Privacy policy
Effective September 27, 2026
Oyaka helps businesses that accept card payments see where their money goes: settlements, refunds, chargebacks, alerts, fees and bank deposits. This policy explains what information we handle to do that, why, who we share it with and the choices you have.
1. Who this policy covers
"Oyaka," "we" and "us" mean the company that operates oyaka.com and the Oyaka service. "Merchant" means a business that signs up for Oyaka, and "you" means a merchant or a person using Oyaka on a merchant's behalf.
We handle two kinds of information. Account information is about merchants and their team members, and we decide how it's used. Merchant data is the payment and customer information a merchant brings into Oyaka by connecting its gateway, processor, alert provider and bank. We process merchant data only on the merchant's behalf and according to its instructions, as its service provider. If you bought something from a business that uses Oyaka and have a question about your information, please contact that business first; we will help them respond.
2. Information we collect
Account information you give us: your name, work email, company name, password (stored only as a secure hash), two-factor sign-in settings, team roles, notification preferences, and billing details for your Oyaka subscription (card payments for your subscription are handled by Stripe; we never see your full card number).
Merchant data from systems you connect:
- From your payment gateway (such as NMI): transaction IDs, amounts, dates, card brand, the last four digits of the card, order references, refunds and settlement batches.
- From your processor (such as PayArc): chargeback cases, reason codes, deadlines, outcomes, fees and deposit amounts.
- From your alert provider (such as Kount): alert type (RDR, CDRN, Ethoca), amount, date, the related transaction and what action was taken.
- From your bank, if you choose to connect it through Plaid: deposit and debit amounts, dates and descriptions for the connected account.
- Records you upload, such as signed customer agreements, receipts and customer messages, to use as dispute evidence.
Information we collect automatically: log data such as IP address, browser type, pages visited and actions taken in the product, which we use to keep the service secure, fix problems and keep the audit trail described below. We use only the cookies needed to keep you signed in and remember your settings. We do not use advertising cookies.
3. Information we never store
We never store full card numbers, card security codes (CVV), PINs or full bank account and routing numbers. We match records using the last four digits of a card, the amount and the date. If a connected system sends a full card number by mistake, we discard it before it is saved.
4. How we use information
- To provide the service: linking every refund, alert, chargeback and fee to its original sale, forecasting your deposit, checking it against your bank, recommending which disputes to fight and drafting dispute responses.
- To carry out actions you request, such as issuing a refund through your gateway or submitting dispute evidence to your processor. We only take these actions when a person on your team asks us to.
- To send the messages you choose, such as the daily summary and alerts about deadlines or broken connections, plus essential service and billing notices.
- To keep Oyaka secure, prevent fraud and abuse, and keep a record of who did what in each account.
- To improve Oyaka. For example, a merchant's own closed disputes improve the win estimates shown to that merchant. We may also use aggregated, de-identified statistics (which cannot identify any merchant, person or card) to improve our models and features.
- To bill for your subscription and to meet legal, tax and accounting obligations.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
5. Who we share information with
We share information only as needed to run the service:
- The systems you connect. When you issue a refund or submit dispute evidence, we send the needed details to your gateway or processor on your instruction.
- Service providers that host and operate Oyaka for us under contracts that limit their use of the information to providing services to us (listed below).
- Partners you authorize. If your payment services provider (such as an ISO) offers Oyaka to you, it can see summary numbers for your account only if you allow it. Transaction and customer details stay private unless you grant access.
- Legal and safety reasons. When required by law, subpoena or court order, or to protect the rights, property or safety of Oyaka, our customers or others.
- Business transfers. If Oyaka is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction, subject to this policy.
Service providers
We will update this list before adding a new provider that handles merchant data, and merchants on paid plans can ask to be notified of changes.
6. How long we keep information
We keep account information and merchant data for as long as the account is active. After an account is closed, we delete or de-identify merchant data within 90 days, except where we must keep specific records longer for legal, tax, accounting or dispute purposes, which is generally no longer than seven years. Backups are overwritten on a rolling basis. A merchant can ask us to delete its data sooner by contacting us.
7. How we protect information
Information is encrypted in transit (TLS 1.2 or newer) and at rest. API keys for the systems you connect get a second layer of encryption and are never displayed again after you enter them. Our database is reachable only through a private network connection. Every user must sign in with two-factor authentication, access is limited by role, and actions that move money or submit evidence are logged. No system is perfectly secure, but we work to protect your information and will notify affected merchants without undue delay if a breach affects their data. See our security page for more.
8. Your choices and rights
Merchants can view, correct, export and delete their data, disconnect any connected system at any time, and choose which notifications they receive. Team members can update their own profile and notification settings.
Depending on where you live, including California, you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, and to not be discriminated against for using these rights. To make a request, email privacy@oyaka.com. We will verify your identity before acting and respond within the time the law requires. If your information came to us as merchant data, we will pass your request to that merchant and help it respond. You may use an authorized agent, who must show us your written permission.
9. Children
Oyaka is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16.
10. Where information is processed
Oyaka is operated from the United States, and information is stored and processed in the United States.
11. Changes to this policy
If we make material changes, we will email account owners and show a notice in the product at least 30 days before the change takes effect. The effective date at the top shows when this policy last changed.
12. Contact us
Questions or requests about privacy: privacy@oyaka.com. Security concerns: security@oyaka.com.