Privacy Policy

Effective date: 15 August 2026 · Last updated: 15 August 2026

This Privacy Policy explains how PaidBeep (“we“, “us“, “our“) collects, uses, stores, shares and protects information when you use paidbeep.com, app.paidbeep.com, the PaidBeep Android application (the “Listener App“), and the PaidBeep plugin for WooCommerce (together, the “Service“). It is designed to meet our obligations under the (Indian) Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and rules thereunder.

The most important thing to understand: PaidBeep is payment verification software. We never collect, hold or process your money or your customers’ money, and we never collect banking credentials, UPI PINs, card numbers, CVVs, OTPs or passwords of any bank or UPI application. Payments flow directly between your customer’s bank and your bank. What we process is information about payments — enough to confirm to your website that a payment arrived.


1. Who this policy covers

  • Merchants — business owners who create a PaidBeep account.
  • Merchants’ customers (“End Customers”) — people who pay a Merchant through a checkout page powered by our software. We process limited End Customer data on behalf of the Merchant, who is the data fiduciary for that data. End Customers should also review the privacy policy of the store they are buying from.
  • Visitors to our websites.

2. Information we collect

2.1 From Merchants (you give it to us)

  • Account data: email address, password (stored only as a secure hash by our authentication provider), business name, mobile number.
  • Payment receiving details: your UPI ID (VPA) and the QR screenshot you upload during setup. The screenshot is decoded in your browser to cross-check your UPI ID; we store the resulting UPI ID, not the image.
  • Support communications: messages you send us.

2.2 From the Listener App (with your explicit permission)

The Listener App requests Android Notification Access and SMS (RECEIVE_SMS) permissions. With these permissions, the app:

  • reads notifications only from known payment applications (for example PhonePe, Google Pay, Paytm, BHIM) and incoming SMS, and forwards to our servers the text of payment-related messages (for example: “Received ₹300 from …”, “A/c XX credited by Rs.300 … Ref No …”);
  • sends a periodic “heartbeat” so your dashboard can show whether your phone is online;
  • sends basic device metadata (Android version, manufacturer) at pairing.

From these messages we extract and store: amount, payer name as stated in the message, transaction reference (UTR) where present, and the raw message text (kept so that unrecognised formats can be reviewed and supported — this is how the product improves). We do not read, store or transmit your personal conversations: messages that do not match payment-sender patterns are not used for verification; where a non-matching message from a monitored payment source is logged for parser improvement, it is retained only for that purpose and access is restricted.

You can revoke Notification and SMS permissions at any time in Android settings — the Service’s automatic verification will stop working, but nothing else breaks.

2.3 About End Customers (on behalf of the Merchant)

  • Order information sent by the Merchant’s website: order number and amount.
  • The transaction reference (UTR) an End Customer types on the payment page, if they use the manual option.
  • The payer name exactly as it appears in the payment message received on the Merchant’s own device.

We do not collect End Customers’ bank account numbers, card details, addresses, or contact details. Those, if collected at all, are collected by the Merchant’s own store, under the Merchant’s own privacy policy.

2.4 Automatically

Standard technical data: IP address, browser type, timestamps of API requests, and error logs — used for security, debugging and abuse prevention. Our websites use only cookies/local storage necessary for login sessions and interface preferences; we do not run third-party advertising trackers.

3. What we use information for

  1. Providing the Service — matching payment messages to orders, showing your dashboard, generating payment QR codes, sending alerts (for example, “your phone is offline”).
  2. Billing — maintaining your prepaid Credits and fee ledger.
  3. Support and troubleshooting — including reviewing raw message text when a payment was not recognised.
  4. Improving the Service — for example, adding support for a bank’s SMS format found in the ingest log.
  5. Security and fraud prevention — protecting you, End Customers and the platform.
  6. Legal compliance — responding to lawful requests by public authorities and enforcing our Terms.

We do not sell or rent personal data. We do not use your data, or End Customer data, for advertising.

4. Where data is stored, and transfers

Our backend is hosted on Supabase (infrastructure provided by Amazon Web Services), currently in the Asia Pacific (Tokyo) region, with web servers in data centres in Europe/India depending on the surface. By using the Service you consent to your information being transferred to and stored in these locations, protected by the safeguards described in this policy and our processors’ certifications.

5. Who we share data with

  • Processors that help us run the Service, bound by contract to process data only on our instructions: Supabase/AWS (database, authentication, hosting), our VPS provider (web hosting), and our email delivery provider (transactional emails).
  • The Merchant you paid (for End Customers): verification status, amount, payer name and reference of your payment appear in that Merchant’s dashboard — this is the entire purpose of the Service.
  • Authorities, when required by law, court order, or to protect rights, safety and property.
  • A successor in the event of a merger, acquisition or asset sale, under this same policy.

6. How long we keep data

  • Account data: while your account is active and for up to 90 days after deletion, except where longer retention is required by law.
  • Payment messages, orders and verification records: up to 8 years, consistent with Indian bookkeeping and tax record expectations for the Merchants they belong to, after which they are deleted or irreversibly anonymised.
  • Ingest logs kept for parser improvement: up to 24 months.
  • Backups roll off automatically on the schedule of our hosting providers.

7. Security

We use industry-standard measures: encryption in transit (HTTPS/TLS) everywhere; passwords handled by a dedicated authentication service and never stored in plaintext; row-level security so each Merchant can access only their own data; least-privilege API keys; device pairing tokens that can be revoked by unpairing. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the authorities as required by law.

8. Your rights

Subject to applicable law (including the DPDP Act, 2023), you have the right to: access a summary of your personal data; correct inaccurate data (most account data is directly editable in your dashboard Profile); erase your personal data; withdraw consent (for example, revoke the app’s permissions); nominate a person to exercise your rights in case of death or incapacity; and lodge a grievance.

To exercise any right, email support@paidbeep.com with the subject “Privacy Request”. We respond within the timelines required by law. If you are an End Customer, we may direct your request to the Merchant you transacted with, who controls that data.

Grievance Officer: Grievance Officer, PaidBeep — support@paidbeep.com. We acknowledge grievances within 72 hours and aim to resolve them within 15 days. If you are unsatisfied, you may complain to the Data Protection Board of India.

9. Children

The Service is for business use by adults. We do not knowingly collect data from children under 18. If you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced via the dashboard or email before they take effect. The “Last updated” date above always reflects the current version.

11. Contact

PaidBeep · support@paidbeep.com · https://paidbeep.com