Privacy Policy — WisiPay Merchant

Last updated: 26 September 2026

Company: Wise Tech Payments Technology Private Limited (“WisiPay”, “we”, “us”) · Privacy contact: [email protected]

1. Scope and our role

This policy explains how personal data is handled when an authorized business user uses the WisiPay Merchant mobile application, connected services and WisiPay Tally connector where enabled. It applies to owners, approvers, accountants and other authorized users, and to personal data about beneficiaries entered by a merchant.

WisiPay supplies technology for payment initiation, approval, status tracking and reconciliation. A merchant’s bank or contracted, regulated payment provider executes payments and holds associated funds or virtual accounts. WisiPay does not itself provide a payment gateway, hold customer funds or issue a wallet merely by supplying this App. The banking arrangement is governed by the merchant’s agreement with the relevant provider.

Responsibility for data depends on deployment. WisiPay controls account administration, support and security data it handles for its own purposes. Where a business customer operates the platform on its own infrastructure, that customer may control merchant and transaction data, while WisiPay processes it to provide contracted technology and support. We may route requests about customer-controlled data to that customer or assist it in responding.

2. Data we process

Depending on enabled features and the information supplied, this may include:

CategoryExamplesPurpose
Account and business contactName, work email, phone, company, role, merchant ID and authentication recordsProvisioning, sign-in, permissions, notices and support
Business verificationGSTIN, PAN, registration and authorized representative details, verification results and submitted documentsVerification required by the customer or banking partner; fraud controls
Bank and beneficiaryAccount holder name, account number, IFSC, bank name, beneficiary details and validation resultsBeneficiary setup, payment instructions and verification
Payment and accountingAmount, payee, narration/reference, approval history, status, UTR, relevant Tally company, voucher and ledger fieldsGenerate, approve, track, write back and reconcile payments
Device, security and supportIP address, device and app version, session identifiers, audit and error logs, support messages and attachmentsProtect and maintain the service and respond to requests

The Tally connector should transmit only the data needed for the configured workflow. Precise fields depend on the integration and customer configuration. If you add a beneficiary’s details, you must have authority to provide them and give notices required by law.

Where available, optional notifications may use a device push token for transaction or security alerts. If device biometric unlock is offered, the operating system performs the match; WisiPay receives an authentication result, not a fingerprint or face template. Camera, photo picker or document access, if offered, should be used only for files you choose to capture or attach. Actual permissions and SDK behavior must match the released build.

We do not use merchant KYC or payment data for targeted advertising or sell it to data brokers.

3. How data is used

We use data to manage authorized access; display and route instructions for approval; send instructions to the merchant’s configured bank or payment provider; record status and write it back to Tally; verify identities or accounts where configured; provide notifications and support; investigate misuse; maintain audit trails; and meet applicable legal and contractual obligations. Some processing is necessary to provide the requested service. Where consent is legally required, we seek it through the relevant user or customer workflow.

4. Sharing

Data may be disclosed to the merchant organization and its authorized users, its chosen bank, payment or verification partner, the operator of a customer-controlled deployment, and contracted hosting, communications, notification, security or diagnostics providers to the extent actually used. We may disclose data when required by law or a valid request, or to investigate fraud and security incidents. Providers are expected to use data for their services under appropriate agreements.

The identity of a bank, hosting provider or third-party SDK depends on the deployment and App build. This policy does not claim a particular bank, Firebase service or analytics provider is used in every installation. Linked services may have their own notices.

5. Storage, transfers and security

Data may reside in WisiPay-managed or contracting customer-controlled systems, as agreed for the deployment. Any processing outside India must comply with applicable Indian restrictions and contractual safeguards. Payment data residency requirements, where applicable, are addressed with the relevant regulated partner and deployment owner.

We apply authentication, access controls, transport protection, logging and other measures appropriate to the deployment. Access to payment and verification records is limited to those with a business need. No electronic system is completely secure. Report suspected unauthorized access to [email protected].

6. Retention

We retain account, transaction, verification, audit and support records as long as necessary for the service, customer instructions, dispute handling, fraud prevention and applicable law. The period varies by record, deployment, provider and any legal hold. On expiry, data is deleted, de-identified or appropriately archived. Closing an account does not erase records a customer, bank or WisiPay must lawfully keep. You may ask which records and retention rules apply to your account.

7. Rights and choices

Contact [email protected] to ask about your personal data, seek correction or erasure where applicable, withdraw consent for optional processing or raise a grievance. We may verify your identity and coordinate with your merchant organization or deployment owner. Android settings can disable optional push notifications; essential account or security messages may still use other channels.

India’s Digital Personal Data Protection Act, 2023 is being brought into force in phases. Rights and procedures under it apply as the relevant provisions commence; other applicable rights remain available under current law. We respond within legally required periods and explain lawful retention or restrictions.

8. Account and data deletion

To request deletion of your WisiPay Merchant account and associated personal data, email [email protected] from your registered address with the subject “WisiPay Merchant account deletion” and include your registered mobile number or merchant ID. Do not send passwords, OTPs, full bank account numbers or identity documents unless a secure method is specifically provided. We verify requests, explain any pending payment steps and confirm what can be deleted and what must be retained by law or customer instruction.

This request route is available even after you uninstall the App. An account deletion request includes a request to delete associated personal data, subject to the retention described in Section 6.

9. Children and external services

The App is for authorized business users aged 18 or older and is not directed to children. We do not knowingly invite children to create accounts. External sites and services linked from the App follow their own notices.

10. Changes and contact

We may update this policy when practices or legal requirements change. The date above identifies the latest revision. Material changes will be communicated through the App, email or another suitable channel.

Wise Tech Payments Technology Private Limited

Privacy and grievance requests: [email protected]

For a customer-operated deployment, identify that customer and your merchant account so we can route your request.