Privacy Policy
How we collect, use, and protect information when you use the AlliancePay Monitoring & CRM platform.
Effective date: 1 January 2026
This Privacy Policy explains how OneAI (the “Owner”) and its operating partner AlliancePay (the “Operator”) collect, use, share and protect personal information in connection with the AlliancePay Monitoring & CRM platform (the “Service”).
By using the Service or providing information to us through the marketing website, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Who we are
The Service is owned by OneAI, which contracts subscriptions and is the controller of account-level personal data.
The Service is operated day-to-day by AlliancePay, who acts as processor on behalf of subscribing organisations for the data those organisations upload or generate.
2. Information we collect
2.1 Information you give us
- Account information: name, email address, username, role and permission assignments.
- Contact information you send through our marketing website (name, company, email, message).
- Content you create within the Service: notes, cases, SAR narratives, resolution comments, uploaded documents.
2.2 Information we collect automatically
- Authentication artefacts: hashed passwords, access and refresh tokens, session identifiers.
- Access metadata: IP address, browser type, timestamps, actions performed (kept in an immutable audit log).
- Product telemetry needed to keep the Service running (health checks, error logs, background-worker events).
2.3 Information we receive from your organisation
- Merchant records, transaction data feeds, KYC documents, chargeback data and any other information a subscribing organisation elects to load into its tenant.
- Sanctions and PEP lookups against publicly available data from OpenSanctions.
3. How we use information
- To provide, maintain and secure the Service.
- To authenticate you and enforce role- and permission-based access.
- To generate monitoring alerts, watchlist entries, cases, exports and other Service outputs on behalf of your organisation.
- To respond to enquiries you send through the marketing website.
- To comply with legal obligations, including sanctions screening, anti-money-laundering rules and applicable payments regulation.
- To detect, prevent and address technical or security issues.
4. Legal bases (GDPR & similar regimes)
- Contract — to deliver the Service under your organisation's subscription with OneAI.
- Legitimate interests — to secure the Service, prevent abuse and improve product quality.
- Legal obligation — to comply with financial-services and anti-financial-crime regulation.
- Consent — where you opt in to specific communications through the marketing site.
5. How we share information
We do not sell personal information. We share information only in these situations:
- Within the platform — with authorised users of your organisation's tenant, subject to their role and permissions.
- Sub-processors — vetted infrastructure providers (cloud hosting, email delivery, sanctions data). A current list is available on request.
- Legal & regulatory — when required by law, subpoena, court order, or regulator with jurisdiction over the Owner or Operator.
- Safety & enforcement — to investigate fraud, security incidents, or Terms violations.
6. International transfers
The Service is delivered from infrastructure that may be located outside your country. Where required, we rely on Standard Contractual Clauses or equivalent safeguards to legitimise cross-border transfers.
7. Security
- Encryption in transit (TLS) for every API and email hop.
- BCrypt-hashed passwords with per-user salt.
- Short-lived JWT access tokens with rotating refresh tokens.
- Role- and permission-based access controls enforced at the API.
- Immutable audit log of privileged actions.
- Signed download URLs with 24-hour expiry for exports.
No system is perfectly secure. If you believe your account has been compromised, contact security@alliancepay.io immediately.
8. Data retention
We retain personal information for as long as your organisation's subscription is active and thereafter for the periods required by applicable law and by your organisation's regulatory obligations. Tenant data is soft-deleted rather than destroyed to preserve the audit trail; hard-deletion is available on written request from a subscribing organisation.
9. Your rights
Depending on the jurisdiction that applies to you, you may have the right to:
- Access personal information we hold about you.
- Correct inaccuracies.
- Request erasure, subject to legal and contractual retention obligations.
- Object to or restrict certain processing.
- Data portability, where technically feasible.
- Lodge a complaint with a supervisory authority.
Send rights requests to privacy@alliancepay.io.
10. Cookies
The marketing website uses strictly necessary cookies for basic functionality. The Service uses local storage to keep you signed in. We do not use third-party advertising trackers.
11. Children
The Service is not intended for individuals under 18 years of age.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated through the Service or by email to account administrators. The “Effective date” above always reflects the current version.
13. Contact
Privacy enquiries: privacy@alliancepay.io
Security disclosures: security@alliancepay.io
Legal: legal@alliancepay.io
See also our Terms & Conditions.