Back
Privacy Policy
Effective Date: August 1, 2026
This Privacy Policy explains how Mara Linux and Business Solutions, Inc. ("Company", "we", "our", or "us") collects, uses, processes, stores, shares, and protects personal information in connection with the Integralink payment integration platform, including its websites, merchant portal, APIs, checkout pages, payment links, point-of-sale features, and related services (collectively, the "Platform").
Integralink is a technology and payment integration platform that enables Merchants to connect with supported third-party payment service providers, financial institutions, payment networks, and related service providers ("Payment Providers"). Depending on the payment method and integration used, certain payment information may be collected or processed directly by the applicable Payment Provider rather than stored by Integralink.
This Policy is intended to comply with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and other applicable data protection requirements.
1. Information We Collect
A. Merchant and Authorized User Information
- Full name and contact information;
- Company or business name;
- Business registration and verification information;
- Government-issued identification and tax information, where required;
- Bank or payout destination information, where applicable;
- Compliance and onboarding documents;
- Account, role, sub-account, and access information.
B. Customer or Payer Information
- Name, where provided;
- Email address;
- Mobile number;
- Billing or transaction-related information;
- Payment method information and provider-issued payment references, where applicable;
- Invoice, transaction, payment status, and related reference information.
Depending on the payment method, sensitive payment credentials such as complete card information may be collected and processed directly by the applicable Payment Provider. Integralink may receive tokens, masked details, transaction identifiers, payment status, or other information necessary to operate the Platform without storing the complete payment credential.
C. System and Technical Information
- IP address;
- Device, browser, and operating system information;
- Login, access, security, and audit logs;
- API requests, webhook events, and integration-related records;
- Cookies and similar technology information;
- Other technical information reasonably necessary for security, fraud prevention, troubleshooting, and Platform operation.
2. Purposes of Processing
We may process personal information for the following purposes:
- Creating, verifying, securing, and managing Merchant accounts and authorized users;
- Operating Merchant and sub-account functionality;
- Facilitating payment initiation, routing, checkout, and integration with supported Payment Providers;
- Displaying, recording, and monitoring invoices, transactions, payment statuses, balances, settlement-related information, and payouts where applicable;
- Facilitating reconciliation, payment-status verification, refunds, reversals, or dispute-related workflows where supported;
- Generating reports, records, notifications, and transaction history;
- Providing customer and technical support;
- Preventing fraud, abuse, unauthorized access, and security incidents;
- Meeting applicable legal, contractual, compliance, audit, and Payment Provider requirements;
- Maintaining, troubleshooting, analyzing, and improving the Platform.
3. Legal Bases for Processing
Where required by applicable law, we process personal information on one or more lawful bases, which may include:
- Consent of the data subject;
- Performance of a contract or steps necessary to enter into a contract;
- Compliance with legal obligations;
- Protection of legitimate interests pursued by the Company or another party, where such interests are not overridden by the rights of the data subject;
- Establishment, exercise, or defense of legal claims; and
- Other lawful grounds permitted under applicable data protection law.
4. Information Received from Merchants and Payment Providers
Integralink may receive personal information directly from Merchants, authorized users, Customers or Payers, and supported Payment Providers.
Merchants that submit Customer or Payer information through the Platform are responsible for ensuring that they have an appropriate lawful basis and have provided any notices or obtained any consents required by applicable law.
Payment Providers may send Integralink transaction references, payment statuses, settlement-related information, payout status, masked payment information, webhook data, or other information needed to operate, reconcile, support, or secure a transaction.
5. Sharing and Disclosure of Information
We may disclose personal information where reasonably necessary to:
- Supported Payment Providers, banks, financial institutions, acquiring institutions, card schemes, and payment networks involved in a requested transaction or service;
- Cloud hosting, infrastructure, communications, security, analytics, and other technology service providers supporting the Platform;
- Professional advisers, auditors, consultants, insurers, and other service providers where appropriate;
- Government agencies, courts, regulators, law enforcement authorities, or other persons where disclosure is required or permitted by law;
- Other parties where necessary to investigate fraud, security incidents, disputes, or enforce legal rights.
Information shared with Payment Providers may be used to initiate, process, verify, reconcile, settle, refund, reverse, or otherwise support a transaction, depending on the applicable service.
We do not sell personal information.
6. Third-Party Payment Providers
Payment Providers integrated with the Platform are independent organizations and may process personal information under their own privacy notices, terms, security practices, and legal obligations.
Integralink does not control all processing performed independently by a Payment Provider. Merchants and Customers should review the applicable provider's privacy information where relevant.
The specific Payment Provider used for a transaction may depend on the Merchant's configuration, selected payment method, provider availability, and other Platform or provider requirements.
7. Cross-Border Data Transfers
Some authorized service providers or Payment Providers may process or store information outside the Philippines. Where cross-border processing occurs, the Company will take reasonable measures required by applicable law to protect personal information and ensure appropriate safeguards.
8. Data Security
The Company implements reasonable and appropriate administrative, technical, and organizational safeguards designed to protect personal information, including measures such as:
- Access controls and authentication;
- Encryption or secure transmission mechanisms where appropriate;
- Security monitoring and logging;
- Credential and API access controls;
- Vulnerability and incident management;
- Employee confidentiality and access restrictions;
- Backup, recovery, and other operational safeguards where appropriate.
While reasonable safeguards are employed, no method of transmission, processing, or electronic storage can be guaranteed to be completely secure.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to operate the Platform, maintain transaction and audit records, resolve disputes, enforce agreements, support reconciliation, prevent fraud, and comply with applicable legal, contractual, or Payment Provider requirements.
Certain records may be retained after account closure where retention is required or reasonably necessary for legal, regulatory, accounting, security, fraud-prevention, dispute, or contractual purposes.
10. Rights of Data Subjects
Subject to applicable law and any lawful limitations, data subjects may exercise rights including:
- Right to be informed;
- Right to access;
- Right to object;
- Right to rectification;
- Right to erasure or blocking;
- Right to data portability, where applicable;
- Right to damages, where provided by law;
- Right to lodge a complaint with the National Privacy Commission.
Requests may be submitted using the contact information below. We may request reasonable information to verify the identity and authority of the person making the request before acting on it.
11. Cookies and Similar Technologies
The Platform may use cookies, logs, analytics tools, and similar technologies to maintain sessions, improve functionality, enhance security, prevent fraud, troubleshoot issues, and understand Platform usage.
Users may manage certain cookie settings through their browser. Disabling necessary cookies may affect the functionality or security of parts of the Platform.
12. APIs, Webhooks, and Merchant Integrations
Merchants may integrate their own systems with Integralink through APIs, webhooks, and related tools. Information transmitted through these integrations may include Customer, transaction, invoice, payment status, and provider-reference information necessary to perform the requested service.
Merchants are responsible for securing their own systems, protecting API credentials, limiting access to personal information, and handling information received from Integralink in accordance with applicable privacy and security requirements.
13. Compliance and Lawful Requests
The Company may collect, use, retain, or disclose personal information where reasonably necessary to comply with applicable laws and regulations, lawful court orders or government requests, data protection obligations, Payment Provider or payment network requirements, contractual obligations, security requirements, or the establishment, exercise, or defense of legal claims.
14. Changes to this Privacy Policy
We may revise this Privacy Policy from time to time to reflect changes in the Platform, our data practices, Payment Provider requirements, applicable laws, or security practices.
Updated versions will be posted through the Platform or website and will state their effective date. Where required or appropriate, material changes may also be communicated through email, the Platform, or other reasonable means.
15. Contact Information
For privacy-related inquiries, requests, or concerns, please contact:
Data Protection OfficerMara Linux and Business Solutions, Inc.
Unit I CK Bldg., Don A. Roces Ave. cor. South A, Paligsahan, Quezon City, Philippines
Email: [email protected]
Phone: 02 8477 4889