Akahu — how bank payments work on Able
What connecting your bank does, exactly what we can access, and how to withdraw it.
01Why connect a bank account
Able moves money account-to-account instead of through cards. For a business, sales are paid straight into its own bank account with no card fees and no holding account in between. For a customer, paying means approving the payment at your own bank, under limits you set — Able never holds your money and never sees your banking login. Connecting a bank is always optional. A business can run entirely on payments it collects itself; connecting simply switches on the account-to-account rail.
02Who Akahu is
Akahu is New Zealand’s open finance intermediary — accredited under the Customer and Product Data Act and used by banks, lenders and fintechs across the country. When you connect a bank on Able you are handed to Akahu’s own secure page: your online-banking credentials are entered there and only there. Able receives an access token, never your login.
03Exactly what we ask for, and for how long
Able requests two things and nothing more. Basic account information — the account name, number, type and capabilities — so you can pick the account money lands in, and so we can show you which accounts are connected. We do not request balances, transaction history, or identity records. Payment initiation — the ability to start a payment from an account, and only within a consent you approve at your bank first: a fixed payee, a per-payment limit and a periodic limit. A payment outside those bounds is refused by the bank itself. The access is enduring: it lasts until you withdraw it, and every payment stays inside the limits you approved. Account numbers are stored masked wherever they are shown, and the access token is held encrypted on our servers — it never reaches your browser.
04Withdrawing access
You can withdraw access at any time, from any of three places: disconnect in your Able settings (the Akahu panel), revoke at my.akahu.nz, or cancel the authority at your own bank. Revoking stops all future payments immediately. When you disconnect or delete your account, Able revokes its token with Akahu and deletes the connection data it exchanged, as the Privacy Act 2020 requires. If access is revoked from outside — at your bank or at Akahu — Able detects it and stops using the connection.