Privacy Policy
PayPluse is a payment-notification and order-reconciliation tool for merchants who accept UPI payments into their own FamPay account. PayPluse never receives, holds, or routes customer funds — every payment moves directly between the customer and your own UPI address. This page states exactly what data PayPluse stores, why, who processes it, and how to have it removed.
Data we collect
Account profile: your full name, email address and phone number, plus an avatar or logo image if you upload one. We also record the timestamp of your acceptance of the Terms and Privacy Policy.
Business settings: the FamPay UPI ID and payee display name used on checkout, your default order expiry, order note template, business name and support email.
Mailbox connection (only if you choose to connect one): the Gmail address you connect and a Gmail App Password generated by you in your Google Account. PayPluse never asks for, and never stores, your normal Google password.
Order details: the amount and generated order reference, plus any optional fields you choose to attach — description, reference note, return URL, free-form metadata, and the optional customer name, customer email and customer phone fields. These customer fields are entirely optional; an order can be created with an amount alone.
Payment notification metadata: when PayPluse reads an official FamPay credit-alert email from your connected mailbox, it extracts and stores only the parsed fields — UTR, amount, payer VPA, transaction timestamp, reference note, and the Gmail message ID used for idempotency. Raw email bodies and headers are processed in memory for that parse and then discarded; they are never written to storage or logs.
Operational records: the webhook endpoints you register, your API keys (stored only as a salted SHA-256 hash — the full key is displayed once at creation and cannot be recovered), webhook delivery logs, and audit entries such as a mailbox being connected, whose metadata never contains passwords, keys, secrets or email content.
How your data is used
To create the frozen payment sessions and QR codes behind your checkout links; to match incoming FamPay notifications to your orders and decide their status; to render your dashboard, orders list and transaction ledger; to deliver the webhooks you registered; and to authenticate you and rate-limit abuse of the API. PayPluse does not sell your data and does not use it for advertising.
Credential storage, encryption and key rotation
Your Gmail App Password is encrypted with AES-256-GCM before storage: a unique initialization vector per value, with the authentication tag stored alongside the ciphertext. Encryption keys are versioned (V1, V2, and so on), and every stored credential records which key version encrypted it.
New data is always encrypted under the current key while older keys remain available only to decrypt existing rows. Rotating to a new key re-encrypts stored credentials at a controlled pace, and an old key is retired only once no stored credential references it. Server secrets — including the encryption key, the App Password itself and the service credentials — never reach the browser bundle, API responses, logs or error messages.
Third parties who process your data
Supabase hosts the database, authentication, avatar file storage, background functions and realtime updates that Power PayPluse. Google (Gmail) provides IMAP access to your connected mailbox using the credentials you supply, and Google OAuth sign-in if you register with Google. Disconnecting your mailbox — or revoking the App Password in your Google Account — ends PayPluse’s access to your inbox.
Retention and deletion
Your data is retained while your account is active. Disconnecting the mailbox immediately deletes the stored encrypted App Password. Requesting account deletion revokes your API keys, removes your webhook endpoints, deletes stored mailbox credentials and marks your merchant record as deleted; anything that must be retained to meet a legal obligation is listed on the confirmation screen before you confirm the deletion.
Parsed notification metadata and message IDs are retained as your transaction ledger so your own payment records stay complete; delete your account to remove them.
Your choices
The optional customer name, email and phone fields stay empty unless you fill them in. You can disconnect your mailbox at any time from the Integrations page, which deletes the stored credential immediately rather than merely disabling it.