PRIVACY POLICY
Last Updated: 31-08-2026
This Privacy Policy ("Policy") explains our policy regarding the collection, use, storage, processing, disclosure, and protection of information by iPayso ("iPayso", "we", "us", or "our"), which operates the iPayso mobile application and related services (collectively, the "iPayso Services" or "Services").
iPayso is a B2B (Business-to-Business) application designed primarily for local shopkeepers, merchants, and small business owners in India.
The iPayso App provides Merchants with a digital ledger ("Digital Khata") to record credit or "udhaar" transactions with their customers, maintain running balances, record payments or repayments, generate UPI payment requests, and prepare payment reminders that may be shared through supported third-party applications.
This Policy forms part of and should be read together with the iPayso Terms and Conditions of Use.
Capitalized terms used in this Policy but not defined herein shall have the meanings assigned to them in the Terms and Conditions of Use.
By accessing or using the iPayso Services, you acknowledge that you have read, understood, and agreed to the collection, storage, use, and processing of information as described in this Policy, subject to applicable law.
If you do not agree with any provision of this Policy, please do not access or use the iPayso Services.
As we update, improve, and expand the iPayso Services, this Policy may be updated from time to time. Users are encouraged to review this Policy periodically.
1. INFORMATION WE COLLECT
The information we collect or process may be broadly categorized as: (a) Information supplied by Users; and
(b) Information automatically generated or collected when Users access or use the iPayso Services.
The information collected is limited to what is reasonably necessary to provide, maintain, secure, and improve the iPayso Services.
2. INFORMATION SUPPLIED BY USERS
To register for and use the iPayso Services, Users may be required to provide certain information.
The information supplied by Users may include the following.
Account and Authentication Information
Users may authenticate with iPayso using:
• Google Authentication (OAuth)
Depending on the authentication method selected, iPayso may collect or receive:
• Name;
• Email address;
• Mobile phone number;
• Basic profile information made available by Google Authentication;
• Authentication-related identifiers; and
• Other information necessary to create and maintain the User's Account.
This information enables us to authenticate Users, create Accounts, provide access to the Services, and maintain Account security.
Business Information
To use the core features of iPayso, Users may be required to provide information relating to their business, including:
• Shop or business name;
• Owner name;
• Business phone number; and
• Personal or business UPI ID.
The UPI ID provided by the User may be used to generate a UPI payment request through the UPI Intent functionality available through the App.
Users are responsible for ensuring that all information provided to iPayso is accurate, complete, and up to date.
Customer Information
iPayso allows Merchants to create and maintain digital ledger records relating to their customers.
The Merchant may provide information including:
• Customer name;
• Customer phone number; and
• Transaction-related notes.
The Merchant is responsible for ensuring that the collection, entry, and use of customer information through iPayso is lawful and complies with applicable privacy and data-protection laws.
iPayso provides the software and infrastructure through which Merchants may store and manage such information.
Ledger and Transaction Information
When using the Digital Khata functionality, Users may record information relating to transactions with their customers.
This may include:
• Date of transaction;
• Time of transaction;
• Transaction type;
• Credit or "udhaar" amount;
• Payment or repayment amount;
• Running balance;
• Payment status manually entered by the Merchant; and
• Optional transaction notes.
This information is stored and processed to provide the digital ledger and related business-management functionality.
3. INFORMATION AUTOMATICALLY PROCESSED WHILE USING THE APP
When you access or use iPayso, certain technical information may be automatically processed or generated as necessary to operate, maintain, secure, and improve the Services.
We may use this information to understand technical issues, maintain application performance, protect the security of the Services, and improve the User experience.
iPayso does not intentionally collect information that is not reasonably necessary for the operation of its Services.
4. INFORMATION WE DO NOT COLLECT THROUGH THE APP
iPayso does not require Users to provide or store sensitive payment credentials such as:
• UPI PIN;
• Debit card PIN;
• Credit card PIN;
• CVV;
• Credit card number;
• Debit card number;
• Internet banking password;
• Bank account password; or
• Other confidential payment authentication credentials.
Users should never provide their UPI PIN, OTP, CVV, card PIN, or banking password to iPayso or to anyone claiming to represent iPayso.
5. HOW WE USE INFORMATION
The information collected or processed through iPayso may be used for the following purposes:
Providing the Services
To:
• Create and maintain User Accounts;
• Authenticate Users;
• Maintain business profiles;
• Provide Digital Khata functionality;
• Store customer records entered by Merchants;
• Record credit and repayment transactions;
• Display running balances;
• Generate UPI payment requests;
• Support payment reminder functionality; and
• Provide other features and Services offered through iPayso.
Maintaining and Improving the Services
We may use information to:
• Improve the functionality of the App;
• Understand technical issues;
• Improve application performance;
• Develop new features;
• Improve User experience;
• Maintain and enhance security; and
• Analyze general usage and operational trends.
Customer Support
We may use relevant information to:
• Respond to User questions;
• Provide technical assistance;
• Investigate complaints;
• Resolve issues; and
• Communicate with Users regarding their Accounts or Services.
Security and Fraud Prevention
We may use information to:
• Detect unauthorized access;
• Prevent misuse;
• Investigate suspicious activity;
• Protect User Accounts;
• Protect the Platform; and
• Protect the rights and safety of iPayso and its Users.
Legal and Regulatory Compliance
We may use or disclose information where reasonably necessary to:
• Comply with applicable laws;
• Respond to lawful government requests;
• Respond to court orders or legal processes;
• Cooperate with law-enforcement authorities; or
• Protect our legal rights.
6. MERCHANT-CONTROLLED CUSTOMER INFORMATION
iPayso is a software platform that enables Merchants to maintain their own customer ledgers.
The Merchant determines:
• Which customers are added to the Digital Khata;
• What customer information is entered;
• What transaction information is recorded; and
• The business purpose for which such information is used.
Accordingly, depending on the applicable privacy and data-protection laws and the specific processing activity, the Merchant may act as the entity responsible for determining the purpose and means of processing customer information, while iPayso may process such information on behalf of the Merchant to provide the Services.
Merchants are responsible for ensuring that they have the appropriate legal basis, authorization, notice, or consent, where required under applicable law, before entering customer information into iPayso.
iPayso does not independently determine the purpose for which a Merchant maintains a customer's ledger.
7. UPI PAYMENT REQUEST FUNCTIONALITY
iPayso provides a utility that allows Merchants to generate UPI payment requests.
iPayso is not a payment gateway or payment aggregator and does not operate a nodal or escrow account for UPI transactions.
iPayso does not:
• Receive customer funds;
• Hold Merchant funds;
• Route customer funds;
• Settle payments;
• Process card payments;
• Operate a payment gateway; or
• Act as an intermediary for the movement of funds.
When a Merchant initiates a payment request, iPayso generates a standard UPI QR Code.
The Android App may use the native Android Intent mechanism to open a compatible UPI application already installed on the User's device.
The actual payment transaction takes place outside iPayso between the customer's bank, the Merchant's bank, the selected UPI application, and the applicable UPI infrastructure.
8. NO AUTOMATIC PAYMENT CONFIRMATION
Since the actual payment transaction takes place outside the iPayso App, iPayso does not receive automatic payment success or failure callbacks from the customer's bank or UPI application.
Accordingly:
• iPayso does not independently verify the success of a UPI payment;
• iPayso does not guarantee payment settlement;
• iPayso does not guarantee that a payment request will be completed;
• iPayso does not guarantee successful QR code scanning; and
• iPayso does not automatically mark ledger entries as "Paid."
The Merchant is solely responsible for verifying their bank account or other appropriate banking records before manually marking a ledger entry as paid.
9. WHATSAPP PAYMENT REMINDERS
iPayso may provide a functionality that allows Merchants to prepare payment reminders for customers and share them through WhatsApp.
The functionality may use Android Deep Linking or Intent mechanisms to open the Merchant's installed WhatsApp application.
The payment reminder may contain information entered by the Merchant and may include an optional QR code image generated on the device.
The Merchant must review the message and manually press the "Send" button in WhatsApp.
iPayso does not:
• Send WhatsApp messages automatically in the background;
• Send messages without the Merchant's action;
• Access or control the Merchant's WhatsApp account;
• Guarantee delivery of WhatsApp messages; or
• Guarantee that a customer has read a message.
iPayso is not affiliated with, endorsed by, or sponsored by WhatsApp or Meta Platforms, Inc.
The use of WhatsApp is governed by WhatsApp's own terms and privacy practices.
10. THIRD-PARTY SERVICES
The iPayso Services may interact with or depend upon third-party services and infrastructure.
These may include:
• Google Authentication;
• Supabase;
• PostgreSQL database infrastructure;
• WhatsApp;
• UPI applications;
• Banks;
• NPCI infrastructure;
• Android operating system services; and
• Other third-party technology or infrastructure providers.
Third-party services are governed by their own terms and privacy policies.
iPayso does not control the privacy practices of third parties.
When you use a third-party service, your information may be processed by that third party in accordance with its applicable privacy policy.
11. GOOGLE AUTHENTICATION
If you choose to register or log in using Google Authentication, Google may provide iPayso with information associated with your Google Account as permitted by your authorization and Google's authentication services.
This may include:
• Name;
• Email address;
• Basic profile information; and
• Authentication-related identifiers.
Your use of Google Authentication is also subject to Google's applicable terms and privacy policies.
12. INFORMATION SHARING
iPayso does not sell your personal information to third parties for monetary consideration.
Information may be shared or made available in limited circumstances, including:
Service Providers
We may use third-party service providers for:
• Authentication;
• Database hosting;
• Cloud infrastructure;
• Application infrastructure;
• Security;
• Technical support;
• Error monitoring; and
• Other services required to operate iPayso.
Such service providers may process information only to the extent necessary to provide their services to iPayso.
We take reasonable steps to ensure that service providers handling information on our behalf maintain appropriate confidentiality and security measures.
Legal Requirements
We may disclose information where required or permitted by applicable law, including to:
• Government authorities;
• Law-enforcement agencies;
• Courts; or
• Other legally authorized entities.
Security and Protection
We may disclose information where reasonably necessary to:
• Prevent fraud;
• Investigate security incidents;
• Prevent misuse of the Services;
• Protect iPayso;
• Protect Users; or
• Protect the rights, safety, and property of others.
13. DATA STORAGE AND INFRASTRUCTURE
iPayso uses Supabase and PostgreSQL-based infrastructure for backend database and authentication-related functionality.
Information provided through the App may be stored and processed using this infrastructure.
iPayso uses reasonable technical and organizational measures to protect information stored through the Platform.
14. DATA ISOLATION AND SECURITY
iPayso operates as a multi-tenant SaaS application.
Each Merchant operates within an isolated business environment.
The Platform is designed so that one Merchant cannot ordinarily access or view the business or customer data belonging to another Merchant through normal authorized use of the App.
The iPayso database uses Row Level Security (RLS) policies designed to restrict database read and write operations according to the authenticated User and the relevant business_id.
These controls are intended to ensure that User requests are restricted to the appropriate business environment.
However, no electronic system, database, or transmission over the internet can be guaranteed to be completely secure.
Accordingly, while we take reasonable measures to protect information.
15. DATA RETENTION AND DELETION
We retain information for as long as reasonably necessary to:
• Provide the iPayso Services;
• Maintain User Accounts;
• Maintain digital ledger and transaction records;
• Provide customer support;
• Prevent fraud and misuse;
• Resolve disputes;
• Comply with legal obligations; or
• Enforce our Terms and Conditions.
The retention period may vary depending on the nature of the information and the purpose for which it is processed.
When information is no longer required, iPayso may delete, anonymize, or securely dispose of such information, subject to applicable legal, regulatory, security, and legitimate business requirements.
16. MERCHANT RESPONSIBILITIES
Merchants are responsible for:
• Providing accurate information to iPayso;
• Keeping Account information updated;
• Protecting their Account credentials;
• Protecting their mobile device;
• Ensuring the accuracy of customer records;
• Ensuring the accuracy of transaction records;
• Ensuring the accuracy of the UPI ID entered into the App;
• Obtaining any required consent or authorization for customer information;
• Independently verifying payments received in their bank account; and
• Maintaining independent records of important business information.
iPayso shall not be responsible for losses arising from:
• An incorrect UPI ID entered by a Merchant;
• Loss or theft of a mobile device;
• Compromised Account credentials;
• Internet or network interruptions;
• Failure or unavailability of a third-party UPI application;
• Bank or NPCI infrastructure issues;
• Incorrect information entered by a Merchant; or
• Failure of a Merchant to independently verify a payment.
17. CUSTOMER PRIVACY AND DATA REQUESTS
Where a customer has concerns regarding personal information entered into iPayso by a Merchant, the customer may first contact the relevant Merchant who collected or entered the information.
As the Merchant generally determines what customer information is collected and for what business purpose it is used, the Merchant may be responsible for responding to customer requests relating to such information, subject to applicable law.
Where iPayso is legally responsible for responding to a request, the relevant individual may contact iPayso using the contact details provided in this Policy.
iPayso may require reasonable information to verify the identity of the person making a request.
18. USER RIGHTS
Subject to applicable law, Users may have certain rights regarding their personal information.
These may include the right to:
• Request access to personal information;
• Request correction of inaccurate information;
• Request deletion of personal information;
• Withdraw consent where processing is based on consent; and
• Exercise other rights available under applicable privacy and data-protection laws.
Certain rights may be subject to legal or regulatory limitations.
Requests may be submitted using the contact details provided in this Policy.
We may request reasonable information to verify your identity before processing a request.
19. ACCOUNT DELETION
A User may request deletion or deactivation of their iPayso Account by contacting iPayso through the applicable support or privacy contact details.
Upon receiving a valid request, iPayso may delete or deactivate the Account and associated information, subject to:
• Applicable legal requirements;
• Legitimate business requirements;
• Fraud prevention;
• Security requirements;
• Dispute resolution; and
• Information that iPayso is legally required or permitted to retain.
Deleting the iPayso App from your mobile device does not necessarily delete your Account or information stored on iPayso's servers.
20. DATA TRANSFERS
Information processed through iPayso may be stored or processed through infrastructure operated by iPayso or its third-party service providers.
Depending on the location of such infrastructure and service providers, information may be processed or stored outside the User's state or country.
Where required by applicable law, iPayso will take appropriate measures relating to such processing or transfer.
21. COMMUNICATIONS
iPayso may communicate with Users through the contact information provided during registration or use of the Services.
Communications may include:
• Account-related information;
• Authentication-related communications;
• Service updates;
• Security alerts;
• Customer support communications;
• Changes to the Terms or Privacy Policy; and
• Other communications necessary for providing the Services.
iPayso may use third-party service providers to facilitate certain communications.
Users are responsible for ensuring that the contact information provided to iPayso is accurate and up to date.
22. CHANGES TO THIS PRIVACY POLICY
We may update this Policy from time to time to reflect:
• Changes in technology;
• Changes to the iPayso Services;
• Changes in our data practices;
• Changes in applicable laws; or
• Other operational requirements.
Any changes will be posted through the App or other appropriate channels.
Where required by applicable law, we may provide additional notice regarding material changes.
Users are encouraged to review this Policy periodically to remain informed about how iPayso collects, uses, stores, and protects information.
23. RESPONSIBLE ORGANIZATION FOR DATA PROCESSING
The iPayso Services are provided and operated by: iPayso
The Company is responsible for the collection and processing of information relating to Users for the purposes of providing and operating the iPayso Services, subject to applicable law.
In relation to customer information entered by Merchants into the Digital Khata, the Merchant may determine the purposes for which such information is collected and used, while iPayso provides the software infrastructure for processing such information on the Merchant's behalf.
24. GRIEVANCE REDRESSAL
If you have any grievance, question, or concern relating to the processing of your information or this Privacy Policy, you may contact our Grievance Officer or Privacy Contact using the details below.
Email: hello@ipayso.com
We will endeavour to address complaints and privacy-related requests in accordance with applicable laws and our internal grievance-handling procedures.
25. CONTACT US
For questions regarding this Privacy Policy or the protection of your information, please contact:
iPayso
Support Email: hello@ipayso.com
By accessing or using the iPayso Services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, storage, use, and processing of information as described herein, subject to applicable law.