gateway credentials (encrypted), API keys (hashed), and billing information.
Customer/end-buyer data, collected on behalf of merchants during checkout: name, email, phone, delivery address, and order details (product, amount, custom checkout fields). This data belongs to the merchant's business relationship with their customer; we process it as the merchant's service provider.
Lead data, collected via landing pages: name, contact details, and any custom fields configured by the merchant on that page.
Technical data: IP address, browser/device information, and analytics events collected for fraud prevention, security, and to power the analytics dashboard.
We never collect or store full card numbers, CVV, or other card data — all card handling takes place directly at the connected payment gateway (BOG, TBC, Credo, etc.), never on our servers.
3. How We Use Data
We use collected data to: operate and improve the Services; process payments by routing requests to the payment gateway you connect; deliver webhooks and notifications; provide customer support; detect and prevent fraud and abuse; send transactional emails/SMS (receipts, OTPs, order updates); and, where you have opted in, send product updates and marketing communications.
4. Legal Basis for Processing
We process personal data on the basis of: performance of a contract (providing the Services to merchants and facilitating their transactions with customers), legitimate interest (fraud prevention, security, service improvement), consent (marketing communications, optional cookies), and compliance with legal obligations (tax and financial record-keeping).
5. Sharing of Data
We share data with: the payment gateways you connect (to process transactions), SMS and email delivery providers (to send notifications), Cloudflare (CDN, DNS, storage), and, where legally required, government or regulatory authorities. We do not sell personal data to third parties.
6. Data Retention
Payment records (transaction IDs, amounts, statuses) are retained indefinitely for accounting and dispute purposes. Detailed request/response logs from payment gateways are purged after 90 days. Customer and lead data is retained for as long as the merchant's account is active, or as required by law, and deleted upon a valid deletion request where no legal retention obligation applies.
7. Security
Gateway credentials and sensitive fields are encrypted at rest. All traffic to the hosted payment page (qpy.ge) is served over HTTPS with HSTS enabled. Access to production data is restricted to authorized personnel, and administrative "login as merchant" actions are logged with full audit trail.
8. Cookies
We use essential cookies required for authentication and session management, and, where enabled, analytics cookies (e.g. for conversion tracking configured by a merchant on their own checkout). You can control non-essential cookies through your browser settings.
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Merchants can manage most of this directly from their dashboard; customers and leads can contact the merchant they transacted with, or reach us directly, to exercise these rights.
10. International Data Transfers
Some of our infrastructure and sub-processors (e.g. Cloudflare) may process data outside Georgia. Where this occurs, we rely on the sub-processor's own security and compliance commitments to protect the data in transit and at rest.
11. Children's Privacy
The Services are not directed at individuals under 18, and we do not knowingly collect personal data from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the dashboard or email. Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
13. Contact
For privacy questions or to exercise your data rights, contact us at [email protected].
This Privacy Policy explains how Quickpay.ge and Landingpage.ge (together, the "Services", "Platform", "we", "us") collect, use, and protect personal data belonging to merchants, their customers, and website visitors. By using the Services, you agree to the practices described here.
2. What We Collect
Merchant account data: name, email, phone, business details, brand information, gateway credentials (encrypted), API keys (hashed), and billing information.
Customer/end-buyer data, collected on behalf of merchants during checkout: name, email, phone, delivery address, and order details (product, amount, custom checkout fields). This data belongs to the merchant's business relationship with their customer; we process it as the merchant's service provider.
Lead data, collected via landing pages: name, contact details, and any custom fields configured by the merchant on that page.
Technical data: IP address, browser/device information, and analytics events collected for fraud prevention, security, and to power the analytics dashboard.
We never collect or store full card numbers, CVV, or other card data — all card handling takes place directly at the connected payment gateway (BOG, TBC, Credo, etc.), never on our servers.
3. How We Use Data
We use collected data to: operate and improve the Services; process payments by routing requests to the payment gateway you connect; deliver webhooks and notifications; provide customer support; detect and prevent fraud and abuse; send transactional emails/SMS (receipts, OTPs, order updates); and, where you have opted in, send product updates and marketing communications.
4. Legal Basis for Processing
We process personal data on the basis of: performance of a contract (providing the Services to merchants and facilitating their transactions with customers), legitimate interest (fraud prevention, security, service improvement), consent (marketing communications, optional cookies), and compliance with legal obligations (tax and financial record-keeping).
5. Sharing of Data
We share data with: the payment gateways you connect (to process transactions), SMS and email delivery providers (to send notifications), Cloudflare (CDN, DNS, storage), and, where legally required, government or regulatory authorities. We do not sell personal data to third parties.
6. Data Retention
Payment records (transaction IDs, amounts, statuses) are retained indefinitely for accounting and dispute purposes. Detailed request/response logs from payment gateways are purged after 90 days. Customer and lead data is retained for as long as the merchant's account is active, or as required by law, and deleted upon a valid deletion request where no legal retention obligation applies.
7. Security
Gateway credentials and sensitive fields are encrypted at rest. All traffic to the hosted payment page (qpy.ge) is served over HTTPS with HSTS enabled. Access to production data is restricted to authorized personnel, and administrative "login as merchant" actions are logged with full audit trail.
8. Cookies
We use essential cookies required for authentication and session management, and, where enabled, analytics cookies (e.g. for conversion tracking configured by a merchant on their own checkout). You can control non-essential cookies through your browser settings.
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Merchants can manage most of this directly from their dashboard; customers and leads can contact the merchant they transacted with, or reach us directly, to exercise these rights.
10. International Data Transfers
Some of our infrastructure and sub-processors (e.g. Cloudflare) may process data outside Georgia. Where this occurs, we rely on the sub-processor's own security and compliance commitments to protect the data in transit and at rest.
11. Children's Privacy
The Services are not directed at individuals under 18, and we do not knowingly collect personal data from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the dashboard or email. Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
13. Contact
For privacy questions or to exercise your data rights, contact us at [email protected].