Payment providers
How customers pay, what it costs, and when the money lands.
Card data never touches this platform. The acquirer returns a token; we store the token and the last four digits, nothing else. No PAN, no CVV, not in the database and not in logs. Credentials below are write-only - once saved, a secret can be rotated but never read back, not even here.
Aggregator: PayHere. STK push + callback.
No true pre-auth - full-amount debit then adjust. See risk register.
Aggregator: PayHere.
Acquirer: Commercial Bank. 3-D Secure enforced. Tokenised - no PAN stored.
Stored balance. Ledger-backed.
Wallet settings
Stored balance - a liability, treat it like one
Needs a saved payment token and explicit consent.
Adds AML obligations - legal review first.
Off. Expiring customer money is a policy decision, not a technical one.
Refunds & voids
Who can move money back
Operators and support can request; only finance approves. This is a spec rule, not a preference.
Would bypass the approval rule above. Leave off.
Auto-approve is set to zero, which means never. Raising it creates a path to move customer money without a second pair of eyes - if you do it, keep it small and watch the audit log.