AyeFace runs as a software overlay on any POS. Merchants get biometric checkout, cross-merchant loyalty, and AI-powered revenue tools โ without changing hardware.
Biometric POS overlay โ runs on any device, no hardware swap. Every face scan captures payment, loyalty redemption, and origin attribution in one transaction. Collab Hub lets you run joint campaigns with neighbouring merchants without exposing customer data.
Link all your payment methods and loyalty programs once. At any AyeFace terminal, choose face scan or QR โ payment, rewards, and receipt handled in under 2 seconds. Unified loyalty dashboard, nearby rewards, cross-border payments, and micro-investing all in one app.
Deploy in under a day โ no hardware swap, no POS migration required.
Connect AyeFace to your existing POS, payment gateway, and loyalty platforms through our API or plug-and-play app.
Configure AI agents, set reward rules, campaigns, and customer segments from the merchant dashboard.
Launch across locations. AI agents handle personalization, loyalty, and upselling autonomously.
Tailored configurations for every retail environment.
Use your existing SEA QR codes and cards at merchants in China via TenPay โ face-authenticated, no extra hardware.
Learn more โAuthorize AI agents to pay and earn loyalty on your behalf โ with biometric approval, per-agent spend limits, and full audit trails.
Learn more โYour Universal Checkout for All Merchants โ accept all payments, automate loyalty, and drive sales with AI agents.
Accept all payment methods while effortlessly converting every facial payment into seamless membership with our Payment Assistant.
Foster lasting loyalty with deep insights into customer behavior and real-time campaign rewards guided by our Loyalty Assistant.
Boost sales by automating upselling with AI Sales & Loyalty Agents, offering real-time personalized promotions.
The first payment infrastructure designed for AI agents acting on behalf of humans.
Southeast Asia QR codes and cards accepted directly in China via TenPay โ one click, biometric-authenticated, no hardware changes needed for merchants on either side.
Biometric approval for AI agents to transact. Full audit trail, revocable permissions, enterprise controls.
Streamline payment optimization, transactions, loyalty profile creation, and points accumulation into one cohesive customer journey.
Automate loyalty accumulation and redemption with personalized offers during payment. Easy management of campaigns and cross-merchant collabs.
Empower retailers with a co-pilot in self-ordering. Revenue intelligence for upselling, and prompt-based analytics on O2O data.
Authorization layer for AI agents to pay and earn loyalty on behalf of human principals. The infrastructure for the agentic economy.
Full compliance with GDPR for all EU data processing.
Consent-first biometric enrollment per Malaysia's PDPA.
End-to-end encrypted transactions with bank-grade protocols.
Facial data processed locally with explicit opt-in. View full compliance โ
Biometric POS overlay. Cross-merchant loyalty clearinghouse.
AI-attributed revenue. No new hardware.
Each pillar solves a specific merchant pain point โ and they compound when combined.
Software layer on any POS โ no hardware swap. One face scan authorises payment, loyalty redemption, and profile creation simultaneously.
Every transaction tagged with an origin signal โ which campaign, AI agent, or referral path drove the purchase. First-party attribution at checkout.
Cross-merchant loyalty clearinghouse. Run joint campaigns, share customer segments, and split reward budgets โ without exposing raw customer data.
Biometric identity as the trust anchor. Loyalty abuse, account sharing, and promo farming are structurally blocked.
VISA, Mastercard, DuitNow, TnG, GrabPay, ShopeePay and more โ accepted at every touch point via face or QR.
Real-time upsell recommendations at the point of scan. Context-aware โ basket size, visit history, time of day.
Automates reward timing, tier progression, and campaign targeting. 3ร redemption vs. static loyalty programs.
Prompt-based analytics on your O2O data. Ask in plain language โ get segment breakdowns, cohort trends, campaign ROI.
Run co-branded campaigns with neighbouring merchants. Shared budget, shared reach โ without data leakage.
Tag every sale back to the exact campaign or agent interaction that drove it. Real attribution at checkout.
Biometric liveness check blocks spoofing. Promo abuse and loyalty farming structurally prevented.
Multi-channel campaigns โ push, SMS, email โ with AI-driven segmentation and automated scheduling.
SEA QR codes and cards accepted in China via TenPay. One face, no currency friction.
Full compliance with EU GDPR and Malaysia's PDPA. Consent-first biometric enrollment.
End-to-end encrypted transactions. Facial templates processed locally, never stored as raw images.
One biometric identity across every merchant, loyalty program, and payment method โ on any device, in any country.
AyeFace Checkout runs on the merchant's device in-store, or on merchant's e-commerce online.
The merchant's device shows the AyeFace checkout screen facing the customer.
Look at the camera, blink once, select payment & rewards.
Scan the QR to launch AyeFace checkout on your web browser and complete the face scan & payment/rewards selection on your own device.
VISA, Mastercard, TnG, DuitNow, GrabPay, ShopeePay โ all linked to your AyeFace profile.
Loyalty points earned, campaigns applied, and receipt sent โ all in the same transaction.
9 features across payments, loyalty, and cross-border โ all on user.ayeface.com, no app download needed.
Link all your cards and e-wallets. Pick your preferred method at checkout โ or let AI optimize for rewards.
All your points, stamps, and memberships in one place. No more juggling ten different loyalty apps.
See live offers from merchants around you โ filtered by what you've actually bought before.
Refer friends and earn points when they transact. Both parties benefit โ across any Collab Hub merchant.
Convert points across merchants and programs at transparent rates. Your loyalty has real liquidity.
Set daily spend caps, redemption limits, and auto-save rules. Full control without touching individual apps.
Use your SEA payment methods at merchants in China via TenPay โ face-authenticated, zero extra setup.
Auto-save a percentage of every transaction into a locked savings goal. Savings can be held in stablecoins (USDC/USDT) to earn on-chain yield โ with biometric access only.
Round up transactions and invest spare change into ETFs or bonds. Loyalty points can seed your investment pot.
Facial recognition is never mandatory. Pay by QR code at any AyeFace terminal, always.
Request full data deletion from the portal. No facial templates retained after deletion. GDPR & PDPA compliant.
Every payment method, every merchant, every loyalty program โ one face.
As AI agents become economic actors โ booking, buying, subscribing โ AyeFace provides the identity, payment authorization, and loyalty infrastructure that keeps humans in control.
Authorize AI agents to transact on your behalf with a single biometric approval. Full audit trail, revocable at any time.
AI agents earn and redeem loyalty points on your behalf โ maximizing value across every autonomous transaction.
Set per-agent daily limits, merchant category restrictions, and auto-revoke triggers. Enterprise-grade, auditable controls.
Every agent transaction logged with biometric authorization evidence. Compliant with financial audit requirements.
Fund AI agents with USDC or USDT pools โ programmable money for autonomous commerce. Every disbursement requires biometric authorization from the human principal.
Expose your catalog, pricing, and checkout to AI agents via a single API. Accept agent-initiated payments the same way you accept human ones โ no separate integration needed.
Interested in early access for your AI infrastructure?
From order to loyalty in one scan
Whether counter service or full dining, AyeFace authenticates, tracks spending, and personalises the menu โ all before the customer says a word.
Face recognised on arrival. Regular orders pre-loaded. Repeat guests served faster every visit.
Real-time upsell at scan โ 'Add a drink for RM 2?' โ powered by past order history.
Points from every outlet in your F&B group aggregate automatically.
Know which items drive revisits and which hours to staff up.
Pay at the pump, earn on every fill
No more fumbling for wallets at the forecourt. Customers walk up, scan their face, and the pump authorises โ with loyalty points credited before the nozzle clicks off.
Face scan authorises the pump. No card, no app, no PIN. Works with existing forecourt POS.
Corporate fleet cards tied to biometric ID. Every fill logged against the driver profile.
Show a targeted offer on the pump screen mid-fill โ car wash, snacks, loyalty top-up.
Know your regulars, preferred fuel grade, average spend, and visit frequency.
One face, every store across your network
Multi-outlet chains get a unified customer identity layer โ same face recognised at every branch, loyalty consolidated, and campaign attribution tracked to the exact touchpoint.
One face profile works across every branch. Customers never re-enrol at a new location.
See visit frequency per branch, cross-branch basket overlap, and migration patterns.
AI agent adapts offers per customer based on history across all branches.
Franchise operators get local dashboards; HQ gets consolidated reporting. No IT lift.
Every tenant's loyalty, one shopper profile
Mall operators unlock the cross-tenant customer view they've never had. Shoppers accumulate points across every store in the mall โ without juggling separate apps.
One enrolment at the mall level. Points earned at any tenant, redeemed at any tenant.
Track dwell time, cross-tenant journeys, and conversion rates per zone or floor.
Shoppers receive personalised suggestions โ 'You might like the sale at L2' โ in-app.
New tenants join the loyalty network the same day they open.
Scan once, ride all day
Theme parks and leisure venues replace wristbands, paper tickets, and cash with a single face scan โ fast entry, per-ride loyalty, and AI-driven upsells between attractions.
Face scan replaces paper tickets and e-ticket QR codes. Eliminates queue at the gate.
Points earned per ride, per spend, per F&B purchase โ all under one park profile.
Between rides: 'Try the new rollercoaster โ 80 pts on your next scan.'
Know real-time density per zone, dwell time per attraction, and revenue per visitor.
Tap-free commuting, every journey counted
Commuters board buses, trains, and ferries with their face โ no card tap, no app scan. AyeFace handles fare deduction and loyalty credit simultaneously at the turnstile.
Biometric turnstile replaces transit card tap. Sub-3s throughput keeps platforms moving.
Points earned on bus, MRT, and ferry โ consolidated into one commuter profile.
Commuters see journey summaries, savings vs driving, and peak-hour nudges in-app.
Operators see real-time load, popular routes, and off-peak incentive effectiveness.
Start free โ scale with AI agents as your business grows. No upfront hardware costs.
Whether you're exploring AyeFace for a single store or a nationwide rollout, we'd love to hear from you.
Everything you need to know about AyeFace.
Still have questions? We're happy to help.
Company announcements, product launches, partnerships, and media coverage.
For press enquiries, interviews, or partnership announcements, contact our communications team.
Guidelines, assets, and press resources for journalists, partners, and collaborators.
We're a lean, high-impact team building AI infrastructure that powers how billions transact. Join us.
Work on products used across Southeast Asia and expanding globally.
Small teams, big responsibilities. Your work ships to production fast.
We build with AI, for AI โ and we're at the frontier of agentic commerce.
Last Updated: 1 October 2025
Aye Global Holdings Pte. Ltd. and its subsidiaries (collectively "Aye", "we", "our", or "us") are committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect personal data in connection with AyeFace services, and describes the rights you have with respect to your data.
This Policy applies to users of AyeFace applications, merchants and partners onboarded to the AyeFace platform, and visitors to our websites. By accessing or using AyeFace, you acknowledge that you have read and understood this Policy.
"Personal Data" means any information that relates to an identified or identifiable individual, including but not limited to name, identification number, biometric data, contact information, financial information, and behavioural data.
"Biometric Data" means facial recognition templates and related measurements derived from facial images, processed solely for identity verification and authentication within AyeFace.
"Processing" means any operation or set of operations performed on Personal Data, including collection, recording, storage, use, disclosure, or deletion.
"Data Subject" means any identified or identifiable natural person whose Personal Data is processed by Aye.
"Merchant" means any business entity that has contracted with Aye to accept payments and use AyeFace services at their point of sale.
"AyeFace Platform" means the collective software, APIs, applications, and associated services provided by Aye for biometric payment, loyalty, and AI-driven CRM features.
Data We Collect from Users: Identity data (full name, NRIC/passport number, date of birth); biometric data (facial recognition templates derived from facial scans); contact data (mobile number, email address); payment data (tokenised payment credentials, DuitNow IDs, transaction history); device data (device identifiers, operating system, IP address); behavioural data (purchase history, loyalty points, preferences, AI-generated insights).
Data We Collect from Merchants: Business registration information; authorised representative identity data; contact and billing information; POS device data; transaction records and performance metrics.
How We Use Your Data: To provide, operate, and improve AyeFace services; to verify your identity and authenticate transactions; to process payments and manage loyalty programmes; to personalise your experience through AI-driven recommendations; to comply with legal and regulatory obligations; to detect and prevent fraud and unauthorised access; to communicate service updates, promotions, and compliance notices; and to conduct research and analytics to improve our platform.
Data collected directly from you (registration, onboarding); automatically (device and usage data via the AyeFace application and POS terminals); from merchants (transaction and interaction data when you use AyeFace at their premises); and from third parties (payment processors, identity verification partners, and fraud prevention services).
Our websites and applications may use cookies, pixel tags, local storage, and similar tracking technologies to recognise your device, remember preferences, measure the effectiveness of communications, and analyse usage patterns.
Essential cookies are necessary for the platform to function and cannot be disabled. Analytics cookies help us understand how users interact with our services so we can improve them. Preference cookies allow us to remember your settings and choices.
You may control cookie preferences through your browser settings or our cookie preference centre. Note that disabling certain cookies may affect the functionality of AyeFace services. For mobile applications, similar device-level tracking may apply and can be managed through your device operating system settings.
Within the Aye Group: Personal data may be shared among Aye Global Holdings Pte. Ltd. and its subsidiaries for operational, administrative, and service delivery purposes, subject to this Policy.
With Merchants: We share only your store activity (transaction amounts, points earned, rewards redeemed) with the merchant where the transaction occurred. We do not disclose your identity, biometric data, or payment credentials to merchants.
With Service Providers: We engage trusted third-party providers for cloud hosting, payment processing, identity verification, fraud prevention, analytics, and customer support. These providers are bound by data processing agreements and are permitted to use your data only as directed by Aye.
For Legal Compliance: We may disclose personal data where required by applicable law, court order, regulatory authority, or to protect the rights, property, or safety of Aye, its users, or the public.
Corporate Transactions: In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to continued protection under equivalent terms.
We do not sell personal data to third parties for their own marketing purposes.
Aye operates across Southeast Asia and may transfer personal data to jurisdictions outside your home country, including Singapore, Malaysia, and other locations where our service providers operate.
Where personal data is transferred across borders, we ensure that appropriate safeguards are in place, such as standard contractual clauses, adequacy decisions, or binding corporate rules, in accordance with applicable data protection laws including the Malaysian Personal Data Protection Act 2010 (PDPA), Singapore PDPA, and GDPR where applicable.
By using AyeFace services, you consent to the transfer of your personal data to our processing locations as described in this Policy. We will always ensure that cross-border transfers are subject to protections at least equivalent to those in your home jurisdiction.
We process personal data on the following legal bases:
Consent: For biometric data collection, marketing communications, and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Contractual Necessity: To provide AyeFace services, process payments, and fulfil our obligations to users and merchants under applicable Terms and Conditions.
Legal Obligation: To comply with applicable laws and regulations, including anti-money laundering (AML), know-your-customer (KYC), and financial reporting requirements.
Legitimate Interests: For fraud prevention, security, service improvement, analytics, and network integrity, where these interests are not overridden by your data protection rights.
For special categories of data (biometric data), we rely on explicit consent and applicable exemptions under data protection law.
We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction.
Technical measures include: AES-256 encryption for data at rest; TLS 1.2+ encryption for data in transit; biometric template tokenisation โ raw facial images are not stored; multi-factor authentication for platform access; Presentation Attack Detection (PAD) compliant with ISO/IEC 30107; regular penetration testing and vulnerability assessments; and SOC 2-aligned infrastructure controls.
Organisational measures include: role-based access controls (least privilege); mandatory data privacy training for all staff; data processing agreements with all third-party providers; incident response and breach notification procedures; and regular privacy impact assessments for new features.
In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant authorities in accordance with applicable law.
Subject to applicable law, you have the following rights regarding your personal data:
Right of Access: Request a copy of the personal data we hold about you.
Right to Correction: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data where there is no legitimate ground for continued processing.
Right to Restrict Processing: Request that we limit how we process your data in certain circumstances.
Right to Data Portability: Receive your personal data in a structured, machine-readable format where processing is based on consent or contract.
Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent: Withdraw consent for biometric data processing or marketing at any time without penalty.
To exercise your rights, contact us at dpo@aye-ai.org or through the AyeFace User Portal. We will respond within 30 days. Requests may be subject to identity verification. You also have the right to lodge a complaint with your local data protection authority.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
User account data is retained for the duration of your account and for 7 years after account closure for legal and audit compliance. Biometric templates are deleted within 30 days of account closure or consent withdrawal. Transaction records are retained for 7 years to satisfy financial regulatory requirements. Marketing data is retained until you withdraw consent or opt out.
Where data is no longer required, we securely delete or anonymise it in accordance with our data retention schedule. Anonymised, aggregated data may be retained indefinitely for research and analytics purposes.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
Data Protection Officer
Aye Global Holdings Pte. Ltd.
Email: dpo@aye-ai.org
For complaints or concerns: complaints@aye-ai.org
We are committed to resolving data privacy concerns promptly. If you are not satisfied with our response, you may escalate to the relevant data protection authority in your jurisdiction.
This Privacy Policy is effective as of 1 October 2025. We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Material changes will be communicated to you via in-app notification, email, or prominent notice on our website at least 14 days before taking effect. Your continued use of AyeFace services after the effective date of any update constitutes acceptance of the revised Policy.
We encourage you to review this Policy periodically. The "Last Updated" date at the top of this page indicates when the Policy was most recently revised.
Last Updated: 25 November 2025
In these AyeFace User Terms and Conditions ("Terms"), references to "You", "Your" and "Yours" refer to the individual end user utilising the AyeFace service. References to "We", "Our", "Ours" and "Us" refer to Aye Global Holdings Pte. Ltd., providing AyeFace services to You.
Aye Global Holdings Pte. Ltd. wholly owns Aye Solutions Sdn. Bhd., and these Terms are binding with respect to any contracts or engagements entered into with Aye Solutions Sdn. Bhd. in connection with AyeFace services.
These Terms govern Your access to and use of the AyeFace platform, including biometric verification, automated payment features, and AI-driven personalisation. By using AyeFace, You agree to be bound by these Terms and acknowledge that Your Personal Data will be processed in accordance with Our Privacy Policy and applicable data protection laws (Malaysian PDPA, Singapore PDPA, and GDPR where applicable).
"AyeFace" means the software-based biometric payment solution comprising facial recognition functionality, customer onboarding, AI CRM integration, and transaction processing interfaces, including mobile applications, APIs, and associated features.
"AyeFace Account" means the account registered by You, including Your biometric profile, associated payment methods, AI-generated preferences, and consent records.
"Auto DirectDebit" means the payment authorisation mechanism whereby You consent to automated fund transfers from Your designated bank or e-money account linked to a DuitNow ID, subject to Your revocable consent.
"DuitNow ID" means a commonly recognised identifier (mobile number, NRIC, passport number, or business registration number) used to link a bank or e-money account for DuitNow transactions.
"Merchant" means any business or entity participating in the AyeFace ecosystem that accepts payments via AyeFace and offers products or services to You as a Customer.
"User Portal" means the digital platform through which You can manage Your AyeFace Account, payment methods, rewards, preferences, and exercise Your data protection rights.
These Terms set out the conditions for Your use of AyeFace services, including the AI features and Facial Recognition Payment service. AyeFace allows You to initiate payments to participating Merchants using facial recognition, through payment methods linked to Your AyeFace Account โ including bank or e-money accounts via DuitNow ID, credit or debit cards, regional e-wallets, and other alternatives as may be introduced.
While AyeFace facilitates payments and personalisation, all payment processing is conducted by the respective merchant acquirers connecting to authorised financial institutions, card issuers, or e-wallet providers. AyeFace does not itself hold, receive, or transfer funds. We are not a bank, e-money issuer, or payment institution.
You may register at user.ayeface.com/register. To register, You must complete a facial capture process and set a PIN for verification. By completing registration, You confirm that You are at least 18 years old and capable of entering into a binding contract.
You may link a payment method including: a credit or debit card; a bank or e-money account via DuitNow ID; or a supported e-wallet account. By linking a payment method, You consent to Us securely storing Your payment details in encrypted form, solely to facilitate future payments. Full card or bank credentials are not stored directly โ we rely on tokenisation provided by licensed payment processors.
Once a payment is confirmed via AyeFace, it is considered final and irrevocable, except in cases of fraud, unauthorised use, or error. Such cases are subject to investigation by the relevant financial institution.
Through the User Portal, You may manage payment methods (add, update, remove), suspend or revoke consent, set payment limits, enable/disable PIN verification, manage notification preferences, view and track eligible rewards, and obtain referral codes.
We will notify You 7 days before Your payment method consent expires. If expired, a new consent must be submitted. You can view transaction history including ID, timestamp, and merchant info. For disputes, contact complaints@aye-ai.org with the transaction ID.
You must take reasonable precautions to keep login credentials confidential. You are responsible for all account activity until You notify Us of any unauthorised use.
By making Your first payment at a merchant using AyeFace, You consent to automatic enrollment into that merchant's membership program (if enabled), in accordance with the merchant's terms. AyeFace does not guarantee membership benefits.
No personal information other than Your store activity (purchases, points earned, rewards redeemed) is shared with merchants. You may receive promotional messages facilitated by AyeFace without merchants accessing Your personal data directly. You may opt out at any time by emailing complaints@aye-ai.org.
AyeFace may also create its own rewards programmes, which may be changed, edited, or removed at AyeFace's discretion.
When You register, Your facial features are captured and converted into a unique, tokenised template using secure encryption. This biometric data is processed solely for recognition, authentication, and personalisation within AyeFace.
AI features may include personalised prompts, menu recommendations, targeted marketing, and contextual suggestions based on Your preferences and purchase behaviour. AI is not used to initiate, authorise, or complete payments โ all payment transactions require explicit action by You.
We employ Presentation Attack Detection (PAD) and anti-spoofing measures consistent with ISO/IEC 30107 standards. AyeFace does not perform automated decision-making producing legal or significant effects without human oversight.
You acknowledge that AI and biometric technologies are probabilistic and may not always be accurate. Performance may be affected by environmental factors such as lighting or device quality.
You may initiate a refund request by contacting the relevant merchant directly with the transaction ID. Refunds will only be processed once approved by the merchant and returned to Your original payment method.
For erroneous or unauthorised payments, initiate a dispute directly with Your financial institution or payment provider. AyeFace Support (complaints@aye-ai.org) may assist in investigation but is not a payment processor and cannot directly refund amounts.
Where a wrongful transaction is confirmed as caused solely by a proven AyeFace system malfunction, We will facilitate a refund through the relevant payment processor. Your full cooperation with investigation is required.
To the fullest extent permitted by law, We shall not be liable for losses arising from: Your use of AyeFace services; errors or delays in payment processing by financial institutions; accuracy of biometric verification or AI outputs; unauthorised account access due to Your failure to safeguard credentials; or service interruption, except where caused by Our proven gross negligence or wilful misconduct.
You agree to indemnify Us against claims arising from Your breach of these Terms, unauthorised use of AyeFace, or violation of third-party rights. Nothing in these Terms limits liability for death or personal injury caused by Our gross negligence or fraud.
Contact Us: complaints@aye-ai.org
We will acknowledge complaints within seven (7) working days and provide a substantive response within one (1) calendar month. This does not affect Your rights to escalate to relevant supervisory authorities.
Amendments: We may amend these Terms with at least thirty (30) days' prior notice via email, the AyeFace portal, or Our official website. Continued use after the effective date constitutes acceptance.
Governing Law: These Terms are governed by the laws of Malaysia. You submit to the exclusive jurisdiction of the courts of Malaysia, without prejudice to mandatory consumer protection laws of Your country of residence.
International Data Transfers: EU Standard Contractual Clauses (SCCs) apply automatically for cross-border transfers subject to EU/UK data protection regulations. See: commission.europa.eu/standard-contractual-clauses
Severability, No Waiver, Entire Agreement: Standard provisions apply. In the event of conflict between these Terms and the Privacy Policy regarding personal data, the Privacy Policy shall prevail.
Last Updated: 11 February 2026
In these AyeFace Merchant Terms and Conditions ("Terms"), references to "You", "Your", "Yours" refer to the merchant utilising AyeFace services. References to "We", "Our", "Ours", "Us" refer to Aye Global Holdings Pte. Ltd.
Aye Global Holdings Pte. Ltd. wholly owns Aye Solutions Sdn. Bhd., and these Terms are binding with respect to any contracts entered into with Aye Solutions Sdn. Bhd. in connection with AyeFace services.
These Terms govern Your access to and use of the AyeFace platform, including facial recognition functionality, CRM features, and AI-driven personalisation tools. By using AyeFace, You agree to be bound by these Terms and to comply with all applicable data protection laws (Malaysian PDPA, Singapore PDPA, and GDPR where applicable), including ensuring necessary notices and consents are obtained from Your Customers.
"AyeFace" means the software-based biometric payment solution comprising facial recognition functionality, customer and merchant onboarding, AI CRM integration, and transaction processing interfaces.
"AyeFace Virtual Terminal Account" means the account registered by You to operate the AyeFace application installed on the Device.
"Confidential Data" means business information relating to the performance and operations of Your store(s), including sales data and store metrics.
"Customer Personal Data" means any information relating to an identified or identifiable individual who interacts with You via AyeFace, including biometric identifiers, transaction data, and contact details.
"Device" means the tablet, kiosk, or other equipment on which the AyeFace Virtual Terminal is installed.
"Merchant Portal" means the account and platform provided under an active Basic or Pro subscription, including the integrated CRM suite with loyalty automation, sales analytics, and AI agents.
"Subscription Tier" refers to the level of plan selected by You (Free, Basic, or Pro), determining the features available.
"Virtual Terminal" means the AyeFace application interface enabling Customers to interact with facial recognition, place orders, make payments, and interact with AI components.
These Terms govern Your use of AyeFace services including facial recognition payment functionality, AI features, CRM tools, Virtual Terminal features, and payment processing features available under your selected Subscription Tier (Free, Basic, or Pro).
Your use is subject to the limitations and inclusions of the plan selected. Access to certain features, such as the Merchant Portal and advanced CRM analytics, is available only to Basic and Pro tier subscribers. Free plan users have access to core biometric payment functionality only.
If subscribed to a Basic or Pro plan, You will be issued login credentials to access the Merchant Portal. The Merchant Portal is not available to Free plan merchants.
Through the Merchant Portal, You may create and manage one or more AyeFace Virtual Terminal Accounts. You are solely responsible for the accuracy of all information entered and for keeping it updated.
You must protect the confidentiality of all login credentials, use strong passwords, and employ multi-factor authentication where provided. Any use of Your account(s) will be deemed to have been made by You. Notify Us immediately of any suspected security breach.
AyeFace offers three subscription tiers: Free, Basic, and Pro. The Free plan allows limited access to the Virtual Terminal only. Basic and Pro plans include full Merchant Portal access, CRM tools, AI agents, and analytics.
Trial users: We will notify You at least fourteen (14) days prior to trial expiry. Unless cancelled before expiry, Your account automatically converts to the monthly subscription plan, and applicable charges will be applied to the payment method provided.
Post-trial, if You do not continue with a paid subscription, You may request an export of Customer Personal Data and Confidential Business Data within thirty (30) days of trial expiry. After this period, such data will be securely deleted or anonymised.
AyeFace is a software-based service. We do not manufacture, sell, lease, or supply any hardware. Devices procured through Our authorised hardware partners are governed solely by Your agreement with that hardware provider. We disclaim any warranties relating to the Device.
You are responsible for ensuring the Device meets minimum technical and connectivity requirements. We are not liable for service disruptions from Device-related issues including hardware faults, software conflicts, or power/internet interruptions.
The AyeFace service includes AI functionality designed to enhance Customer engagement and provide data-driven insights. You acknowledge that AI outputs are probabilistic and intended to support, not replace, human judgment. You are solely responsible for evaluating AI-generated recommendations before acting upon them.
AI features process data in accordance with Our Privacy Policy. We reserve the right to improve, modify, or update AI features at Our discretion, including changes to models or training data, without prior notice.
Subscription fees are billed automatically based on Your selected billing cycle (monthly or annual). All prices are exclusive of applicable taxes. In the event of non-payment: We may suspend or terminate access; interest accrues at 10% per annum from the due date; and We reserve the right to recover collection costs including legal fees.
We will provide at least thirty (30) days' advance notice of any price adjustments. Your subscription renews automatically unless cancelled. All payments are non-refundable except where required by applicable law.
All merchants will be provided with a settlement account through the mutually appointed merchant acquirer. All transaction settlements, timing, reconciliation, disbursement, chargebacks, and related fees are subject solely to the terms of the appointed merchant acquirer. We are not a party to settlement arrangements and are not responsible for any settlement-related issues.
You may cancel Your subscription at any time. Monthly plan cancellations retain access until end of current paid month (no refunds). Annual plan cancellations retain access until end of paid annual period (no refunds for unused months).
We may suspend, restrict, or terminate access if: You materially breach these Terms; You fail to pay outstanding fees after notice; required by law or regulatory request; or Your use poses a security risk. Termination does not release either party from obligations incurred prior to the effective date.
For cancellation or plan changes, contact: merchants@aye-ai.org with at least fourteen (14) working days' advance notice.
To the maximum extent permitted by law, We shall not be liable for: losses from Your use of AyeFace services; AI-generated outputs or recommendations; inaccuracies in analytics; Device issues; or actions of hardware vendors or third-party partners.
You agree to indemnify Us against claims arising from Your breach of these Terms, misuse of AyeFace, Customer or third-party claims relating to Your business operations, negligent or unlawful acts by You or Your employees, or breach of data protection laws.
Nothing in these Terms excludes liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation.
We process all data in accordance with the Malaysian PDPA, Singapore PDPA, GDPR, and Our Privacy Policy.
For Customer Personal Data collected through the AyeFace User Portal, We act as data controller. For data generated through Your store interactions, You act as data controller. Each party shall comply with its respective obligations under applicable data protection laws.
Any AI model training or performance insights are based solely on anonymised and aggregated AyeFace User data. Merchant Data is not used for these purposes.
If a personal data breach occurs affecting Customer Personal Data, We will notify You without undue delay and provide reasonable assistance for Your legal compliance obligations.
Amendments: at least thirty (30) days' prior notice, except where immediate changes are required by law or security. Notice via email, Merchant Portal, or Our website. Continued use constitutes acceptance.
Governing Law: Laws of Malaysia. Exclusive jurisdiction of Malaysian courts.
International Data Transfers: EU Standard Contractual Clauses apply automatically for cross-border transfers subject to EU/UK regulations. See: commission.europa.eu/standard-contractual-clauses
Data Retention: Data retained only as long as necessary for service delivery, compliance, and legal obligations. Securely deleted or anonymised upon termination after a reasonable retention period.
Merchant contact: merchants@aye-ai.org
Enterprise-grade security infrastructure underpinning every AyeFace transaction.
Full technical security: GitHub โ | Technology stack: GitHub โ
General Data Protection Regulation. Full compliance for all EU data subjects including rights of access, erasure, portability, and consent withdrawal.
Personal Data Protection Act 2010. Consent-first biometric enrollment, data minimisation, and subject access request handling.
Personal Data Protection Act 2012 (amended 2021). Mandatory breach notification, data portability obligation, and enhanced consent framework for biometric data.
Data Privacy Act of 2012 (Republic Act 10173). NPC-registered data processing with explicit consent for sensitive personal information including biometrics.
Personal Data Protection Act B.E. 2562 (2019). Explicit consent for biometric data as a sensitive data category, data subject rights, and cross-border transfer controls.
Personal Data Protection Decree 13/2023/ND-CP. Biometric data classified as sensitive, mandatory impact assessments, and prior consent for collection and processing.
Personal Data Protection Law No. 27/2022. Explicit consent for biometric and sensitive data, mandatory DPO appointment, and two-year compliance transition period.
Personal Data Protection Order 2021. Consent-based processing, data subject access and correction rights, and cross-border transfer obligations.
Operating under applicable ASEAN data governance frameworks and Cambodia's e-Commerce Law pending a dedicated personal data protection law. Consent-first practices applied.
Operating under Laos' Electronic Data Protection provisions and ASEAN regional frameworks pending comprehensive data protection legislation. Consent-first practices applied.
All transactions and biometric templates are encrypted in transit (TLS 1.3) and at rest (AES-256). Raw facial images are never stored.
Compliant with Visa, Mastercard, and PayNet security standards. Tokenized payment credentials โ no raw card data stored.
Multi-tenant cloud infrastructure with regional data residency options. 99.9% uptime SLA. Auto-scaling, DDoS protection, and WAF.
Immutable audit logs for all transactions, biometric events, and admin actions. Tamper-evident logging for compliance and forensics.
Discovered a security vulnerability? We take all reports seriously and aim to respond within 24 hours.
Report a Vulnerability