VagaPay
For partners

Partner & API Compliance

How we meet the regulatory, security and operational standards our partners require.

Effective date: September 3, 2026

Overview

VagaPay works with booking platforms, payment providers, banks, crypto wallet providers and other API-integrated services. This page sets out how we meet the requirements those partners place on us and how we support a safe, reliable integration.

Partners who need documentation, security questionnaires or audit evidence can request them using the contact details at the bottom of this page.

1. Compliance with partner requirements

  • KYC and AML: verification of user identity using government-issued ID, date of birth and other relevant information for anti-money-laundering compliance.
  • Transaction monitoring: real-time and batch monitoring of transactions for suspicious or fraudulent activity.
  • Data accuracy: collection of verified personal, financial and compliance information to meet banking, payment and crypto partner requirements.
  • Regulatory reporting: transaction reports, user verification data and supporting documentation provided on request by authorised regulatory authorities.

2. API and integration standards

  • Secure authentication: OAuth 2.0 and other industry-standard authentication protocols, with credentials held in managed secret storage.
  • Encrypted data transmission: all data exchanged via APIs is encrypted using TLS 1.2 or above.
  • Rate limiting and stability: integrations are designed to respect partner limits and avoid overload, including caching where a partner prefers fewer live calls.
  • Data integrity: transaction, user and compliance data are validated for consistency before transmission.
  • Attribution: affiliate identifiers are passed correctly so bookings are attributed to the right partner account.

3. Privacy and data-sharing compliance

  • Limited disclosure: personal and financial data are shared with partners strictly on a need-to-know basis, and never sold to third parties.
  • Regulatory alignment: data sharing complies with GDPR, applicable local financial regulations and partner-specific requirements.
  • Consent management: users are informed about third-party sharing, and consent is obtained where required, including cookie consent on the website.

4. Security measures

  • Encryption at rest and in transit: sensitive data is encrypted in storage and during API communication.
  • Access controls: role-based access ensures only authorised personnel can reach partner-related data.
  • Monitoring and audit trails: continuous logging of API calls, transactions and data access supports accountability and regulatory reporting.

5. Risk and incident management

  • Fraud prevention: automated monitoring combined with manual review detects and prevents unauthorised activity, including duplicate or invalid reward claims.
  • Incident response: in the event of a data breach or operational incident, affected partners are notified promptly and mitigation is applied in line with best practice and regulatory requirements.

6. Partner onboarding and support

  • Documentation: technical and compliance documentation is maintained and shared with partners on request.
  • Audit cooperation: we cooperate with partner audits, including providing evidence of policies, user verification and transaction monitoring.
  • Continuous improvement: processes are reviewed and updated as partner and regulatory standards evolve.

7. Contact for partner compliance

Partners can reach us for technical, security or compliance enquiries at:

Vaga Solutions LLC

63 N. Burritt Ave, Room 100 East, Buffalo, WY 82834, USA

Email: support@vagapay.app

Last updated: September 3, 2026