This Privacy Policy explains how XenPay Payment Solutions Private Limited collects, uses, stores, and protects your information when you use our payment software, APIs, and merchant hardware.
XenPay Payment Solutions Private Limited ("XenPay", "we", "us", or "our") is a B2B financial technology company providing payment software, API services, and merchant hardware, including sound boxes, QR standees, POS machines, and prepaid cards. This Privacy Policy describes how we collect, use, disclose, and safeguard information when banks, NBFCs, cooperative societies, fintech startups, merchants, and their end customers ("you") use our website, mobile applications, APIs, sandbox environment, and hardware products (collectively, the "Service").
By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.
We collect information in the following ways:
As a payment technology provider, XenPay processes certain financial data on behalf of Merchants and their End Customers. This may include:
| Data Type | Examples |
|---|---|
| Transaction Data | UPI transaction ID, amount, timestamp, payer/payee VPA, order reference |
| Settlement Data | Bank account number, IFSC code, settlement cycle, payout status |
| Identity/KYC Data | PAN, Aadhaar (masked/tokenized where applicable), business proof documents |
| Card Data (where applicable) | Tokenized card details processed through PCI-DSS compliant partners; XenPay does not store raw card numbers or CVV |
We do not sell financial data. Financial and transaction data is used strictly for processing payments, settlements, reconciliation, fraud prevention, regulatory reporting, and providing support to Merchants and Partner Banks/NBFCs.
We use the information we collect to:
XenPay processes Personal Data on the basis of: (a) your consent, given at the time of registration or use of the Service; (b) the necessity to perform our contract with you or your organization; (c) compliance with legal and regulatory obligations, including those prescribed by the Reserve Bank of India (RBI), the Prevention of Money Laundering Act (PMLA), and applicable Indian data protection law; and (d) our legitimate interests in operating a secure and compliant payments business, such as fraud prevention and risk management.
We may share your information with:
We do not sell, rent, or trade your Personal Data to third parties for their independent marketing purposes.
Our Service may integrate with or link to third-party services (for example, identity verification APIs, SMS gateways, or analytics providers). This Privacy Policy does not apply to the practices of third parties, and we encourage you to review their respective privacy policies. XenPay is not responsible for the privacy practices of any third-party website or service accessed through our platform.
We implement industry-standard technical and organizational measures designed to protect your information, including:
While we strive to use commercially acceptable means to protect your Personal Data, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
We retain Personal Data, including KYC and transaction records, for as long as necessary to fulfil the purposes described in this Policy, and as required under RBI guidelines and applicable law, which may require retention of transaction and KYC records for a minimum prescribed period (typically at least 5 to 10 years, depending on the record type and applicable regulation) even after account closure.
XenPay uses cookies and similar tracking technologies on our website and dashboard to remember your preferences, keep you logged in, and understand how our Service is used. You can control cookies through your browser settings; however, disabling cookies may limit certain functionality, such as staying logged in to your merchant dashboard. We do not place Personally Identifiable Information directly within cookies.
Subject to applicable law, you may have the right to:
To exercise these rights, please contact us using the details in the "Contact Us" section below.
As a regulated payment technology provider, XenPay is required to conduct Know Your Customer (KYC) verification and Anti-Money Laundering (AML) checks on Merchants before onboarding and on an ongoing basis. This may include verifying identity documents, business registration details, bank account ownership, and screening against government watchlists. We onboard merchants with additional caution and conduct periodic internal and third-party audits to ensure continued compliance with RBI and bank-prescribed AML standards.
Where our Service involves card-based payments, card data is processed through payment partners and gateways that are certified as compliant with the Payment Card Industry Data Security Standard (PCI-DSS). XenPay does not store full card numbers, CVV, or PINs on its own systems; such data, where processed, is tokenized or handled directly by PCI-DSS compliant infrastructure.
XenPay primarily stores and processes data within India, in line with RBI data localization requirements applicable to payment system data. Where any data is transferred outside India (for example, to a cloud infrastructure provider or sub-processor), we ensure that such transfers are subject to appropriate contractual and security safeguards, and that payment system data required to be stored in India under RBI directives is stored exclusively within India.
The Service is intended for use by businesses, merchants, and adults engaging in commercial payment activity, and is not directed at individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete such information promptly.
In the event of a data breach affecting your Personal Data, XenPay will take prompt action to investigate and contain the breach, and will notify affected Merchants, Partner Banks/NBFCs, and applicable regulators in accordance with our contractual obligations and applicable law.
If you close your XenPay merchant account, we will deactivate your access to the Service. Certain records, particularly KYC, transaction, and settlement data, will continue to be retained for the period required under RBI guidelines and applicable law, even after account closure, for audit, legal, and regulatory purposes.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised policy on this page and update the "Last updated" date above. For material changes, we will provide additional notice, such as through the Service or by email, where appropriate. Your continued use of the Service after such changes constitutes your acceptance of the revised Policy.
In accordance with applicable Indian law, we have appointed a Grievance Officer to address any concerns or complaints regarding the processing of your Personal Data. You may reach our Grievance Officer using the contact details below, and we will acknowledge and address your grievance within the timelines prescribed under applicable law.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: