Legal

Privacy Policy

How we collect, use, store and protect information on the ZeroPay Gateway platform.

Last updated: 11 September 2026

1. Who this covers

This policy applies to merchants who use the Platform and to end customers whose order and payment information passes through it. For end-customer data, the merchant is the data fiduciary and ZeroPay acts as a data processor on the merchant's instructions.

2. What we collect

  • Merchant account data: name, business name, email, password hash, store domain.
  • Integration credentials: Shopify access token, WhatsApp phone number ID and API token, PhonePe merchant ID, salt key and salt index — all encrypted at rest.
  • Order data: customer phone number, product and variant identifiers, quantity, amount, order status and timestamps.
  • Payment metadata: transaction reference, payment link and payment status returned by the aggregator. We never receive or store card numbers, CVVs, UPI PINs or bank credentials.
  • Technical logs: webhook payloads, processing state, error traces and basic device or browser information.

3. Why we use it

  • To validate stock, create orders and generate payment links.
  • To send transactional WhatsApp messages: summaries, payment links and receipts.
  • To show merchants their orders, revenue and fees-saved metrics.
  • To detect fraud and abuse, and to meet legal and regulatory obligations.

We do not sell personal data and we do not use customer phone numbers for our own marketing.

4. Legal basis and consent

Processing is based on the merchant's contract with us and, for end customers, on the consent given when they initiate an order conversation from the storefront, as contemplated by the Digital Personal Data Protection Act, 2023.

5. Sharing

We share only what is necessary with Shopify (inventory and order sync), Meta/WhatsApp (message delivery), PhonePe (payment initiation and status), our cloud hosting and database provider, and with authorities where required by law.

6. Storage and security

Payment transaction data is stored in India in line with the RBI circular on Storage of Payment System Data dated 6 April 2018. Secrets are encrypted using AES-256-GCM, transport is over TLS, access is scoped per merchant by row-level security policies, and payment callbacks are signature-verified before any state change. See our Security page.

7. Retention

Order and payment records are retained for the period required under applicable tax and payment regulations, generally up to eight years, and then deleted or anonymised. Webhook logs are retained for a shorter operational period. Credentials are deleted when an integration is removed or an account is closed.

8. Your rights

Subject to law, you may request access to, correction of, or erasure of your personal data, withdraw consent, or nominate a person to exercise your rights. End customers should contact the merchant they ordered from; we will assist that merchant. Requests to us can be raised through Grievance Redressal.

9. Cookies

We use strictly necessary cookies and local storage for sign-in sessions and your light/dark theme preference. We do not run advertising trackers.

10. Breach notification

In the event of a personal data breach we will notify affected users and the Data Protection Board of India as required under the DPDP Act, 2023, and inform relevant payment partners.

11. Children

The Platform is not intended for anyone under 18 years of age.

12. Changes

Updates to this policy will be posted here with a revised date and, where material, notified to merchants directly.