1. Introduction
TaraPayments ("we", "our", or "us") is a Philippine payment gateway integration built for GoHighLevel users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read this policy carefully. If you disagree with its terms, please discontinue use of the service.
2. Information we collect
We may collect the following types of information:
- Account information — Name, email address, business name, and GoHighLevel account details provided during onboarding.
- Payment credentials — Your Xendit API keys, which are encrypted at rest and never exposed client-side.
- Transaction data — Payment amounts, method used, timestamps, and transaction status forwarded from Xendit's infrastructure.
- Usage data — Log data, IP addresses, browser type, and pages accessed within the TaraPayments dashboard.
- Customer data — Information about your end customers that passes through payment flows (name, email, phone) as necessary to process transactions.
3. How we use your information
We use the information we collect to:
- Process and route payments through Xendit's BSP-regulated infrastructure
- Trigger GoHighLevel automations and workflow events on successful payments
- Send payment receipts and transaction notifications
- Provide customer support and respond to inquiries
- Monitor service performance, detect fraud, and ensure security
- Comply with applicable Philippine laws and BSP regulations
- Improve our service through aggregated, anonymized analytics
4. How we share your information
We do not sell your personal information. We may share data with:
- Xendit — Our payment infrastructure partner. All transactions are processed through Xendit's BSP-licensed platform. Xendit's own privacy policy governs their data handling.
- GoHighLevel — Payment events and contact data are transmitted to your GHL account via webhooks per your configuration.
- Service providers — Third-party vendors who assist with hosting, monitoring, and support, bound by confidentiality agreements.
- Legal authorities — When required by law, court order, or BSP/government directive.
5. Data security
We implement industry-standard security measures to protect your information:
- Xendit API keys are encrypted at rest using AES-256 encryption
- All data in transit is protected via TLS 1.2 or higher
- Server access is restricted to authorized personnel only
- We do not store full card numbers, CVVs, or raw payment credentials
No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Data retention
We retain your account and transaction data for as long as your subscription is active and for a period of five (5) years thereafter, as required by Philippine financial regulations. You may request deletion of your personal data by contacting us, subject to our legal retention obligations.
7. Your rights
Under applicable Philippine data privacy laws (Republic Act 10173 — Data Privacy Act of 2012), you have the right to:
- Be informed about how your data is processed
- Access a copy of your personal data we hold
- Correct inaccurate or incomplete data
- Request erasure of your data (subject to legal limitations)
- Object to or restrict certain types of processing
- Lodge a complaint with the National Privacy Commission (NPC)
To exercise any of these rights, contact us at support@payments.taraai.ph.
8. Cookies and tracking
TaraPayments uses essential cookies to maintain session state and authentication. We do not use third-party advertising or tracking cookies. You may disable cookies in your browser settings, though this may affect service functionality.
9. Third-party links
Our service may contain links to third-party websites including GoHighLevel and Xendit. We are not responsible for the privacy practices of those sites and encourage you to review their respective privacy policies.
10. Children's privacy
TaraPayments is a business-to-business service and is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice in the dashboard. Continued use of the service after changes constitutes acceptance of the updated policy.
12. Contact us
For privacy-related questions or requests, contact us at: