Privacy Policy
What data KaroPay collects to run your UPI payment gateway, why we need it, who can see it and how you stay in control — including the read-only access used for Email Alerts.
The short version
- We never sell your data or your customers’ data.
- Merchant passwords, access tokens and App Passwords are encrypted (AES-256-GCM) before they are stored.
- Email Alerts is read-only and only looks at Paytm / PhonePe payment-alert mails — never your other emails.
- We don’t hold money, so we never collect your customers’ card, bank account or UPI PIN details.
1 Data we collect
| Type | What it includes |
|---|---|
| Account details | Name, mobile number, email, business name, profile photo / logo and login activity. |
| Merchant connection | Your UPI ID and merchant details (name, merchant ID, QR), plus the login mobile / email, password or session needed to read your provider dashboard. |
| Email Alerts | Your Gmail address and either a Google access token or a Gmail App Password, and the details read from payment-alert mails (amount, payer name / UPI ID, UTR, order ID, time). |
| Orders & payments | Order amount, client_txn_id, status, customer name, mobile and email you send us, UDF fields, UTR and payer UPI ID once paid. |
| Integration & logs | API credentials, webhook URL, API request / response logs, webhook delivery results, IP address and device / browser details. |
| Billing | Plans purchased, quota usage, wallet top-ups and wallet transactions. |
2 Email Alerts access
When you choose UPI ID + Email Alerts, you connect your Gmail inbox in one of two ways:
Connect with Google
Uses Google’s read-only Gmail permission (gmail.readonly). We store an encrypted refresh token, never your Google password.
Gmail App Password
A 16-character password you create in your Google account, used only to read mail over IMAP. It is stored encrypted.
- We only search for mails from the payment-alert sender you chose (
no-reply@paytm.comornoreply@phonepe.com), and only while you have orders waiting for payment. - We never read, store or send any other email, and we never send mail from your account.
- Disconnecting in KaroPay deletes the stored token / App Password. You can also revoke access any time from your Google account.
3 How we use data
- To create payment QRs and links that pay your own UPI ID, detect payments and update order status.
- To send webhooks to your server and notifications to you (email, WhatsApp, Telegram) about orders, plans and your account.
- To run billing, plans, quota and your wallet.
- To provide support, investigate issues and keep request logs for troubleshooting.
- To prevent fraud and misuse, and to meet legal and regulatory obligations.
5 How we protect it
- Merchant dashboard passwords, provider API tokens, Google tokens and Gmail App Passwords are encrypted with AES-256-GCM before storage.
- All traffic to KaroPay is served over HTTPS; every API call needs your API key and secret.
- Access to production data is restricted to authorised staff, and activity is logged.
6 How long we keep it
- Account, order and billing records are kept while your account is active and afterwards for as long as the law requires.
- Email-alert credentials are deleted as soon as you disconnect the inbox.
- Technical logs are kept only as long as needed for support, security and audit.
7 Your customers’ data
When you send customer details with an order, you decide what is collected and why; KaroPay processes that data on your behalf only to run the payment. You are responsible for telling your customers how their data is used and for having a lawful basis to share it with us.
8 Your rights & choices
- View and update your profile and merchant connection from your dashboard.
- Disconnect your merchant account or inbox at any time.
- Ask us for a copy of your data, a correction or deletion (subject to legal record-keeping) by writing from your registered email.
We handle these requests in line with applicable Indian law, including the Digital Personal Data Protection Act, 2023.
9 Cookies
We use a session cookie to keep you logged in and remember basic preferences. We do not use advertising cookies.
10 Changes to this policy
If we change this policy we will update the “Last updated” date above, and notify you by email or on your dashboard for important changes.
Privacy questions or data requests
Write to support@karopay.in from your registered email with your request. We acknowledge within 24 business hours.