PixVibe UPI operates with strict adherence to the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) and the IT Act, 2000.
1. Introduction & Commitment to Privacy
At PixVibe UPI ("we", "our", or "us"), we prioritize the privacy and security of our merchants, developers, and end customers. This Privacy Policy details our principles regarding data collection, transmission, and zero-compromise encryption standards across our UPI payment aggregation software.
2. Information We Collect
When merchants register or process transactions through our gateway, the following minimal information is handled:
- Merchant Account Details: Name, business name, mobile number, email address, and API authentication token.
- Transaction Metadata: Order ID, transaction amount, timestamp, UPI Reference / UTR number, and payment status (Pending, Success, Failed).
- Zero Banking Data Storage: We DO NOT collect, store, or have access to any customer UPI PIN, Net Banking Passwords, Debit/Credit Card CVVs, or OTPs. All fund settlements occur peer-to-peer directly into the merchant's linked bank account.
3. Purpose of Processing Data
We utilize the collected metadata solely for:
- Facilitating real-time UPI transaction verification and webhook dispatching to merchant websites.
- Displaying merchant analytics, transaction ledgers, and settlement statistics on the merchant console.
- Preventing duplicate payment verifications and protecting merchants against payment fraud.
- Providing technical assistance through our customer helpdesk ticket system.
4. Android Companion App & Notification Telemetry Privacy
Our Android Companion App operates under strict privacy safeguards:
- Strict Financial Whitelist: The app is hardcoded to parse notifications only from verified financial applications (PhonePe, Google Pay, Paytm, BharatPe, BHIM, and banking applications) and default system SMS apps.
- Local On-Device Filtering: All personal text messages, OTPs, personal chats (WhatsApp, Telegram, etc.), photos, contacts, and non-payment alerts are discarded locally on the merchant's device and are NEVER uploaded or stored.
- Zero Personal Telemetry: The app does not request or track GPS location, device contacts, microphone, or camera access.
5. Data Protection & Security Standards
We implement enterprise-grade security protocols:
- End-to-End SSL/TLS Encryption: All API communication between merchant servers and our gateway is encrypted using 256-bit TLS standards.
- Cryptographic Password Hashing: Passwords are protected using one-way
BCRYPT algorithmic salting and hashing.
- Strict Anti-Sharing Policy: We never sell, rent, or trade merchant or customer data to third-party marketing companies.
6. Data Retention & Rights
Merchants possess full rights to view, export, or request deletion of their transaction records and account data. Requests for account termination and data purge can be submitted directly via our Helpdesk Support desk.
7. Grievance & Privacy Officer Contact
If you have any questions, concerns, or grievances regarding this Privacy Policy, please contact our designated Data Protection Officer: