Checkout friction
Open app, scan, input, confirm and wait-especially costly at peak hours.
Trusted PalmPay connects Palm Vein and Palm Print identity, VNeID-assisted onboarding, Open Banking virtual-account top-up, closed-loop prepaid value, loyalty and managed palm terminals in one bank-merchant platform.
From verified identity to funded wallet and palm-authorized checkout.
Reference-device benchmark. End-to-end performance depends on device profile, network, integration, matching policy and deployment conditions.
QR and mobile apps digitized payment, but high-frequency checkout still carries friction. Trusted PalmPay turns identity into a secure transaction touchpoint and connects payment, loyalty and operational data at the moment of sale.
Open app, scan, input, confirm and wait-especially costly at peak hours.
Banks need trusted off-app touchpoints that increase transaction frequency and ecosystem engagement.
Retailers need shorter queues, clearer reconciliation and loyalty activated directly at checkout.
Users increasingly expect natural, contactless and device-independent experiences.
PalmPay is not a standalone scanner. It is an operating platform that coordinates identity, value, loyalty and auditable transaction data.
Contactless, fast and policy-controlled payment at the point of sale.
Palm Print / Palm Vein linked to a verified customer profile and consent lifecycle.
Points, offers, vouchers, cashback and member-tier rules at checkout.
Real transaction events and operational insight for authorized bank and merchant use.
| Criteria | Current QR / app | Trusted PalmPay |
|---|---|---|
| Steps | Open app, scan, input and confirm | Present palm; authenticate and pay |
| Dependency | Phone, battery, connectivity and user actions | No phone or OTP at checkout after enrollment |
| Identity | Often separate from payment context | Biometric identity linked to the transaction |
| Loyalty | Frequently fragmented or applied later | Rules applied directly at the payment touchpoint |
| Data | Limited identity-to-transaction continuity | Authorized identity, transaction and behavior signals |
Customers download the PalmPay Client, store teams use PalmPay Merchant, enterprise users sign in to governed portals, and new banks or merchant chains follow controlled onboarding and device activation journeys.
CUSTOMERS
Enroll, manage consent, choose merchant wallets, top up through an assigned VA, pay by palm, view receipts and use loyalty benefits.
STORE OPERATIONS
Monitor payment status, shifts, devices, receipts, permitted refunds, loyalty actions and store-level exceptions.
WEB-BASED PORTALS
Govern tenants, stores, users, transactions, Open Banking, devices, loyalty, approvals, reconciliation, security and audit.
GET STARTED
Register a merchant chain, bank integration or PalmPay Device through readiness assessment, verification, configuration, UAT and go-live approval.
Trusted PalmPay connects banking rails, merchant operations, palm identity and customer engagement in one governed operating model. Each participant keeps a clear role, measurable value and auditable responsibility.
Enrollment, funding and payment are deliberately separated so banks, merchants and end users understand who does what, where money moves and how consent is enforced.
Trusted PalmPay coordinates identity, reconciliation and the merchant-specific internal ledger. In the reference model, customer funds move directly to the merchant's bank account through the assigned virtual account; PalmPay does not receive or hold customer funds. Final legal roles, licensing, safeguarding and settlement responsibilities must be confirmed for each bank-merchant deployment.
Transfers from bank app to an assigned VA
Posts funds to the merchant account and sends a trusted credit notification
Reconciles the credit and updates the customer ledger for that merchant chain
Receives funds and accepts internal-value payment at its own points of sale
Identity proofing, consent, palm enrollment and payment activation are separated into auditable steps. VNeID may support identity verification through an approved integration and contractual access model; production scope must be agreed with the authorized service owner.
Customer starts onboarding in Palm Client, bank app, merchant app or an assisted enrollment station.
Verify identity attributes and transaction context through the approved VNeID/RAR integration path when applicable.
Display purposes, data categories, retention, sharing, withdrawal and fallback before palm enrollment.
Capture Palm Print and/or Palm Vein, run quality and PAD/liveness controls supported by the approved device profile.
Create a protected biometric reference and bind it to the verified customer profile without placing wallet data in the biometric domain.
Activate allowed use cases; support suspension, revocation, re-enrollment, device loss and consent withdrawal.
Production onboarding should combine identity assurance, operator/device authorization, biometric quality, presentation-attack controls, signed evidence, policy versioning and a clear exception path.
Open Banking connectivity and a customer-specific Virtual Account (VA) are the bridge between real money in the banking system and the internal balance used for fast palm checkout.
Map customer, merchant chain, bank account and reference context with controlled lifecycle and reconciliation rules.
Receive bank webhook/event with authentication, signature validation, timestamp, replay protection and source allow-listing.
Apply idempotency, amount/reference validation, exception handling and an auditable internal ledger entry.
Expose unmatched, duplicate, reversed, delayed and manually reviewed cases to bank and merchant operations.
In the reference closed-loop model, real funds move directly into the merchant's bank account. Trusted PalmPay receives the trusted transaction notification and manages the merchant-specific internal balance; it does not receive or hold customer funds. Licensing, safeguarding, settlement, refund and consumer-protection roles must be agreed for each deployment.
The platform separates biometric trust from the prepaid ledger, applies zero-trust controls at integration boundaries and preserves a clear audit trail from device request to business outcome.
The reference terminal combines contactless palm capture with a merchant-facing display and integration options for USB-host or direct-backend operation. Device selection, liveness/PAD controls, template strategy and retention policy are validated during the PoC.
The palm terminal can operate as a USB-controlled peripheral for an existing POS/PC or as a directly connected managed endpoint. The same hardware can support payment, attendance, access, identity verification and approved custom workflows.
Actual ports, radio modules and biometric capabilities depend on the approved terminal variant and supplier specification.
Render approved screens for amount, merchant, order, check-in, identity, consent, result and notifications. The terminal never invents business values.
HOST or backend initiates a 1:N identification request; device returns the result and correlation reference through the same controlled mode.
Bind the transaction to a claimed user or token for 1:1 verification, step-up authentication or high-risk confirmation.
Support payment, attendance, access control, identity verification and custom workflows with policy-separated application contexts.
Inventory, enrollment, certificates, configuration, firmware, logs, health, alerts, remote disable and audit.
OpenAPI 3.1, TLS 1.3+, mTLS, MQTT 5.0, idempotency keys, correlation IDs, error model and supplier protocol deliverables.
A production website should show only approved partner names and logos. The structure below is ready for connected, pilot and integration-ready partners without implying participation before written approval.
Bank-led ecosystem / Merchant-chain rollout / Device/SDK partnership / POS/ECR integration / Channel deployment / Loyalty/affiliate network
PalmPay onboarding combines commercial qualification, business verification, integration readiness, security review, store and device setup, UAT and go-live governance.
Business identity, tax code, representative, project owner, locations and selected capabilities.
Authority, identity path, privacy roles, systems, bank relationship, POS landscape and deployment scope.
Enterprise owner, administrators, stores, roles, wallet model, loyalty, bank adapters and policies.
Model, serial, firmware, store, terminal mode, certificate, network, POS binding and support owner.
Open Banking events, VA mapping, POS/ECR, palm workflows, exception cases, reconciliation and reporting.
Acceptance evidence, security approval, operating procedures, support model, SLA and rollback readiness.
PalmPay separates monetary balance from points, applies configurable earn and redemption rules, supports internal, cross-merchant and affiliate programs, and preserves a complete point-ledger and reconciliation trail.
Merchant wallet balance and loyalty points are independent value domains with separate states, controls and audit evidence.
Earn rate, product eligibility, campaign multiplier, member tier, cap, rounding, waiting period and expiry are policy-driven.
Internal, cross-merchant and affiliate redemption use approved relationships, exchange tables, budgets and settlement rules.
Refund, failed redemption, expiry, merchant suspension, suspected fraud and administrative adjustment follow explicit state transitions.
EARN FLOW
POINT LIFECYCLE
REDEMPTION
Pending, available, reserved, redeemed, expired, revoked and reversed balances.
Eligibility, rate, tier, campaign, cap, rounding and anti-duplication controls.
Availability check, reservation, conversion, confirmation, release and reversal.
Audience, store, product, period, budget, member tier and maker-checker approval.
Merchant relationships, conversion ratios, coefficients, limits and effective dates.
Point liability, issue/redeem/expire/reverse totals, payables, receivables and campaign KPIs.
Palm biometrics are sensitive data. The website describes engineering controls and deployment expectations-not a blanket compliance certification. Every production arrangement requires documented legal, security, privacy and bank-risk approval.
Separate biometric services and templates from wallet/ledger data to reduce blast radius and simplify access governance.
Device identity, mTLS, signed requests, nonce/replay controls, rate limiting and API gateway policy.
Encrypted transit and storage, least privilege, key management, quality thresholds and configurable retention.
Idempotency, double-entry or equivalent ledger controls, state machines, reversals, reconciliation and immutable audit evidence.
Purpose-specific notice, explicit consent where required, withdrawal, re-enrollment, retention and data-subject workflow.
Monitoring, alerting, incident response, vulnerability management, penetration testing and controlled change.
Reference framework for deployment review in Viet Nam: regulations on non-cash payments, payment services/intermediaries, banking online-service security, cybersecurity and personal-data protection. Applicability depends on the contractual model, data flows, licensed parties and final system design.
Standards are used as engineering and test references, not as unqualified certification claims. The applicable edition, scope, laboratory evidence and contractual acceptance criteria must be confirmed for the selected device and deployment.
Reference for PAD performance testing and reporting of the selected palm capture profile.
Evidence: attack taxonomy, test plan, APCER/BPCER or applicable metrics, limitations.Reference for protected biometric references, identity binding, storage/comparison models and privacy.
Evidence: threat model, template protection, renewability/revocability, access model.Reference for risk management, governance, operational controls and continual improvement.
Evidence: scoped ISMS, risk treatment, control ownership, audit and incident processes.Reference for authorization, authentication, resource control, inventory and unsafe consumption risks.
Evidence: threat model, API tests, gateway policies, secure SDLC and remediation records.Secure channels, mutual identity, authorized topics, certificate lifecycle and replay-resistant messages.
Evidence: cipher policy, PKI profile, topic ACL, rotation and revocation tests.Versioned APIs, idempotency, correlation, error semantics, event schema and traceability.
Evidence: API specification, conformance tests, audit mapping and operational runbook.Small-ticket, repeat purchases and peak-hour queue pressure.
Fast checkout, loyalty and store-level reconciliation.
Closed community, repeat users and measurable adoption.
Identity, service journey and payment can be linked with strict privacy boundaries.
B2B2C programs, employee benefits and controlled enrollment.
Scale, multi-store operations and deeper POS/CRM integration.
Dedicated environment with controlled tenancy, keys, networks and data residency.
Deploy core services inside customer-controlled infrastructure and security zones.
Keep sensitive services and ledgers in controlled zones while integrating managed components.
REST APIs, events and adapters for POS/ECR, mobile, CRM, ERP, BI and bank systems.
Align use case, roles, money flow, target KPI and risk assumptions.
Deploy 1-3 locations, enroll a controlled cohort and measure performance.
Standardize operations, integrate loyalty, reconciliation, support and SLA.
Scale by location, merchant group and authorized ecosystem partners.
The blocks below show how customer channels, administration, palm trust, payment value, loyalty and external integrations work together.
1-3 locations; controlled users; basic payment, balance and KPI dashboard.
5-20 locations; POS/ECR integration; loyalty basics; shift and transaction reconciliation.
Open Banking, virtual accounts, merchant acquiring integration, campaigns and behavioral analytics.
Multi-chain scale, CRM/ERP/BI integration, 24/7 operations, security assurance and SLA.
A high-resolution business overview is included for workshops and internal alignment. Every key point also appears as accessible HTML on this page.
Open high-resolution overview ↗
Search-focused topic pages provide the depth that a single landing page cannot.
How palm identity, wallet value and payment orchestration work together.
↗Dual operating modes, dynamic UI, interfaces and device management.
↗Money flow, bank events, reconciliation and closed-loop ledger controls.
↗Identity-assisted onboarding, consent, biometric binding and lifecycle.
↗Biometric protection, PAD references, API security and assurance gates.
↗Bank, merchant, device, POS and deployment partnership models.
↗Point ledger, earn/redeem rules, cross-merchant exchange and reconciliation.
↗Entry points for customers, stores, enterprise users and partners.
↗Business registration, verification, integration readiness, UAT and go-live.
↗Claim, provision, bind, test, activate and operate PalmPay terminals.
No. The device is one component. Trusted PalmPay combines enrollment, palm biometrics, trusted APIs, payment orchestration, a merchant-specific internal ledger, loyalty, reconciliation and bank connectivity.
In the reference closed-loop model, funds move directly to the merchant bank account through an assigned virtual account. PalmPay reconciles the credit and maintains an internal ledger. The production legal and licensing model must be agreed by the bank, merchant and advisors.
The recommended design avoids retaining raw palm images on the POS. The final answer depends on the selected device, SDK, matching architecture, diagnostic settings and approved retention policy.
No universal guarantee is made. The figure is a reference-device recognition benchmark. End-to-end latency must be measured in the target deployment.
Yes, subject to integration assessment. PalmPay is designed around APIs, event-driven integration and adapters for POS/ECR, Open Banking, CRM, ERP and analytics systems.
Begin with a controlled environment, define success metrics before deployment, prefer 1:1 verification first, validate privacy and security controls, then expand by measured evidence.
The customer transfers from their bank app to a customer-specific VA mapped to the selected merchant chain. The bank posts funds directly to the merchant account and sends a trusted credit notification. PalmPay reconciles the event and credits the merchant-specific internal ledger.
VNeID may support identity verification through an approved integration and contractual access path. PalmPay still needs purpose-specific notices, consent, enrollment evidence and lifecycle controls for the palm credential.
HOST/USB mode lets an existing POS or PC control the terminal through a documented USB protocol. Direct Backend mode lets the PalmPay backend control the device through OpenAPI and MQTT over protected network channels.
Yes, the multi-application design can support attendance, access control, identity verification and approved custom workflows, subject to device capability, policy separation and deployment approval.
Tell us the bank, merchant environment, target locations and systems to integrate. Mobile-ID will prepare a focused architecture and workshop plan.