Skip to main content

How to Add Terms & Conditions and a Privacy Policy for Payment Gateway Applications

This guide explains how Pixalink merchants can publish their own Terms & Conditions and Privacy Policy in the Customer Portal, then prepare the document formats listed in the provided CommercePay merchant-onboarding guide.1

Important

Default (Pixalink Default) links to Pixalink's corporate policies. A payment gateway application normally needs the merchant's own legal policies showing the merchant's legal business name and registration details. For a merchant application, use Text, Link, or File with merchant-specific content.

For a broader introduction to the portal, see What Is the Customer Portal and How to Set It Up. For the complete theme-editing workflow, see How to Customise Your Customer Portal Theme.

Before you start

Prepare the following information:

  • Full legal business name exactly as shown in SSM, including punctuation and the legal suffix
  • SSM registration number
  • Physical business address
  • Business email address and phone number with the +60 country code
  • Merchant-approved refund, cancellation, delivery or service-fulfilment rules
  • Privacy contact details
  • Final Terms & Conditions and Privacy Policy reviewed for the merchant's actual business

Caution

The sample wording in an onboarding guide is not a substitute for merchant-specific legal review. Refunds, cancellations, delivery, retention periods, payment methods and data-sharing practices must match the merchant's real operations and applicable law.

  1. In the Pixalink admin panel, go to Loyalty Program > Customer Portal Design.
  2. Open the Customer Portal theme used by the relevant space and click Edit.
  3. Select the Legal tab.
  4. Under Terms & Conditions, choose a Mode:
    • Text - paste the complete merchant Terms & Conditions into the editor.
    • Link - paste the full public URL of the merchant's existing Terms & Conditions page.
    • File - upload the final Terms & Conditions as a PDF.
    • Default (Pixalink Default) - uses Pixalink's corporate Terms & Conditions and is not the merchant's own policy.
  5. Under Privacy Policy, choose a Mode:
    • Text - paste the complete merchant Privacy Policy into the editor.
    • Link - paste the full public URL of the merchant's existing Privacy Policy page.
    • File - upload the final Privacy Policy as a PDF.
    • Default (Pixalink Default) - uses Pixalink's corporate Privacy Policy and is not the merchant's own policy.
  6. Save the Customer Portal theme.
  7. Open the customer-facing portal and test both policy links.
  8. Open each policy in a private or incognito browser window to confirm that it is publicly accessible without logging in.
  9. Copy the two working public URLs for the payment gateway application.

Open Customer Portal Design

Mode What to provide Best used when Payment gateway note
Text Paste the final policy into Pixalink The merchant does not have separate policy pages Pixalink generates a public customer-portal page that can be shared as a live URL
Link A complete public HTTPS URL The merchant already publishes the policy on its website The page must load without a login, password or expired preview link
File A PDF upload The merchant maintains an approved policy document The current Pixalink upload control accepts PDF for legal-policy files; test the public file URL after saving
Default Nothing; Pixalink's policy is used General platform fallback only Do not treat Pixalink's corporate policy as the merchant's own policy for onboarding

CommercePay document-format checklist

The provided CommercePay onboarding guide lists nine checklist items. Items 3 to 5 are sections inside the Terms & Conditions, so they do not need to be separate pages unless CommercePay specifically asks for them separately.1

# Item Format listed in the guide Main checks
1 Privacy Policy Public web URL or PDF PDPA statement, data collected, purposes, third-party disclosures, retention, customer rights and privacy contact
2 Terms & Conditions Public web URL or PDF Malaysia governing law, user obligations, liability, intellectual property, termination, payment terms and contact details
3 Refund Policy Dedicated section within the Terms & Conditions Return or refund window, eligibility, process, timeline, exclusions and return-shipping responsibility
4 Cancellation Policy Dedicated section within the Terms & Conditions Cancellation method, notice period, fees and treatment of prepaid or unused services
5 Service / Shipping / Delivery Policy Dedicated section within the Terms & Conditions Processing and delivery timeframes, coverage, charges, digital fulfilment and handling of delays
6 Contact Us Public web page Legal business name, SSM number, physical address, business email, +60 phone number and preferably operating hours
7 Business premises photo JPG or PNG Clear exterior, readable company signboard and visible unit or lot number; the guide recommends at least 500 KB
8 SSM Company Profile Official, unmodified PDF Submit all pages; active status, registered address and ownership or officer details must be visible; the guide recommends a document issued within the last 12 months
9 Bank statement header PDF or clear scan Company or business bank account, first page or header only, issued within the last three months, with bank name, account-holder name, account number and statement date visible

Note

For the policy items, format and accessibility are separate checks. A PDF stored only on an employee's computer is not a public policy URL. Publish the policy through Pixalink or a public website, test the URL, and then submit that working URL.

What the Terms & Conditions should cover

At minimum, review and customise these sections:

  • Merchant legal name and SSM registration number
  • Description of products or services
  • User obligations and prohibited activities
  • Prices, currency, taxes and payment terms
  • Limitation of liability and warranty wording
  • Intellectual property
  • Account suspension or termination
  • Refund process, eligibility, timeline and exclusions
  • Cancellation method, notice period, fees and treatment of prepaid amounts
  • Service, shipping or delivery timeframes, charges, coverage and delays
  • Malaysian governing law and jurisdiction
  • Merchant contact details

Do not publish refund, cancellation or delivery promises that the merchant cannot operationally fulfil.

What the Privacy Policy should cover

At minimum, review and customise these sections:

  • Merchant identity and contact details
  • Types of personal data collected
  • Purposes for collecting and using the data
  • Payment gateway, logistics, IT-provider and regulatory disclosures where applicable
  • Whether marketing is optional and how customers can withdraw consent
  • Retention periods or the criteria used to determine them
  • Customer rights, including access and correction
  • Privacy enquiry or complaint contact
  • How policy updates are communicated

The merchant is responsible for its customer-facing policy and for ensuring it reflects the merchant's real processing. Pixalink provides the technology used to display the policy; Pixalink's own corporate policies do not replace the merchant-customer documents.

Final consistency check before submission

  • Legal business name matches the SSM profile exactly
  • Bank account-holder name matches the registered business name
  • SSM number is consistent across the policies and Contact Us page
  • Physical address is consistent across the application documents
  • Terms & Conditions and Privacy Policy each have a working public URL
  • Public policy pages open without a customer login
  • Refund, cancellation and service or delivery sections are inside the Terms & Conditions
  • Contact Us page shows the legal name, SSM number, address, email and +60 phone number
  • Premises photo is clear and shows the signboard and unit or lot number
  • SSM PDF is official, complete and unmodified
  • Bank statement header is within three months and transaction details are not needed
  • All PDF files are readable, correctly oriented and not password-protected

Frequently asked questions

No. The default option points to Pixalink's corporate Terms & Conditions and Privacy Policy. Use merchant-specific Text, Link, or File content for a merchant application.

Do I need separate Refund, Cancellation and Delivery pages?

The provided CommercePay guide says these can be dedicated sections inside one Terms & Conditions document. Confirm with CommercePay if your onboarding officer requests separate pages.

The current Pixalink File mode accepts PDF for both Terms & Conditions and Privacy Policy. Convert the final approved document to PDF before uploading.

Yes. Choose Link and enter the complete public URL. Test it in a private browser window to make sure it does not require login and is not a temporary preview link.

Are these document requirements the same for every payment gateway?

Not necessarily. This checklist is based on the provided CommercePay guide. Other providers, merchant categories or risk reviews may request different or additional documents.

Who should confirm whether the policy wording is legally suitable?

The merchant should obtain appropriate legal review and confirm the latest onboarding requirements with the payment gateway's merchant-support team before submission.


  1. Source used for the payment-format checklist: CommercePay Merchant Onboarding - Required Documents Guide, prepared by Pixalink, 3 March 2026, 19 pages. It is labelled as a sample/template document; confirm current requirements with CommercePay merchant support before submission. ↩ ↩

Was this article helpful?

Thank you for your feedback!

0 found this helpful 0 did not

Search