Privacy Policy
Last updated: 1 August 2026
This page is maintained by the BlackPay team to explain what data BlackPay (“we”, “the app”) collects from merchants who use our UPI payment tracking workspace, and how that data is used. It is app-owned content, not an independent audit or certification.
1. Data we collect
- Account data — email address and password hash handled by our authentication provider, plus your display name.
- Merchant settings — UPI IDs / VPAs, merchant labels and provider selections you enter yourself.
- Payment records — order IDs, amounts, UTR/reference numbers and payment status generated by your own orders.
- Optional Google account data — see section 2.
2. Google account data and Gmail access (FamPay verification)
If you choose to link a Google account for the FamPay provider, BlackPay requests these scopes:
userinfo.email— to show which Gmail account is linked to which merchant account.gmail.readonly— to read FamPay payment-received notification emails in that mailbox so an incoming UPI payment can be matched to your pending order.
We only read messages while a payment of yours is pending, and only search for FamPay payment notifications. We extract the transaction reference, amount and timestamp. We never modify, delete or send email, never read unrelated messages for any other purpose, never sell Gmail data, and never use it for advertising or to train AI models. Access tokens are stored encrypted on our servers and are used only to perform the verification described here.
BlackPay’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect the Google account at any time from the Merchants screen in the app, or revoke access at myaccount.google.com/permissions. On disconnect we delete the stored token for that merchant account.
3. How we use data
Data is used to operate the service: creating payment links, verifying payments, showing your dashboard and order history, enforcing plan limits, and providing support. We do not sell personal data.
4. Sharing
We share data only with infrastructure and provider services required to deliver the product — our hosting and database/authentication provider, Google (for the optional Gmail verification you authorise), and the UPI providers you connect. Data may also be disclosed where required by law.
5. Retention and deletion
Account, merchant and payment records are retained while your account is active. You can delete individual merchant accounts, API keys and Google connections from the app. To delete your account and associated data, contact us using the details in section 8.
6. Security
Access to your data requires authentication, database access is restricted per user, and sensitive credentials such as OAuth tokens are encrypted at rest. No service can guarantee absolute security; please use a strong, unique password.
7. Children
BlackPay is intended for business users aged 18 or over.
8. Contact
For privacy questions, data deletion requests or security reports, email support@mxpay.vip from your registered address, or use the support links inside the app. More ways to reach us are listed on our contact page.