Last updated: 21 September 2026
ZuuPay ("we", "us") provides a UPI payment verification service for businesses. This policy explains what information we collect, why we collect it, and how we protect it.
This policy applies to merchants who create a ZuuPay account on this website or in the ZuuPay Android app, and to visitors of this website.
When you create an account we collect your business name, email address and mobile number. If you choose "Continue with Google", Google shares your name and email address with us so that we can create or open your account. We do not receive your Google password, and we do not access your Gmail, Google Drive, contacts or any other Google service.
Your UPI ID, payee name, bank sender code and callback URL, which you enter yourself so that the service can generate payment QR codes and confirm payments for you.
If you install the ZuuPay Android app on your own phone and switch it on, the app reads payment alerts (bank credit messages and UPI app notifications) on that phone and sends them to our server so we can confirm which order was paid. The app only sends messages that look like a payment credit. Personal messages, chats and other notifications are ignored and are never sent to us.
For each order we store the amount, date and time, status, UTR/reference number and, where the payment alert contains it, the payer's name.
IP address, device model and app version, used for security and troubleshooting.
We do not use your information for advertising, and we do not sell or rent it to anyone.
We are not a bank and we do not hold your money. Payments made by your customers go directly into your own UPI ID / bank account. We never ask for and never store your UPI PIN, bank password, card number, CVV or OTP.
We do not share your personal information with third parties, except:
Account and order records are kept while your account is open, and afterwards only as long as needed for legal and accounting purposes. Raw payment alert messages are kept for a short period (around 30 days) and are then deleted automatically.
Passwords are stored as one-way hashes and are never readable by us. The website uses HTTPS. Each device is authorised with its own token, callbacks are digitally signed, and login attempts are rate limited.
If you signed in with Google, you can also remove our access at any time from your Google Account security settings.
This service is for businesses and is not intended for anyone under 18.
If we change this policy we will update this page and the date shown at the top.
Questions or deletion requests: support@zuupay.in
© 2026 ZuuPay · Terms of Service