How WebPress Pay collects, handles, and protects your data.
Merchant Details: Full legal name, business/company name, mobile number, email address, location, PAN number (for KYC verification), and encrypted Aadhaar reference.
Payment Configuration: Merchant UPI VPA (for generating QR codes) and webhook URLs.
Transaction Metadata: Order ID, amount, 12-digit UTR reference, payment status, and timestamp.
Data is used solely to provide platform services: generating dynamic UPI QR codes, polling bank UTR status, delivering webhook notifications, preventing platform misuse, and providing merchant customer support.
We never store: Customer UPI MPINs, bank passwords, OTPs, or debit/credit card numbers. All payments are executed directly inside authorized UPI banking apps (GPay, PhonePe, Paytm, etc.).
We implement TLS 1.2+ encryption in transit, bcrypt password hashing with secure salt, parameterized SQL queries, and 256-bit random API authentication tokens.
We do not sell or rent data. Limited transaction references (UTR/order IDs) are exchanged with banking APIs strictly for verification, or shared if required by law enforcement under valid Indian legal process.
Order transaction records are retained for 1–3 years to support merchant reconciliation, audit trails, and dispute resolution.
We only use minimal, functional session cookies for merchant authentication. We do not use third-party advertising cookies or behavioral tracking pixels.
Under India's Digital Personal Data Protection Act (DPDPA), you have the right to access, review, and request correction or deletion of your personal merchant profile data.