Legal#
Using Povito Checkout is governed by the documents below. They are drafted by Povito and reviewed by Iraqi counsel (and, for the international set, counsel familiar with the Stripe contracting entity's jurisdiction) before publication. Until a document is published at its link, the link is a placeholder and the document is marked in review by counsel.
Nothing on this page is legal advice
It describes which documents exist, who they are for and where they will be published. Questions about your obligations go to your own counsel or to legal@povito.com.
Documents for merchants and developers#
| Document | Link | Audience | Languages | Status |
|---|---|---|---|---|
| Merchant Terms of Service (L-01) | /legal/merchant-terms | merchants | ar, en (ku summary) | in review by counsel |
| Developer / API Terms — keys, rate limits, sandbox, SDK licences (L-04) | /legal/api-terms | developers | en, ar | in review by counsel |
| Privacy Policy and the privacy notice shown at the phone step (L-06) | /legal/privacy | shoppers | ar, ku, en | in review by counsel |
Cookie and tracking notice for checkout.povito.com (L-07) |
/legal/cookies | shoppers | ar, ku, en | in review by counsel |
| Data Processing Agreement — Povito as processor for merchants — with the sub-processor list (GCP, Stripe, OTPIQ, the payment gateways) (L-08) | /legal/dpa | merchants | en, ar | drafting — Phase 2 |
| Refund, Cancellation and Dispute Policy (shoppers) and Chargeback Procedure (merchants) (L-09) | /legal/refunds | both | ar, ku, en | in review by counsel |
| Information Security Policy, PCI DSS SAQ A + AOC, ASV scan reports (L-11) | on request | merchants | en | in review |
| Accessibility Statement (L-19) | /legal/accessibility | shoppers | ar, ku, en | in review |
| Vulnerability Disclosure Policy (L-20) | /legal/security | public | en | in review — report to security@povito.com meanwhile |
| Brand and Trademark Usage — "Secured by Povito", logos (L-16) | /legal/brand | merchants | en, ar | drafting — Phase 2 |
| Customer Terms — Povito ID, saved instruments, consent to share (L-05) | /legal/customer-terms | shoppers | ar, ku, en | drafting — Phase 2 |
| Merchant Agreement and Fee Schedule (L-02), Acceptable Use Policy (L-03), Service Level Agreement (L-14) | — | external merchants | ar, en | Phase 3 — see below |
Complaints from shoppers are handled under the Complaints Handling Procedure (L-15, Consumer Protection Law No. 1 of 2010); the contact will be published with the refund policy.
Who Povito Checkout is for today#
Povito Checkout currently serves Povito's own storefronts — the marketplace and Povito's sector portals. Offering it to third-party merchants is a regulated activity in Iraq (Central Bank of Iraq Electronic Payment Services Regulation No. 3 of 2014 and instructions under the Central Bank Law No. 56 of 2004, with AML obligations under Law No. 39 of 2015) and is gated on a licensing decision by counsel and Povito's owner. Phase 3 — external merchants, KYB onboarding, a merchant ledger and payouts — does not start before that decision. If you are reading this as a prospective external merchant, contact partners@povito.com; nothing on this site is an offer of service.
Decisions#
The architecture and policy decisions behind the product are recorded as ADR-CHK-001 (D-44 to D-51) in Povito's internal decision log: a separate platform with its own repository; hosted-first with an embedded drop-in later; the Stripe presentment rule; the Povito-Signature webhook scheme; the OpenAPI file as the executable contract; and a shared React kit between the hosted page and the marketplace. They are summarised here so the docs can cite them; the log itself is internal.
Regulatory map (for reference)#
| Regime | Applies to |
|---|---|
| CBI Regulation No. 3 of 2014; PSP/aggregator licensing instructions | any flow of funds for third parties |
| AML/CFT Law No. 39 of 2015 | KYC/KYB, monitoring, reporting |
| Electronic Signature and Transactions Law No. 78 of 2012; Civil Code No. 40 of 1951; Commercial Law No. 30 of 1984 | terms, e-signatures, receipts |
| Consumer Protection Law No. 1 of 2010 | refund policy, disclosure, complaints |
| PCI DSS v4.0.1 | card acceptance — SAQ A, quarterly ASV scans |
| Card network rules via the acquirer (FIB Card, Stripe, later RT Bank) | surcharging, receipts, refunds, chargebacks |
| Apple Pay and Google Pay platform terms | wallets (Phase 2) |
| Stripe Services Agreement, Restricted Businesses | international cards |
| GDPR / UK GDPR | any EU/UK resident paying an international merchant |
| WCAG 2.1 AA (EN 301 549) | the hosted page |
Iraq has no comprehensive data-protection statute yet; Povito drafts to a GDPR-grade standard so nothing must be rebuilt when one passes.