Privacy Policy

Last Updated: July 13, 2026

1. Introduction

This Privacy Policy explains how SSLPay Gateway ("the App") collects, uses, and protects information when you connect it to your CRM account as a Custom Payment Provider powered by SSLCommerz.

2. Information We Collect

  • CRM Account Information:OAuth access/refresh tokens and your location ID, obtained when you install the App from your CRM's app marketplace.
  • SSLCommerz Store Credentials: Your Store ID and Store Password, which you provide via the App's Settings page. The password is encrypted at rest (AES-256-GCM) before storage and is never displayed back to you or anyone else in plaintext.
  • Transaction Records: Payment amounts, currency, card/payment method type, SSLCommerz transaction and bank reference IDs, and status, for each payment processed through your store.
  • Webhook & API Logs: Raw request payloads sent by your CRM platform and SSLCommerz, retained for troubleshooting and audit purposes.

3. How We Use Your Information

We use this information solely to operate the payment integration: to process checkouts, verify and refund transactions, manage subscriptions, and keep your CRM account and SSLCommerz store in sync. We do not sell or share your data with third parties for marketing purposes.

4. Data Storage & Security

Data is stored in a PostgreSQL database. Store passwords are encrypted at rest. Access to transaction and account data within the App is restricted to the App's operator. You can revoke the App's access to your CRM account at any time from your CRM's app marketplace.

5. Third-Party Services

Payments are processed by SSLCommerz using the credentials you provide. We do not control SSLCommerz's own data practices — refer to SSLCommerz's privacy policy for details on how they handle payment data.

6. Contact Us

If you have questions about this Privacy Policy, contact us at zeonstudiohq@gmail.com.