> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Privacy notice

> How Cube Payment Services Pte Ltd collects, uses, discloses, and protects personal data in connection with the RadiumOne developer documentation site.

This Privacy Notice explains how **Cube Payment Services Pte Ltd** (UEN 201403040W), a company incorporated in Singapore with its registered address at 163 Kallang Way, #03-15 Mapletree Hi-Tech Park, Singapore 349256 ("**we**", "**us**", or "**our**"), collects, uses, discloses, and otherwise processes personal data in connection with the RadiumOne developer documentation site (the "**Site**"), in accordance with the Personal Data Protection Act 2012 of Singapore ("**PDPA**").

Capitalised terms not defined here have the meaning given in our [Terms of use](/legal/terms). This notice explains our practices; it does not form part of the Terms of use or any other contract, and does not create contractual rights or obligations.

## 1. Scope

1.1 This notice applies only to personal data processed in connection with your access to and use of the Site, and your communications with us about the Site.

1.2 This notice does **not** apply to personal data processed in connection with the RadiumOne Services, including merchant onboarding, merchant accounts, payment transactions, cardholder or shopper data, or UOB Rewards redemption. That processing is governed by your Merchant Agreement and the privacy notices provided in connection with those services. Where a merchant processes personal data of its own customers through the RadiumOne Services, the merchant is responsible for providing its own privacy notice to those customers and for obtaining any required consent.

1.3 This notice does not apply to third-party websites, repositories, package registries, or AI tools linked from or accessible through the Site, which are governed by their own privacy notices.

1.4 The Site is intended for businesses registered in Singapore and developers acting on their behalf. It is not directed at individuals in the European Economic Area, the United Kingdom, or other jurisdictions outside Singapore.

## 2. Personal data we collect

The Site does not require you to create an account or sign in. We collect the following categories of personal data in connection with the Site.

| Category | Examples | Source |
| - | - | - |
| **Contact and correspondence data** | Name, email address, telephone number, organisation, job title, and the content of messages you send us, including support, security, and data protection requests | You, when you contact us |
| **Technical and usage data** | IP address, browser type and version, operating system, device type, referring URL, pages requested, time of request, approximate location derived from IP address, browser, device, and network request characteristics and request patterns used to distinguish legitimate visitors from automated traffic, and diagnostic and security logs | Automatically, through the Site's hosting, content delivery, and network security infrastructure |
| **Interaction data** | Search queries, questions submitted to any AI assistant, and page feedback, where those features are available on the Site | You, when you use those features |
| **Browser storage data** | Preferences stored in your browser, such as your display theme or the open or closed state of an interface panel | Your browser — see our [Cookie policy](/legal/cookies) |

We do not use analytics or advertising cookies on the Site.

**Business contact information.** Where you provide your name, job title, business telephone number, business address, or business email address solely for business purposes — for example, when contacting us on behalf of your organisation — that information is business contact information under the PDPA, and the PDPA's consent, purpose, and notification obligations do not apply to it. We nevertheless handle it with the same care as other personal data described in this notice.

**Information you must not submit.** The Site is not designed to receive sensitive information. Do not submit payment card data, API keys, access tokens, secrets, passwords, government identification numbers, or the personal data of your customers or other third parties through any Site feature or in correspondence with us. If you do, we will process it only as necessary to delete it or to protect you, us, or others, and Section 4 of our [Terms of use](/legal/terms) applies.

**Personal data of others.** If you provide us with personal data about another individual (for example, a colleague named in a support request), you confirm that you have provided that individual with any notice, and obtained any consent, required by applicable law for us to process that data as described in this notice.

## 3. How we use personal data

We collect, use, and disclose personal data for the following purposes:

* (a) **Operating the Site** — to deliver, host, and display the Site and its features, and to remember preferences stored in your browser.
* (b) **Security and integrity** — to monitor, detect, investigate, and prevent abuse, fraud, automated attacks, unauthorised scraping or automated access in breach of our Terms of use, unauthorised access, denial-of-service attacks, and other security incidents, and to maintain the reliability of the Site.
* (c) **Responding to you** — to respond to your enquiries, support requests, vulnerability reports, and requests to exercise your rights.
* (d) **Improving the documentation** — to understand, in aggregated or de-identified form where practicable, how the Site is used, which content is helpful, and where documentation can be improved.
* (e) **Legal and regulatory compliance** — to comply with applicable laws, regulations, court orders, and requests from public authorities, and to enforce our Terms of use.
* (f) **Legal claims** — to establish, exercise, or defend legal claims.
* (g) **Corporate transactions** — in connection with an actual or proposed merger, acquisition, restructuring, financing, or sale of all or part of our business or assets.

We do not use personal data collected through the Site to make decisions based solely on automated processing that produce legal or similarly significant effects on you. We do not use it to send you marketing messages unless you have separately consented, and any marketing messages we send to Singapore telephone numbers will comply with the Do Not Call provisions of the PDPA.

## 4. Consent and legal basis

4.1 We collect, use, and disclose personal data with your consent, including consent that is deemed under the PDPA — for example, where you voluntarily provide personal data to us for a purpose, or continue to use the Site after being notified of the purposes described in this notice.

4.2 We may also collect, use, and disclose personal data without consent where permitted by the PDPA or other written law, including where it is necessary for our legitimate interests (such as detecting and preventing fraud, security threats, and misuse of the Site), for business improvement purposes, for evaluative purposes, or to comply with law.

## 5. Disclosure of personal data

We do not sell personal data. We may disclose personal data to the following categories of recipients, only to the extent necessary for the purposes in Section 3:

* (a) **Service providers** acting on our behalf, including our documentation hosting platform provider (Mintlify, Inc.) and its subprocessors for cloud hosting, content delivery, search, and, where enabled, AI features , and network security and content delivery providers, such as Cloudflare, Inc., that protect our systems against automated attacks and abuse. Where these providers process personal data on our behalf as data intermediaries, they are permitted to do so only for the purposes of providing their services to us, and subject to contractual confidentiality, security, and retention obligations.
* (b) **CubePay Group companies**, including CubePay Group Pte Ltd and CubePay Pte Ltd, for administration, support, security, and legal compliance.
* (c) **Professional advisers**, such as lawyers, auditors, and insurers, under duties of confidentiality.
* (d) **Public authorities, regulators, and law enforcement agencies**, where required or permitted by law, or to protect the rights, property, or safety of us, our users, or others.
* (e) **Counterparties and advisers** in connection with a corporate transaction described in Section 3(g), subject to confidentiality obligations.
* (f) **Other parties with your consent** or at your direction — for example, when you choose to open Site content in a third-party AI tool, that transfer is made by you and is governed by the third party's privacy notice.

## 6. Transfers outside Singapore

6.1 Our service providers may process personal data outside Singapore, including in the United States and other countries where they or their subprocessors operate .

6.2 Where we transfer personal data outside Singapore, we take appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide the transferred personal data a standard of protection comparable to that under the PDPA, as required by the PDPA and the Personal Data Protection Regulations 2021 — for example, through contractual clauses, binding corporate rules, or recognised certifications held by the recipient.

## 7. Protection of personal data

7.1 We make reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal, and similar risks, and against the loss of any storage medium or device on which it is stored. These arrangements include access controls, encryption in transit, network security protections, and contractual security obligations on our service providers.

7.2 No method of transmission over the internet or of electronic storage is completely secure. While we take reasonable measures to protect personal data, we cannot guarantee its absolute security, and you transmit information to us at your own risk.

## 8. Accuracy

We make reasonable efforts to ensure that personal data we collect is accurate and complete where it is likely to be used to make a decision that affects you or disclosed to another organisation. You are responsible for ensuring that the personal data you provide to us is accurate and complete, and for telling us if it changes.

## 9. Data breaches

If we have reason to believe that a data breach affecting personal data in our possession or under our control has occurred, we will assess whether it is notifiable in a reasonable and expeditious manner. Where it is notifiable under Part 6A of the PDPA, we will notify the Personal Data Protection Commission, and affected individuals where required, within the timeframes required by the PDPA — for the Commission, no later than 3 calendar days after we determine that the breach is notifiable.

## 10. Retention

10.1 We retain personal data only for as long as retention is necessary for the purposes for which it was collected, or for legal or business purposes. After that, we delete or anonymise it, or cease to retain it in a form that identifies you.

10.2 As a guide:

| Data | Retention |
| - | - |
| Contact and correspondence data | Up to 3 years after the enquiry is closed, or longer if needed for a legal claim or regulatory requirement |
| Technical, usage, and security log data | Up to 12 months, unless needed for a security investigation or legal claim |
| Interaction data (search, assistant, feedback) | Up to 12 months, or in aggregated or de-identified form thereafter |
| Browser storage data | Held on your device until you clear it — see our Cookie policy |

Where personal data is held by a service provider under its own retention schedule, it is retained in accordance with that provider's obligations to us.

## 11. Your rights

11.1 Subject to the exceptions in the PDPA, you may:

* (a) **Access** — request access to personal data about you in our possession or under our control, and information about the ways in which it has been or may have been used or disclosed by us within the year before your request;
* (b) **Correction** — request correction of an error or omission in that personal data. Where we correct it, we will, where required by the PDPA, send the corrected personal data to other organisations to which we disclosed it within the year before the correction was made; and
* (c) **Withdraw consent** — withdraw your consent to our collection, use, or disclosure of your personal data, by giving us reasonable notice. We will inform you of the likely consequences of withdrawal — for example, that we may be unable to respond to your enquiry. Withdrawal does not affect our right to continue processing personal data where permitted or required by law without consent.

11.2 **How to make a request.** Send your request to our Data Protection Officer using the contact details in Section 14. We may need to verify your identity before acting on your request, and may decline requests where an exception under the PDPA applies. We will respond to access and correction requests as soon as reasonably possible and within 30 days, or, if we are unable to do so, tell you within that period when we will be able to respond. We may charge a reasonable fee for an access request, and will give you a written estimate of the fee in advance.

11.3 **Individuals outside Singapore.** If mandatory data protection laws of another jurisdiction apply to our processing of your personal data, we will handle your request in accordance with those laws to the extent they apply.

11.4 **Complaints.** If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore. We encourage you to contact us first so that we can try to resolve your concern.

## 12. Children

The Site is intended for business and technical users and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us and we will take appropriate steps to delete it.

## 13. Changes to this notice

We may amend this notice at any time by publishing a revised version on the Site and updating the "last updated" date. Where a change materially affects how we process personal data you have already provided, we will take reasonable steps to inform you where required by applicable law. Your continued use of the Site after a revised notice is published constitutes your acknowledgement of it.

## 14. Contact us and Data Protection Officer

For questions about this notice, or to exercise your rights, contact our Data Protection Officer:

* **Email:** [dataprotection@cubepayment.com](mailto:dataprotection@cubepayment.com)
* **Post:**<br />
  Data Protection Officer<br />
  Cube Payment Services Pte Ltd<br />
  163 Kallang Way, #03-15<br />
  Mapletree Hi-Tech Park<br />
  Singapore 349256
