Legal

Privacy Policy

This Privacy Policy explains how XenPay Payment Solutions Private Limited collects, uses, stores, and protects your information when you use our payment software, APIs, and merchant hardware.

Last updated: September 19, 2026

Introduction

XenPay Payment Solutions Private Limited ("XenPay", "we", "us", or "our") is a B2B financial technology company providing payment software, API services, and merchant hardware, including sound boxes, QR standees, POS machines, and prepaid cards. This Privacy Policy describes how we collect, use, disclose, and safeguard information when banks, NBFCs, cooperative societies, fintech startups, merchants, and their end customers ("you") use our website, mobile applications, APIs, sandbox environment, and hardware products (collectively, the "Service").

Because XenPay facilitates payment collection, payouts, and settlement, some of the information described in this Policy is financial and identity-related in nature and is handled in accordance with RBI guidelines, applicable Indian data protection law, and our agreements with partner banks and NBFCs.

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.

Definitions

  • Merchant: a business or individual onboarded by XenPay to collect payments or receive payouts through the Service.
  • End Customer: a person who transacts with a Merchant using XenPay's payment infrastructure (e.g. scanning a QR code or paying via UPI).
  • Personal Data: any information relating to an identified or identifiable natural person.
  • Sensitive Personal Data: includes financial information, bank account and card details, KYC identity documents, and biometric data, as defined under applicable Indian law.
  • Partner Bank/NBFC: a regulated financial institution that XenPay works with to process payments, settlements, and payouts.
  • Processing: any operation performed on Personal Data, including collection, storage, use, transmission, and deletion.

Information We Collect

We collect information in the following ways:

Information you provide directly
  • Business and personal identity details during merchant onboarding (name, address, PAN, GSTIN, CIN, business type).
  • KYC documents such as Aadhaar, PAN card, passport, business registration certificates, and photographs, where required for regulatory compliance.
  • Bank account details, UPI IDs, and other settlement information.
  • Contact information such as email address, phone number, and registered office address.
  • Support tickets, correspondence, and feedback you send to us.
Information collected automatically
  • Device information (device ID, operating system, browser type, IP address).
  • Usage data such as pages visited, API calls made, and sandbox activity.
  • Location data where required for fraud prevention or merchant hardware activation (e.g. sound box location tagging).
  • Log data generated by our servers, APIs, and hardware devices (sound boxes, QR standees, POS machines).

Payment & Financial Data

As a payment technology provider, XenPay processes certain financial data on behalf of Merchants and their End Customers. This may include:

Data Type Examples
Transaction Data UPI transaction ID, amount, timestamp, payer/payee VPA, order reference
Settlement Data Bank account number, IFSC code, settlement cycle, payout status
Identity/KYC Data PAN, Aadhaar (masked/tokenized where applicable), business proof documents
Card Data (where applicable) Tokenized card details processed through PCI-DSS compliant partners; XenPay does not store raw card numbers or CVV

We do not sell financial data. Financial and transaction data is used strictly for processing payments, settlements, reconciliation, fraud prevention, regulatory reporting, and providing support to Merchants and Partner Banks/NBFCs.

How We Use Your Information

We use the information we collect to:

  • Onboard and verify Merchants in compliance with RBI and banking norms.
  • Process payment collections, payouts, and settlements.
  • Provide, operate, and maintain our APIs, sandbox environment, and merchant hardware.
  • Detect, investigate, and prevent fraud, money laundering, and unauthorized transactions.
  • Generate transaction reports, invoices, and reconciliation statements.
  • Communicate with you about your account, service updates, and support requests.
  • Comply with legal, regulatory, and audit requirements, including RBI-mandated and third-party audits.
  • Improve our products, services, and security controls.

Sharing & Disclosure

We may share your information with:

  • Partner Banks & NBFCs: to process payments, payouts, and settlements, and to comply with sponsor bank requirements.
  • Payment Networks & NPCI: for UPI, card, and other payment rail processing.
  • Regulators & Auditors: including the RBI, law enforcement agencies, and bank-appointed third-party auditors, as required by law or our compliance obligations.
  • Service Providers: such as cloud hosting, SMS/email providers, and identity verification vendors, bound by confidentiality obligations.
  • Legal Requirements: where disclosure is required to comply with a legal obligation, court order, or government request.
  • Business Transfers: in connection with a merger, acquisition, or sale of assets, subject to confidentiality commitments.

We do not sell, rent, or trade your Personal Data to third parties for their independent marketing purposes.

Third-Party Services

Our Service may integrate with or link to third-party services (for example, identity verification APIs, SMS gateways, or analytics providers). This Privacy Policy does not apply to the practices of third parties, and we encourage you to review their respective privacy policies. XenPay is not responsible for the privacy practices of any third-party website or service accessed through our platform.

Data Security

We implement industry-standard technical and organizational measures designed to protect your information, including:

  • Encryption of sensitive data in transit (TLS/SSL) and at rest.
  • Tokenization of card and other sensitive payment data.
  • Role-based access controls and multi-factor authentication for internal systems.
  • Regular vulnerability assessments, penetration testing, and security audits.
  • 24/7 transaction monitoring for fraud and anomaly detection.

While we strive to use commercially acceptable means to protect your Personal Data, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

Data Retention

We retain Personal Data, including KYC and transaction records, for as long as necessary to fulfil the purposes described in this Policy, and as required under RBI guidelines and applicable law, which may require retention of transaction and KYC records for a minimum prescribed period (typically at least 5 to 10 years, depending on the record type and applicable regulation) even after account closure.

Cookies & Tracking

XenPay uses cookies and similar tracking technologies on our website and dashboard to remember your preferences, keep you logged in, and understand how our Service is used. You can control cookies through your browser settings; however, disabling cookies may limit certain functionality, such as staying logged in to your merchant dashboard. We do not place Personally Identifiable Information directly within cookies.

Your Rights & Choices

Subject to applicable law, you may have the right to:

  • Access the Personal Data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your data, subject to our regulatory retention obligations.
  • Withdraw consent for processing that is based on consent, without affecting the lawfulness of processing carried out prior to withdrawal.
  • Object to certain processing, such as marketing communications.

To exercise these rights, please contact us using the details in the "Contact Us" section below.

KYC & AML Obligations

As a regulated payment technology provider, XenPay is required to conduct Know Your Customer (KYC) verification and Anti-Money Laundering (AML) checks on Merchants before onboarding and on an ongoing basis. This may include verifying identity documents, business registration details, bank account ownership, and screening against government watchlists. We onboard merchants with additional caution and conduct periodic internal and third-party audits to ensure continued compliance with RBI and bank-prescribed AML standards.

PCI-DSS & Card Data

Where our Service involves card-based payments, card data is processed through payment partners and gateways that are certified as compliant with the Payment Card Industry Data Security Standard (PCI-DSS). XenPay does not store full card numbers, CVV, or PINs on its own systems; such data, where processed, is tokenized or handled directly by PCI-DSS compliant infrastructure.

Cross-Border Data Transfer

XenPay primarily stores and processes data within India, in line with RBI data localization requirements applicable to payment system data. Where any data is transferred outside India (for example, to a cloud infrastructure provider or sub-processor), we ensure that such transfers are subject to appropriate contractual and security safeguards, and that payment system data required to be stored in India under RBI directives is stored exclusively within India.

Children's Privacy

The Service is intended for use by businesses, merchants, and adults engaging in commercial payment activity, and is not directed at individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete such information promptly.

Data Breach Notification

In the event of a data breach affecting your Personal Data, XenPay will take prompt action to investigate and contain the breach, and will notify affected Merchants, Partner Banks/NBFCs, and applicable regulators in accordance with our contractual obligations and applicable law.

Account Closure

If you close your XenPay merchant account, we will deactivate your access to the Service. Certain records, particularly KYC, transaction, and settlement data, will continue to be retained for the period required under RBI guidelines and applicable law, even after account closure, for audit, legal, and regulatory purposes.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised policy on this page and update the "Last updated" date above. For material changes, we will provide additional notice, such as through the Service or by email, where appropriate. Your continued use of the Service after such changes constitutes your acceptance of the revised Policy.

Grievance Officer

In accordance with applicable Indian law, we have appointed a Grievance Officer to address any concerns or complaints regarding the processing of your Personal Data. You may reach our Grievance Officer using the contact details below, and we will acknowledge and address your grievance within the timelines prescribed under applicable law.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

  • Company: XenPay Payment Solutions Private Limited
  • Address: Disruptors of Tomorrow Coworking, Plot No.87, 1st Floor, 4th Cross Street, Thirumalai Nagar, Perungudi, Chennai - 600096
  • Email: info@xenpay.in
  • Website: xenpay.in