1. Who we are and how Payable fits
Payments.lk is the brand under which Payable (Pvt) Ltd, of 4th Floor, Huejay Court, No. 32, Sir Mohamed Macan Marker Mawatha, Colombo 03, Sri Lanka, offers an internet payment gateway to Sri Lankan startups and small businesses. Payments.lk provides the merchant platform: the account, the application, the API, the hosted checkout, payment links, cards on file, refunds, webhooks, the dashboard and the endpoint for AI agents.
Card processing and acquiring are provided by Payable through its gateway and its acquiring banks, which are licensed commercial banks supervised by the Central Bank of Sri Lanka under the Payment and Settlement Systems Act, No. 28 of 2005. Payments.lk holds no separate licence; it operates under Payable's arrangements. When you are approved, you become a merchant of Payable as well, and Payable's terms of use at payable.lk/terms apply to the processing of your payments alongside these terms. If these terms and Payable's conflict on a matter of processing, Payable's terms prevail on that matter.
These terms are an electronic contract. Under the Electronic Transactions Act, No. 19 of 2006, they are as binding as a signed paper, and your acceptance, recorded when you create an account, is our record of it.
2. A few definitions
- "You" and "the merchant" mean the business that holds the account and the person who accepted these terms for it.
- "Customer" means a person who pays you through the service.
- "Test mode" means keys and payments that run against Payable's sandbox and move no money. "Live mode" means keys and payments that move real money.
- "Key" means a publishable key, a secret key or an agent key issued in your dashboard.
- "Agent" means an automated program, including an AI assistant, that acts in your account with an agent key.
- "Payable" means Payable (Pvt) Ltd.
3. Eligibility and your account
- You must be a business operating in Sri Lanka, whether a registered company, a partnership, a sole proprietorship or an individual trading in their own name, and you must be an adult authorised to sign for it.
- Payments are in Sri Lankan rupees. Settlement goes to a Sri Lankan bank account in the name of the business or, for a sole proprietor or an unregistered individual, your own name. An account in anyone else's name is refused.
- Everything in your application must be true and complete, and you must upload the documents asked for. You must keep your details current, and you must prove your email address and your Sri Lankan mobile number with the codes we send.
- We verify your identity and your business because the Financial Transactions Reporting Act, No. 6 of 2006, the Prevention of Money Laundering Act, No. 5 of 2006, and the rules of the Central Bank and the card networks require it. An application with false information is refused, and an account opened on false information is closed.
- One account per business. Payable refuses a second merchant with the same business email, website or registration number.
- Applying is not approval. Payable's onboarding staff decide, and neither Payable nor Payments.lk is obliged to approve or to give a reason. If changes are asked for, you can correct the application and send it again.
- Your team members act under the role you give them. Only an owner may change the settlement account or close the account. You are responsible for what anyone does in your account, including through a key.
4. Test mode and live mode
Test keys are yours from the moment your account exists. Once your application has been submitted, a sandbox merchant of your own is set up on Payable's sandbox, and from then test payments run there with the card networks' test cards and 3D Secure, moving no money. Live keys are issued only after Payable approves your application and your account is activated. Test and live data are kept apart; a test key can never make a live payment, and a live webhook endpoint never receives a test event.
5. Fees
Every fee is published on the pricing page, and that page is the only place a rate is stated. There is no setup fee, no monthly fee and no minimum. The rate that applies to a card payment is your plan's card rate: every account starts on the Starter plan, the Growth plan is available on request from the dashboard once our team approves it, and an Enterprise rate is quoted to you in writing. Each plan also sets how much you can take by card in a calendar month, and a payment that would take the month past your plan's limit is refused. Cards issued outside Sri Lanka and premium issuer cards carry the surcharges the pricing page shows. The published rates are for approved merchants in ordinary risk categories; a higher risk category or an enterprise volume is quoted to you in writing before you go live. A change to published rates is announced on the pricing page with the date it takes effect, and every payment records the version of the rate card that priced it.
6. Payments, settlement and payouts
- Your server creates a checkout with a secret key, or you make a payment link in the dashboard, or you charge a card a customer kept on file. The customer is sent to a hosted checkout page on payments.lk, enters their name and contact details, and is then sent to Payable's payment page to enter the card. Payments.lk never sees the card.
- A payment is confirmed only when Payable's signed notification reaches us and verifies. The customer's return to your site proves nothing; read the payment's status from the API, the dashboard or a webhook. A payment that stays unconfirmed is checked against Payable's records and settled or failed from them.
- Payable settles funds to your bank account, less the fees, on bank working days for the previous working day. Payments.lk holds no funds, makes no payouts, and has no balance of yours. Questions about a settlement that did not arrive go to us and we take them up with Payable.
- Payable applies a limit per payment and a limit per month to every merchant. Until your documents have been reviewed you are on the starter limit; after review you move to the verified limit; above that a specialist sets your limit. A payment above a limit is declined by Payable and is not initiated. It is not held.
- Payouts and disputes have no screen of their own in the dashboard yet, and the dashboard says so rather than showing an example.
7. Refunds, disputes and chargebacks
- You can refund a successful payment in full or in part, as many times as its remaining amount allows, from the dashboard or the API. A refund can never exceed what was paid. A live refund is sent to Payable exactly once, after the original payment has settled, and is complete when Payable's notification confirms it. Refunding a payment does not, by itself, reverse the fee recorded on it.
- A chargeback is raised by a card holder with their bank under the card network's rules and is handled by Payable and its acquiring bank. If a customer disputes one of your payments, Payable's team contacts you with what it needs and by when; disputes are not yet listed in the dashboard, and it says so. You are liable for the amount of any chargeback and any fee the network or the bank imposes for it, and you agree that Payable may recover it from your settlements. Chargeback handling and any dispute fee are set out in your approval letter before you go live.
- You must keep evidence of what you sold and delivered, and give it to us or Payable promptly when a dispute is raised.
- Failed and declined payments cost nothing.
8. Your responsibilities
- Keys. A secret key or an agent key is shown once and then held only as a digest. Keep it on a server or in a settings file you control, never in a browser, an app or a public repository. Revoke a key the moment you suspect it has leaked; a revocation is immediate. Everything done with your key is done by you.
- Webhooks. Your endpoint must be a public https address. Verify the signature over the exact bytes received before acting on an event, and treat an unverified request as noise. We retry a failed delivery with increasing delays over about a day and then stop; a missed event is yours to reconcile from the API.
- Your customers. You are the controller of your customers' data. Collect only what your sale needs, tell your customers how you use it, and honour their rights. Give us a customer's details only to make a payment for that customer.
- Your site and your product. Describe accurately what you sell and what it costs, deliver what was paid for, publish your own refund and delivery terms, and answer your customers. Under the Consumer Affairs Authority Act, No. 9 of 2003, a customer has rights against you that a payment gateway cannot take away.
- Your compliance. Hold any licence your activity needs, pay the taxes you owe, and comply with the Computer Crime Act, No. 24 of 2007, the Electronic Transactions Act and every other law that applies to you.
- Notice. Tell us at once if your business changes ownership, activity, name, address or bank account, or if you learn of a security incident that touches the service.
9. Prohibited businesses and uses
The service cannot be used for the following, because Payable, its banks and the card networks will not process for them or the law forbids them:
- Anything illegal in Sri Lanka or in the country of the customer, including the sale of controlled drugs, weapons, counterfeit or stolen goods, and the proceeds of any offence.
- Gambling, betting, lotteries and games of chance without a licence issued under Sri Lankan law.
- Adult content and services.
- Cryptocurrency exchange, trading or mining, foreign exchange dealing, money remittance, money transfer, or acting as a payment intermediary for others, unless licensed by the Central Bank of Sri Lanka and approved by Payable in writing.
- Pyramid schemes, multi level marketing based on recruitment, and investment schemes that promise returns.
- Charging a card without the card holder's authority, splitting one sale into several payments to stay under a limit, and taking a payment for a business other than the one on the account.
- Testing stolen cards, or using the service or its sandbox to probe, overload or interfere with our systems, Payable's or anyone else's, which the Computer Crime Act makes an offence.
- Anything that infringes another person's intellectual property or privacy, or that harasses, defames or threatens.
- Any category Payable or an acquiring bank tells us it will not acquire for. We tell you when that is the reason for a refusal.
A higher risk category that is legal is not refused outright: it is priced separately and confirmed to you in writing before you go live. If you are unsure whether what you sell is allowed, ask before you apply.
10. API and developer terms
- Keys. A publishable key may only create checkouts. A secret key does everything the API offers. An agent key opens only the agent endpoint and is refused everywhere else, so a leaked agent key never becomes a secret key.
- Idempotency. Every write to the API takes an Idempotency-Key. A retried request with the same key returns the first answer; the same key with a different body is refused.
- Limits. Requests to the API are rate limited per address, and requests to the agent endpoint per key as well. When you are limited, back off and retry; do not spread requests across addresses or keys to get around it.
- Agents and approval. An agent key is issued for one named agent, in one mode, with the scopes you tick, and always with an end date of at most a year. What the agent can read is limited by its scopes, and customer details are masked unless you tick the customer scope. An agent cannot move money: it prepares a refund, and a person on your team with the refund role approves or declines it in the dashboard within twenty four hours. You are responsible for everything your agents do with your key, for the model and the tools you connect it to, and for the instructions you give it.
- Software development kits, the pay button and the WooCommerce plugin are provided as source you can read. Use them as documented. Do not reverse engineer, probe or interfere with the API, the checkout or Payable's payment page beyond what the documentation describes.
- Documentation, endpoints and SDKs may change. We keep a change compatible where we can and give notice where we cannot.
11. Availability and changes to the service
We work to keep the service available at all times, but we do not promise uninterrupted availability. The service depends on Payable's gateway, the acquiring banks, the card networks and our hosting providers, any of which may be down or slow. Planned maintenance is announced in advance where we can. We may add, change or withdraw a feature; where a change removes something you rely on, we give notice, and the copy on this site changes in the same release, so what you read here is what the platform does.
12. Suspension and closing the account
- We or Payable may suspend your account or refuse a payment when we reasonably suspect fraud, a breach of these terms, a prohibited use, a legal or regulatory demand, an unusual pattern of chargebacks or refunds, or a risk to a customer, a bank or the network. While an account is suspended no payment can be taken through it. We tell you why unless the law forbids it.
- We may close your account with thirty days' notice for any reason, or at once for a serious breach, a legal requirement, or a decision by Payable or an acquiring bank to stop acquiring for you.
- You may close your account at any time: an owner writes to us and we close it. Refunds and chargebacks that arise after closure remain yours, and records that the law requires us to keep are kept for their retention period as the privacy policy describes.
- Once closed, nothing can be taken through the account, in test mode or live, and nobody can sign in to it. Payments already made are settled in the ordinary way.
13. Intellectual property
The Payments.lk name, site, portal, API, checkout, documentation, SDKs and plugins belong to us or our licensors. You get a non exclusive, revocable right to use them to take payments under these terms. You keep everything that is yours: your name, your logo, your product content and your customers' data. You allow us to show your name and logo on your checkout and on Payable's payment page, which is what they are for. The Payable name and marks belong to Payable.
14. Liability and indemnity
In plain language:
- We are responsible for providing the platform with reasonable skill and care, for keeping your data as the privacy policy says, and for paying what the law says we must pay. Nothing in these terms limits liability that the law does not allow to be limited.
- We are not responsible for losses that come from Payable's gateway, an acquiring bank, a card network or a hosting provider being unavailable, from a decision by Payable or a bank to refuse, delay or reverse a payment or a merchant, from your own breach, from a leaked key, from your webhook endpoint, from an agent acting on your key, or from anything a customer does.
- We are not responsible for indirect losses: lost profit, lost business, lost data you did not back up, or damage to reputation.
- For everything else, our total liability to you in any twelve months is limited to the fees you paid us in those twelve months.
- You will compensate us and Payable for losses, claims and costs that come from your breach of these terms, from a prohibited use, from a claim by your customer about what you sold, from a chargeback, or from your infringement of someone's rights.
15. Governing law and disputes
These terms are governed by the laws of Sri Lanka. Before either of us goes to court, we talk: write to us, and we answer within fourteen days and try to settle it. If that fails, the courts of Colombo have exclusive jurisdiction. Nothing here stops you from taking a consumer complaint to the Consumer Affairs Authority or a data complaint to the Data Protection Authority.
16. If you are a customer paying a merchant
- You are buying from the merchant, not from Payments.lk or Payable. The merchant's own terms cover what you bought, delivery and refunds. Your rights under the Consumer Affairs Authority Act are against the merchant.
- We show you the merchant's name, the amount and what it is for before you pay, and we take your name, email address and phone number because the card networks require them. Your card is entered on Payable's page with 3D Secure, and we never see it.
- If you tick the box to keep your card on file with a merchant, that merchant can charge it for future purchases from them, without you present. Ask the merchant to remove it whenever you like.
- If a payment is wrong, ask the merchant first. If the merchant does not help, write to us and we will help you reach them. A dispute about a card payment can also be raised with the bank that issued your card.
- The privacy policy explains what we keep about you and for how long.
17. Changes to these terms
We change these terms when the platform changes or the law requires it. The date at the top is the version in force. A change that reduces your rights or increases your obligations is sent by email to every account owner at least fourteen days before it takes effect, and continuing to use the service after that date is acceptance. A change required by law or by Payable or a bank may take effect sooner, and we say so in the notice.
18. Contact
Payments.lk, a service offered by Payable (Pvt) Ltd, 4th Floor, Huejay Court, No. 32, Sir Mohamed Macan Marker Mawatha, Colombo 03, Sri Lanka.
Questions, notices and complaints: [email protected]. For the processing of your payments, Payable's terms name its own contact.
This document is published in English, Sinhala and Tamil. Every effort is made to keep the three texts identical in meaning. If they differ, the English text applies.