Privacy Policy & Data Compliance
Last Updated: August 6, 2026 • Compliant with DPDP Act 2023 (India) & IT Act 2000 Section 43A
1. Introduction & Regulatory Scope
DistroPay ("we," "our," or "us") operates the DistroPay Payments API platform. We are committed to protecting the privacy, confidentiality, and security of merchant and end-customer data in strict compliance with the Digital Personal Data Protection Act 2023 (DPDP Act) of the Republic of India and Section 43A of the Information Technology Act 2000.
2. Data Localization & Indian Server Infrastructure
In accordance with Reserve Bank of India (RBI) payment system data localization directives, all payment transaction logs, merchant credentials, and audit trails processed by DistroPay are stored and maintained strictly on secure cloud servers located within the geographic territory of India.
3. Information We Collect
We collect only the minimum data required to facilitate real-time payment routing and webhook notifications:
- Merchant Credentials: Business name, registered email address, website URL, callback endpoints, and UPI VPA configurations.
- Transaction Identifiers: Order ID, transaction amount, status, UTR numbers, timestamp, and gateway reference IDs.
- Security & Technical Data: Encrypted IP addresses, TLS handshake metadata, and signed SHA-256 payload hashes.
Zero Sensitive Credential Storage:
DistroPay never requests, processes, or stores sensitive financial credentials such as UPI MPINs, debit card numbers, net banking passwords, or CVVs. All payment authorizations occur securely on bank-hosted UPI apps.
4. Data Protection Rights (Data Principal Rights)
Under the DPDP Act 2023, registered merchants and data principals possess the following rights:
- Right to Access: View and export registered merchant account data from your billing dashboard.
- Right to Correction & Erasure: Update incorrect information or request account deletion by emailing our compliance officer.
- Right to Grievance Redressal: Submit privacy concerns directly to our dedicated compliance desk.
5. Security Standards & Encryption
We deploy 256-bit SSL/TLS encryption across all API communications. Webhook payloads are cryptographically signed using SHA-256 HMAC signatures to guarantee payload integrity and prevent tamper-in-the-middle attacks.
6. Contact Privacy Compliance Officer
For data protection inquiries or DPDP compliance requests, email our Data Protection Desk at bishtamber0@gmail.com.