Privacy Policy

Last updated: May 25, 2026

1. Overview of Platform Commitments

At MyMobPay, we are committed to providing a secure, transparent, and robust peer-to-peer (P2P) UPI payment processing platform. This Privacy Policy details how we collect, store, isolate, and safeguard data relating to merchants, transactions, and end-consumers.

Our gateway utilizes bank-grade 256-bit encryption layers to prevent spoofing and data sniffing. We operate under strict zero-trust operational models to guarantee absolute transactional privacy.

2. PCI-DSS Compliance & Data Security

PCI-DSS Compliant Isolated Architecture

Our payment gateway is explicitly designed to handle transactions without collecting or retaining sensitive payment credentials (such as raw bank account passwords, debit card pins, or OTPs). All routing is processed using standard, public UPI Virtual Payment Addresses (VPAs).

Because peer-to-peer UPI payments operate directly from the customer's mobile device to the merchant's bank account via official UPI applications (Google Pay, PhonePe, Paytm, BHIM), no intermediary cards or sensitive customer banking details ever pass through our servers.

3. Data Collection & Usage Limits

We collect minimal data required to verify successful payments and maintain operational safety:

  • Merchant Profile Details: Business Name, UPI ID (VPA), and Webhook Outbound Callback URL to handle notifications.
  • Transactional Metadata: Transaction Amount, Order Reference ID, customer phone number (optional), and bank SMS UTR numbers to match and confirm deposits.
  • Authentication Data: Secure password hashes and API keys for merchant portal credentials.

We strictly enforce a policy prohibiting the selling, renting, or leasing of merchant or customer databases to third-party marketing entities.

4. Automated Verification Mechanics

Our platform utilizes automatic matching of bank credit notification SMSs and routing updates. SMS contents parsed via our Android forwarders or routed bank emails are checked only for amount and UTR criteria. Once an order transitions to verified, raw logs are securely hashed to prevent secondary indexing or leakage.

© 2026 MyMobPay Gateway. Secured by 256-bit TLS encryption.

In case of queries regarding data security policies, reach out to security@mymobpay.tech.