Skip to content
Appearance

BongLuy Terms of Service

Effective
15 August 2026
Last updated
15 August 2026
Service boundary

Funds follow the bank path, never the software layer.

The payer sends funds through ABA to the merchant. Bongluy creates the QR and observes payment status but does not enter the funds path.

BongLuy ("BongLuy", "we", "us") is a payment software service operating in the Kingdom of Cambodia. Contact: support@bongluy.com.

These terms are written to be read. Where a clause matters to your integration, it says so in the same words our API reference uses.

In short

BongLuy is bare software. We help a merchant accept money into the merchant's own account. That is the whole of what we do.

We never hold your money. Payments go from the payer to your own ABA merchant account. We do not touch, hold, route, or control funds at any point, and we cannot move, freeze, reverse, or refund them.

We are not responsible for what a payment is for. We do not see, approve, or vet the transaction behind a QR code. If a payment is unlawful, fraudulent, or misused, that is on the people who made it and received it — the payer and the merchant are each accountable for their own conduct, not us.

You carry your own obligations. Your licences, your tax, your customers, your refunds, your disputes with your bank.

This summary is here so the shape of the deal is obvious. It is not a substitute for the terms below, which are what actually govern — where the two differ, the full terms win.

1. This agreement

You agree to these terms when you create a BongLuy account, use an API key, or accept a payment through the service — whichever happens first. If you do not agree, do not use the service.

If you are acting for a business, you confirm you are authorised to bind it, and "you" means that business.

Our Privacy Policy forms part of this agreement and explains what we do with personal data.

2. What BongLuy is, and what it is not

BongLuy is software. We give you an API that creates a KHQR payment against your own ABA PayWay link, returns the QR payload and a deeplink for you to display, and tells you when that payment settles.

The money never reaches us. A payer scans your QR, ABA processes the payment, and ABA settles it into the bank account behind your PayWay link. We are not in that path at any point.

It follows that we are not a bank, a payment institution, an e-money issuer, a payment service provider, or a money transmitter, and we do not hold, transmit, pool, freeze, reverse, or refund funds. We could not do so if you asked us to.

What stays yours:

  • Your relationship with your customers, including support and receipts.
  • Refunds, cancellations, chargebacks, and disputes — these are between you, your payer, and your bank.
  • Whether a payment should have been accepted at all: pricing, tax, invoicing, and the goods or services behind it.
  • Any licence, registration, or approval your own business needs.

What we record is a payment's status and metadata, so you can reconcile. That record is evidence of what our system observed. It is not a settlement, a receipt, or a statement of account — your bank's records govern.

We are not responsible for what a payment is for, or for anyone's misuse of it. We generate a QR code for an amount you specify. We do not see the underlying transaction, do not know what is being bought or sold, and do not approve, vet, endorse, or verify it. We are not a party to it. If a payment is unlawful, fraudulent, deceptive, or otherwise misused, responsibility rests with the people who made and received it: the payer is accountable for their own conduct, and you are accountable for yours as the merchant receiving the funds. Providing the software that displayed the QR makes us neither.

None of this excuses us from acting when we are told. If we become aware of unlawful use, we may suspend an account under §10 and will cooperate with lawful requests from Cambodian authorities. Doing so is not an admission that we controlled or were responsible for the payment.

3. ABA PayWay, and our dependence on it

We are not affiliated with, endorsed by, sponsored by, or acting as agent for Advanced Bank of Asia Ltd. ("ABA"). We refer to ABA, ABA PayWay, ABA Mobile, and KHQR only to describe what our software works with. Those names and marks belong to their owners.

Your PayWay link, your merchant account, and your agreement with ABA or any other bank are yours. You are responsible for obtaining them, keeping them valid, and complying with their terms. If your bank restricts or closes your account, that is between you and your bank; we have no standing in it and no ability to intervene.

The service depends on interfaces operated by ABA that we do not control and are not party to. If ABA changes, throttles, or withdraws them, parts of the service may degrade or stop working with no notice to us and therefore none from us. This is a real risk, not a formality — we accept no liability for it.

In particular, the deeplink we return is derived from ABA's own checkout behaviour and is not a documented or supported interface. It may break at any time. qrString is the source of truth. Build so that a broken deeplink costs you nothing.

4. Your account

You must be at least 18 years old and legally able to enter into this agreement.

Accounts are created by signing in with Google or GitHub. There is no email-and-password sign-up, which means the security of the provider account you sign in with is part of the security of your BongLuy account. Losing control of it means losing control of yours.

Keep your account details accurate and current. We may contact you at the address on your account, and notice sent there is effective whether or not you read it.

5. Credentials and security

Three credentials reach our API, and every one of them belongs on a server.

API keys (sk_live_…). Account-wide, not per-store: one key reaches every store on your account. Shown once at creation and stored by us only as a hash, so a key you did not save cannot be recovered. Expires 90 days after it is created. Key management requires a signed-in browser session — a key cannot rotate itself, deliberately.

Checkout keys. A shared secret for the public payment routes. It does not expire, is not tied to an account, and opens nothing but two read routes — but anyone holding it and a payment id can see that payment.

Session cookies. Held by a browser after a human signs in.

You agree that:

  • You will keep all three server-side. Never ship an API key or a checkout key to a browser, a mobile app, or any client you do not control.
  • You are responsible for everything done with your credentials, including by someone who obtained them from you, until you revoke or replace them.
  • You will tell us promptly at support@bongluy.com if you believe a credential has been exposed, and you will revoke it yourself without waiting for us.
  • You will not attempt to access another account's stores, payments, or keys, and will not enumerate or guess payment identifiers.

We will never ask you for an API key, a checkout key, or a PayWay account password.

6. Acceptable use

Use the service lawfully. You are responsible for complying with every law that applies to you, including anti-money-laundering, sanctions, tax, consumer-protection, and data-protection law, and for holding any licence your activity requires.

You must not use BongLuy for, or in connection with:

  • Fraud, deception, or any transaction you know or suspect to be unauthorised.
  • Money laundering, terrorist financing, or evading sanctions or currency controls.
  • Illegal drugs, weapons, stolen goods, human trafficking or exploitation, or child sexual abuse material.
  • Unlicensed financial services, unlicensed gambling, pyramid or Ponzi schemes.
  • Processing payments for an undisclosed third party, or letting another business collect through your account as if it were yours ("transaction laundering").
  • Infringing intellectual property, or distributing malware.

You must also not attack or degrade the service itself. Specifically, you must not:

  • Circumvent or attempt to circumvent the published limits — 600 requests per minute per API key, 20 requests per second per payment id and 200 per second overall on the public routes, and 20 store writes per minute per account — including by minting extra keys or accounts to widen a limit.
  • Probe, scan, or load-test the service without our written permission, or interfere with anyone else's use of it.
  • Reverse-engineer, decompile, or attempt to derive our source code, or resell or sublicense access to the API as a service of your own.

We may investigate suspected breaches and are required to cooperate with lawful requests from Cambodian authorities.

7. Your integration

Some obligations here are technical, and getting them wrong loses money. They are terms, not suggestions.

  • Read expireAt from the response. A payment lives about three minutes, but the value is set upstream and is not a promise. Do not hardcode it.
  • Treat PENDING past expireAt as unpaid. If our upstream polling exhausts its retries, a payment can remain PENDING after it has expired. Stop polling, treat it as unpaid, and reconcile later against POST /payment/detail. Do not release goods on a status you have not confirmed.
  • Reconcile against your bank. Our records are for reconciliation; your bank's records are authoritative on whether you were paid.
  • Send a tranId. It makes POST /payment idempotent, so a timeout can be retried without creating a second payment. Without one, a retry after a network failure is your risk.
  • USD only. Stores accept USD PayWay links; KHR links are rejected. The currency field on a payment is a label on your own record and never changes what a payer is charged — the PayWay link decides that.
  • Do not rely on webhooks. They do not exist yet. webhookUrl and webhookSecret are accepted and stored, but nothing reads them, and a webhook configured today will never fire. Poll POST /payment/status.
  • Handle new terminal states. FAILED is defined but not yet written. Treat any non-SUCCESS terminal status as unpaid rather than branching on an exhaustive list.
  • Show your payer who they are paying. If you use the public checkout routes, present the store name and amount honestly.

Loss you suffer because your integration ignored this section is yours.

8. Beta

The service is in beta. That is a statement about its maturity, not a disclaimer of it:

  • It is provided free of charge today (see §9).
  • There is no uptime commitment and no guarantee that data is retained indefinitely.
  • Features may be added, changed, or withdrawn, and some documented behaviour is not fully implemented.
  • Interfaces may change, though we will give notice of breaking changes under §11.

Decide with that in mind whether BongLuy is right for the volumes and risk you are carrying.

9. Fees, plans, and quotas

9.1 Today

The service is free. No fees are payable, no plan exists, and no quota is charged against you.

9.2 When paid plans launch

The following applies only from the date we announce paid plans, and never retroactively to anything you did before that date. We will give at least 30 days' notice by email and in the dashboard before charging you anything, and you may close your account before then at no cost.

  • Prepaid access periods. A plan is bought in advance for a fixed period running from the date of payment, not from the start of a calendar month. It does not renew automatically.
  • Quotas. A plan includes a number of transactions. A transaction counts once, when a payment reaches SUCCESS. Payments that expire, fail, or are never paid do not count. Quota is pooled across all stores on your account, not divided between them.
  • Exceeding quota. Requests beyond your quota are refused with an error. We will not silently bill you for overage you did not agree to.
  • Taxes. Fees are exclusive of VAT and any other tax, which you pay in addition where it applies.
  • Price changes. We may change prices with reasonable notice. A change never affects a period you have already paid for.
  • Refunds. Fees are non-refundable, except where the law requires otherwise.

10. Suspension and termination

We may suspend or close your account, in whole or in part, if:

  • you breach these terms, in particular §6;
  • we are required to by law, a court, or a regulator;
  • we reasonably suspect fraud, money laundering, or unauthorised use of your account or credentials; or
  • your use is causing, or is likely to cause, serious harm to the service, to us, or to other users.

Where it is lawful and safe to do so, we will tell you why and give you a reasonable chance to put it right first. Where the risk is immediate, we may act first and tell you after.

While suspended, you can still sign in and read your history, but new payments are refused. Payments already in flight are allowed to settle — we do not strand a payer mid-transaction.

You may close your account at any time. Closing it does not entitle you to a refund of prepaid fees, and does not affect payments already made to you.

Sections 2, 3, 12, 13, 14, 15, 16 and 17 survive termination.

11. Availability and changes to the service

We work to keep the service available, but we do not promise it will be uninterrupted, timely, secure, or error-free. It depends on third parties, including ABA (§3), and on the internet.

We may perform maintenance, and may modify or discontinue features. Where a change would break a working integration, we will give reasonable advance notice through the dashboard, the documentation, or email — except where a change is needed urgently for security or legal reasons.

Design your integration to survive ours: retry on 502 and 503, use tranId for idempotency, and do not depend on undocumented behaviour.

12. Data

What we hold. Your account details; your stores, including the PayWay links you register and any webhook URL and secret you supply; and a record of each payment — its amount, currency label, status, your tranId, the settled transaction id, the receipt URL ABA returns, and timestamps. We store a snapshot of the PayWay link a payment was created against, so a settled payment stays truthful even after you change the store's link.

What we never receive. Card numbers, bank credentials, PINs, or OTPs. Payers authenticate inside ABA's own app; none of that reaches us.

Your customers' data. If you send us anything about your customers — an order id, an invoice reference — you are responsible for having a lawful basis to do so and for what that data reveals. We process it to provide the service and as described in the Privacy Policy.

Getting it out. Your payments and stores are readable through the API for as long as your account is open. Export what you need before you close it.

Keeping it. We retain payment records after account closure where we need to for legal, tax, accounting, or fraud-prevention purposes, and then delete or anonymise them.

Security. We protect your data with measures appropriate to the risk, but no system is perfectly secure, and §14 applies to any loss.

13. Intellectual property

We own the service, the API, the documentation, and the BongLuy name and marks. You own your data, your content, and your business. Nothing here transfers ownership either way.

For as long as this agreement is in force, we grant you a limited, non-exclusive, non-transferable, revocable right to access and use the API in accordance with these terms, and to use our documentation to build your integration.

If you send us feedback, ideas, or bug reports, we may use them without restriction, attribution, or payment. Do not send us anything confidential as feedback.

Neither of us may use the other's name or marks publicly without permission, except that you may state factually that you use BongLuy.

14. Disclaimers and liability

The service is provided "as is" and "as available". To the fullest extent the law allows, we exclude all implied warranties, including merchantability, fitness for a particular purpose, non-infringement, and any warranty arising from a course of dealing.

We are not liable for:

  • payments that fail, are delayed, are duplicated, are misdirected, or never arrive;
  • any act, omission, outage, change, or decision of ABA or any other bank;
  • disputes, chargebacks, or reversals between you, your payers, and your bank;
  • loss arising from your integration, including any failure to follow §7;
  • loss arising from your credentials being exposed by you or on your side.

To the fullest extent the law allows, neither party is liable for indirect or consequential loss, or for loss of profit, revenue, business, goodwill, anticipated savings, or data, however caused.

Our total liability to you for all claims arising out of or relating to this agreement, in aggregate, is limited to the greater of (a) the fees you paid us in the three months before the event giving rise to the claim, and (b) USD 100. The floor exists deliberately: while the service is free, a cap measured only in fees would be nothing at all.

Nothing in this agreement excludes liability that cannot lawfully be excluded, including for fraud or fraudulent misrepresentation.

15. Indemnity

You will indemnify us against claims, losses, damages, fines, and reasonable legal costs arising from:

  • your breach of these terms or of any law;
  • the goods or services you sell and the payments you take for them;
  • your handling of personal data, including your customers'; and
  • any dispute between you and a payer, a bank, or ABA.

We will tell you promptly of any claim we seek indemnity for and will not settle it without your consent, which you will not unreasonably withhold.

16. General

Force majeure. Neither party is liable for a failure caused by something beyond its reasonable control, including outages at ABA or another bank, network or power failure, natural disaster, epidemic, war, civil unrest, or an act of government.

Assignment. You may not assign this agreement without our written consent. We may assign it to an affiliate or in connection with a merger, acquisition, or sale of assets, on notice to you.

Entire agreement. This document and the Privacy Policy are the whole agreement between us on this subject and replace anything said before it.

Severability. If a provision is unenforceable, it is limited or removed to the minimum extent necessary and the rest stays in force.

No waiver. Not enforcing a term once does not waive it.

No partnership. Nothing here makes either of us the other's agent, partner, employee, or joint venturer.

Notices. We give notice by email to your account address or in the dashboard. You give notice to support@bongluy.com.

Changes to these terms. We may update these terms. For material changes we will give reasonable notice by email or in the dashboard, and state the new effective date. Continuing to use the service after that date means you accept the change; if you do not, close your account.

Language. These terms are written in English. If we publish a translation and the versions conflict, the English version governs unless Cambodian law requires otherwise.

17. Governing law

These terms and any dispute arising out of them are governed by the law of the Kingdom of Cambodia. The courts of the Kingdom of Cambodia have exclusive jurisdiction.

We would rather resolve a problem than litigate one. Write to support@bongluy.com first.

18. Contact

Support and legal: support@bongluy.com