Privacy Policy | UPIGateway.dev

This Privacy Policy outlines how UPIGateway.dev collects, uses, protects, and handles your personal and business information when you use our payment automation platform.

Information Collection & Scope of Processing

We collect information that you provide directly to us when creating a merchant account, configuring settings, or communicating with support. This includes your name, email address, phone number, and business details.

To provide payment automation services, we process payment configuration metadata, including your registered UPI ID and transaction reference identifiers. We do not store sensitive customer payment credentials, such as UPI PINs, bank account passwords, or debit card numbers.

We also automatically collect technical log data, including IP addresses, browser types, operating systems, and API request timestamps to maintain system security and prevent fraudulent access.

This information is processed strictly to maintain platform reliability, detect abnormal transaction surges, and protect merchants against cyber threats.

Data Protection, Encryption & Secure Storage

We implement robust technical and organizational security measures to safeguard your data against unauthorized access, alteration, disclosure, or destruction. All communication between your browser and our servers is encrypted using Transport Layer Security protocol.

Merchant API tokens and gateway credentials are stored in encrypted databases hosted within secure cloud data centers. Access to production databases is strictly restricted to authorized engineering personnel subject to multi-factor authentication.

We regularly review our security procedures and infrastructure configurations to maintain compliance with modern data protection best practices.

Our database architecture enforces row-level security policies to ensure that merchant data is completely isolated and inaccessible across accounts.

Cookies, Session Storage & Analytics

We use essential functional cookies and secure local session tokens strictly necessary for user authentication and dashboard navigation. We do not employ intrusive tracking pixels or sell browsing profiles to third-party ad networks.

You can manage your cookie preferences through your browser settings, though disabling essential security cookies may prevent proper authentication within the merchant console.

We believe in data minimization and collect only the telemetry essential for maintaining service uptime and detecting system errors.

Third-Party Disclosures & Non-Monetization Policy

We do not sell, rent, or trade your personal information or transaction history to advertisers or third-party marketing companies. We only share information with trusted third-party service providers that assist us in operating our platform, such as cloud hosting providers and transactional email services.

These service providers are bound by strict contractual confidentiality agreements and are prohibited from using your data for any other purpose.

We may disclose information if required to do so by applicable law, court order, or official request from government or regulatory authorities.

Data Retention Periods & Security Incident Protocols

We maintain comprehensive security incident response procedures designed to identify, mitigate, and resolve potential vulnerabilities rapidly. In the unlikely event of a security breach affecting merchant data, we notify impacted users promptly with actionable remediation guidance.

Log archives and transaction reference tables are retained in compliance with Indian regulatory and tax record-keeping mandates, after which they are systematically purged from active database storage.

Our infrastructure undergoes periodic penetration testing and code auditing by independent cybersecurity professionals to ensure resilient defensive postures.

Your Rights, Data Deletion & Privacy Controls

You have the right to access, review, update, or request the deletion of your personal account information at any time. You can update your profile details directly from your merchant dashboard or by contacting our support team.

Upon account termination, we retain transaction log records only for the period legally required for accounting, tax, and anti-money laundering compliance under Indian law, after which the data is permanently erased.

If you have any questions or concerns regarding our privacy practices, please contact our data privacy officer at privacy@upigateway.dev.

We remain committed to complete transparency in our data handling protocols and privacy governance.