About this Policy
This Privacy Policy explains how ZytePe Payments Technologies Private Limited ("ZytePe", "we", "us" or "our") handles personal data when you visit our website, create or use a business account, access our platform, APIs or integrations, or communicate with us.
This Policy also covers personal data submitted by a business customer in connection with its payment operations. Banks, payment service providers, verification providers and other authorised partners may process data under their own privacy notices and legal obligations.
Scope and privacy roles
Who this Policy covers
This Policy applies to website visitors, prospective and existing business customers, authorised account users, support contacts and other individuals whose personal data is handled through ZytePe's Services.
Business-customer data
Where a Customer submits personal data about an End Customer, employee, vendor or beneficiary, that Customer is responsible for collecting it lawfully, providing required notices and giving ZytePe accurate instructions. We process such data to provide the requested Services and meet applicable security, legal and Partner requirements.
Partner-led services
For regulated payment, banking, verification or settlement services, a relevant Partner may independently determine why and how certain data is processed. Its own terms and privacy notice may therefore apply in addition to this Policy.
Consent and other permitted processing
Where consent is required, we will seek it through an appropriate notice or affirmative action. Withdrawing consent does not affect processing already carried out lawfully and may limit optional features that depend on that consent.
Information we collect
The information collected depends on your relationship with ZytePe, the selected product, your approved use case and applicable onboarding or risk requirements.
Business name, entity type, registration, tax and ownership details required for onboarding.
Name, role, work email, mobile number and account-verification information.
Bank or beneficiary details, order references, transaction status, amount, timestamps and partner references.
IP address, browser, device, session, login and security-event information.
Dashboard actions, API usage, feature interactions, performance and diagnostic logs.
Support requests, feedback, complaints and records of account-related communication.
Keep authentication secrets private. Do not share your UPI PIN, OTP, CVV, banking password or private API secret with anyone, including a person claiming to be ZytePe support.
How we receive personal data
- 01Directly from you
When you enquire, register, complete onboarding, configure the platform, submit a support request or otherwise communicate with us.
- 02From your business
When an employer, Customer or authorised account administrator creates access for you or submits data required for a transaction or workflow.
- 03Automatically
Through cookies, logs, APIs and security tools when you use our website, dashboard, integrations or developer services.
- 04From authorised Partners
Such as banks, payment providers, verification services, fraud-prevention vendors and public or legally permitted business sources.
How we use personal data
- Evaluate enquiries and onboard, verify, activate and administer business accounts.
- Provide dashboards, APIs, integrations, payment tools, support and account communications.
- Initiate, route, monitor, report on or reconcile transactions through relevant Partners.
- Verify businesses, authorised users, beneficiaries or submitted details where required.
- Prevent, detect and investigate fraud, misuse, security incidents and prohibited activity.
- Maintain platform performance, troubleshoot problems, analyse feature usage and improve Services.
- Meet contractual, tax, audit, legal, regulatory, network and Partner obligations.
- Send product or marketing communication where permitted, with available opt-out choices.
Security practices
We use reasonable technical and organisational measures designed for the nature of the data and Services, which may include:
- Access controlsRole-based access and credential-management practices.
- Data protectionEncryption in transit and at rest where appropriate.
- MonitoringLogging, alerting and security-event review.
- ResilienceBackup, recovery and availability controls appropriate to the service.
No internet transmission or storage system is completely secure. Customers must also use strong access controls, protect API credentials and promptly report suspected compromise.
Data retention and deletion
We retain personal data only for as long as reasonably required for the purpose collected, to provide the Services, maintain transaction and audit records, resolve disputes, enforce agreements, prevent fraud and meet legal, regulatory, tax, network or Partner requirements.
Retention periods vary by data type, product, relationship and applicable requirement. When data is no longer required, we take reasonable steps to delete, anonymise or securely isolate it, subject to lawful retention, fraud-prevention, backup and legal-claim needs.
Closing an account does not always result in immediate deletion of transaction, onboarding or compliance records.
Your choices and rights
Subject to applicable law and verification of your request, you may have the right to:
Request information about personal data and its processing.
Correct, complete or update inaccurate personal data.
Request erasure where continued retention is not legally required.
Withdraw consent where processing is based on consent.
Raise a privacy concern through our grievance channel.
Nominate another individual to exercise rights where applicable.
We may ask for information to verify your identity and authority. If a business Customer or Partner controls the relevant data, we may direct your request to that entity or assist it in responding.
Children, policy changes and external services
Children's data
The Services are designed for businesses and are not directed to children. Customers must not submit children's personal data unless it is lawful, necessary for the approved service and supported by any required consent or authorisation.
External links and Partner services
Our website or platform may link to third-party services. Their privacy practices are governed by their own notices, and this Policy does not control their independent processing.
Changes to this Policy
We may update this Policy for legal, product, security or operational changes. The current version and effective date will be posted here. Material changes will be communicated through a reasonable channel where required.
Your data. Your questions.
Contact us to exercise a privacy right, report a concern or request clarification.
