Overview
VagaPay works with booking platforms, payment providers, banks, crypto wallet providers and other API-integrated services. This page sets out how we meet the requirements those partners place on us and how we support a safe, reliable integration.
Partners who need documentation, security questionnaires or audit evidence can request them using the contact details at the bottom of this page.
1. Compliance with partner requirements
- KYC and AML: verification of user identity using government-issued ID, date of birth and other relevant information for anti-money-laundering compliance.
- Transaction monitoring: real-time and batch monitoring of transactions for suspicious or fraudulent activity.
- Data accuracy: collection of verified personal, financial and compliance information to meet banking, payment and crypto partner requirements.
- Regulatory reporting: transaction reports, user verification data and supporting documentation provided on request by authorised regulatory authorities.
2. API and integration standards
- Secure authentication: OAuth 2.0 and other industry-standard authentication protocols, with credentials held in managed secret storage.
- Encrypted data transmission: all data exchanged via APIs is encrypted using TLS 1.2 or above.
- Rate limiting and stability: integrations are designed to respect partner limits and avoid overload, including caching where a partner prefers fewer live calls.
- Data integrity: transaction, user and compliance data are validated for consistency before transmission.
- Attribution: affiliate identifiers are passed correctly so bookings are attributed to the right partner account.
3. Privacy and data-sharing compliance
- Limited disclosure: personal and financial data are shared with partners strictly on a need-to-know basis, and never sold to third parties.
- Regulatory alignment: data sharing complies with GDPR, applicable local financial regulations and partner-specific requirements.
- Consent management: users are informed about third-party sharing, and consent is obtained where required, including cookie consent on the website.
4. Security measures
- Encryption at rest and in transit: sensitive data is encrypted in storage and during API communication.
- Access controls: role-based access ensures only authorised personnel can reach partner-related data.
- Monitoring and audit trails: continuous logging of API calls, transactions and data access supports accountability and regulatory reporting.
5. Risk and incident management
- Fraud prevention: automated monitoring combined with manual review detects and prevents unauthorised activity, including duplicate or invalid reward claims.
- Incident response: in the event of a data breach or operational incident, affected partners are notified promptly and mitigation is applied in line with best practice and regulatory requirements.
6. Partner onboarding and support
- Documentation: technical and compliance documentation is maintained and shared with partners on request.
- Audit cooperation: we cooperate with partner audits, including providing evidence of policies, user verification and transaction monitoring.
- Continuous improvement: processes are reviewed and updated as partner and regulatory standards evolve.
7. Contact for partner compliance
Partners can reach us for technical, security or compliance enquiries at:
Vaga Solutions LLC
63 N. Burritt Ave, Room 100 East, Buffalo, WY 82834, USA
Email: support@vagapay.app
Last updated: September 3, 2026
