Privacy Policy
Last updated 2 August 2026
In short: we collect the account details you sign up with, the store settings you configure, and a record of each payment you create through us. We never see or store your customers' banking credentials, and we never hold your money — payments settle directly into your own bank account. We do not sell your data or your customers' data to anyone.
1. Who we are
CutLuy ("we", "us") operates cutluy.com, a developer platform for accepting Bakong KHQR payments in Cambodia. This policy explains what we do with personal data when you use the dashboard, the API, or a checkout page we host on a merchant's behalf.
For questions about this policy or your data, contact [email protected].
2. What we collect
Account data. You sign in with Google, and we receive your name, email address, and profile picture from that sign-in. We never receive your Google password. We also store a session cookie so you stay signed in.
Store settings. Whatever you configure for each store: its name, logo, brand colour, support email, redirect URLs, and the payment link you connect. Logos you upload are stored in our object storage and served back through cutluy.com.
Payment records. For each payment you create: the amount, currency, status, the QR payload, timestamps, the transaction reference returned by our banking partner, and any reference_id or metadata you attach. Metadata is free-form and supplied entirely by you — see the warning in section 4.
Integration data. Your webhook endpoint URLs, their signing secrets, and a log of delivery attempts including the response status we received from your server. API keys are stored only as a SHA-256 hash — the full key is shown once, at creation, and cannot be recovered by us or by you afterwards.
Operational logs. Ordinary server logs (request paths, status codes, timings) and, where an operator acts on an account through our internal console, an audit record of what was changed and by whom.
3. Your customers (payers)
When someone pays through a CutLuy checkout page, they scan a KHQR code with their own banking app. That authentication and authorisation happens entirely between the payer and their bank.
- We do not receive, request, or store payer bank credentials, card numbers, PINs, or one-time passcodes.
- We receive a transaction reference and a status (pending, scanned, paid, expired, failed) from our banking partner, and store those against the payment.
- We never take custody of funds. Money moves directly from the payer to the merchant's own bank account via the merchant's own payment link.
If a merchant chooses to attach personal data about their customer to a payment's metadata, that data reaches us because the merchant sent it — see section 4.
4. Metadata is your responsibility
The metadata and reference_id fields are stored as you send them and returned to you unchanged. We do not inspect, filter, or redact them.
Do not put sensitive personal data in these fields — no national ID numbers, card numbers, health information, or credentials. If you choose to include personal data about your customers, you are the controller of that data and are responsible for having a lawful basis to collect it and for telling your customers you are doing so.
5. Why we use it
- To operate your account, stores, and hosted checkout pages.
- To create payments, poll their status, and deliver signed webhooks to your endpoints.
- To count transactions against your plan's quota and to bill you for a paid plan.
- To keep the service secure — investigating abuse, fraud, and technical faults.
- To meet legal obligations, including responding to lawful requests from Cambodian authorities.
We do not sell personal data, and we do not use your payment data or your customers' data for advertising or profiling.
7. How long we keep it
Account and store data is kept while your account is open. Payment and webhook delivery records are kept while your account is open and for a period afterwards where we need them for accounting, tax, dispute, or anti-money-laundering purposes.
Operator audit records are kept even if the account they refer to is deleted — an audit log that can be erased by deleting its subject is not an audit log.
8. Security
Traffic to cutluy.com is encrypted in transit. API keys are stored hashed, never in plaintext. Webhook payloads are signed with a per-endpoint secret so your server can verify they came from us — you should always verify that signature. Image storage is private and served only through the application.
No system is perfectly secure. Keep your API keys secret, rotate them if you suspect exposure, and tell us promptly at [email protected] if you believe your account has been compromised.
9. Your choices and rights
- Access. Your payments, webhook deliveries, and settings are visible in the dashboard and readable through the API at any time.
- Correction. You can edit your store settings yourself; email us for anything you cannot change.
- Deletion. Email us to close your account. We will delete or anonymise your data except where we must keep records for the reasons in section 7.
- Revocation. You can revoke any API key and disable any webhook endpoint immediately from the dashboard.
11. Children
CutLuy is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact us and we will remove it.
12. Changes to this policy
We may update this policy as the service changes. The "last updated" date above always reflects the current version, and we will give notice of material changes by email or in the dashboard. Continuing to use CutLuy after a change means you accept the updated policy.
See also our Terms & Conditions.