Legal

Privacy Policy

What data KaroPay collects to run your UPI payment gateway, why we need it, who can see it and how you stay in control — including the read-only access used for Email Alerts.

Last updated: 25 September 2026 About 7 min read

The short version

  • We never sell your data or your customers’ data.
  • Merchant passwords, access tokens and App Passwords are encrypted (AES-256-GCM) before they are stored.
  • Email Alerts is read-only and only looks at Paytm / PhonePe payment-alert mails — never your other emails.
  • We don’t hold money, so we never collect your customers’ card, bank account or UPI PIN details.

1 Data we collect

TypeWhat it includes
Account detailsName, mobile number, email, business name, profile photo / logo and login activity.
Merchant connectionYour UPI ID and merchant details (name, merchant ID, QR), plus the login mobile / email, password or session needed to read your provider dashboard.
Email AlertsYour Gmail address and either a Google access token or a Gmail App Password, and the details read from payment-alert mails (amount, payer name / UPI ID, UTR, order ID, time).
Orders & paymentsOrder amount, client_txn_id, status, customer name, mobile and email you send us, UDF fields, UTR and payer UPI ID once paid.
Integration & logsAPI credentials, webhook URL, API request / response logs, webhook delivery results, IP address and device / browser details.
BillingPlans purchased, quota usage, wallet top-ups and wallet transactions.

2 Email Alerts access

When you choose UPI ID + Email Alerts, you connect your Gmail inbox in one of two ways:

Connect with Google

Uses Google’s read-only Gmail permission (gmail.readonly). We store an encrypted refresh token, never your Google password.

Gmail App Password

A 16-character password you create in your Google account, used only to read mail over IMAP. It is stored encrypted.

  • We only search for mails from the payment-alert sender you chose (no-reply@paytm.com or noreply@phonepe.com), and only while you have orders waiting for payment.
  • We never read, store or send any other email, and we never send mail from your account.
  • Disconnecting in KaroPay deletes the stored token / App Password. You can also revoke access any time from your Google account.

3 How we use data

  • To create payment QRs and links that pay your own UPI ID, detect payments and update order status.
  • To send webhooks to your server and notifications to you (email, WhatsApp, Telegram) about orders, plans and your account.
  • To run billing, plans, quota and your wallet.
  • To provide support, investigate issues and keep request logs for troubleshooting.
  • To prevent fraud and misuse, and to meet legal and regulatory obligations.

4 Who we share it with

  • You and your systems — order and payment details are sent to your configured webhook URL and shown on your dashboard.
  • Your customer — the hosted payment page shows your business name, logo, UPI ID and the order amount.
  • Service providers who help us run KaroPay (hosting, email, messaging), bound by confidentiality.
  • Authorities, only when required by law or to prevent fraud.

We do not sell, rent or trade personal data.

5 How we protect it

  • Merchant dashboard passwords, provider API tokens, Google tokens and Gmail App Passwords are encrypted with AES-256-GCM before storage.
  • All traffic to KaroPay is served over HTTPS; every API call needs your API key and secret.
  • Access to production data is restricted to authorised staff, and activity is logged.
No system is 100% secure. Keep your KaroPay password, API secret and Gmail App Password private, and tell us at once if you suspect they were exposed.

6 How long we keep it

  • Account, order and billing records are kept while your account is active and afterwards for as long as the law requires.
  • Email-alert credentials are deleted as soon as you disconnect the inbox.
  • Technical logs are kept only as long as needed for support, security and audit.

7 Your customers’ data

When you send customer details with an order, you decide what is collected and why; KaroPay processes that data on your behalf only to run the payment. You are responsible for telling your customers how their data is used and for having a lawful basis to share it with us.

8 Your rights & choices

  • View and update your profile and merchant connection from your dashboard.
  • Disconnect your merchant account or inbox at any time.
  • Ask us for a copy of your data, a correction or deletion (subject to legal record-keeping) by writing from your registered email.

We handle these requests in line with applicable Indian law, including the Digital Personal Data Protection Act, 2023.

9 Cookies

We use a session cookie to keep you logged in and remember basic preferences. We do not use advertising cookies.

10 Changes to this policy

If we change this policy we will update the “Last updated” date above, and notify you by email or on your dashboard for important changes.

Privacy questions or data requests

Write to support@karopay.in from your registered email with your request. We acknowledge within 24 business hours.