Data is used for defined workflows.
We use information to operate accounts, support onboarding, transmit authorised instructions, prevent fraud, reconcile transactions and meet legal or partner requirements.
Legal · Data and privacy
This policy explains what personal data SPPT handles across its website, console, APIs and domestic or cross-border workflows; why it is used; when it is shared with regulated partners; and the choices available to you.
We use information to operate accounts, support onboarding, transmit authorised instructions, prevent fraud, reconcile transactions and meet legal or partner requirements.
Banks, payment aggregators, authorised dealer banks and PA-CBs receive the data needed for KYB/KYC, AML, sanctions, FX, execution, settlement and reporting.
Subject to applicable law, individuals can request access, correction, updating or erasure, withdraw consent and raise a grievance through SPPT's privacy contact.
This Privacy Policy applies to personal data processed by SAMHARA PAYINGPATH PRIVATE LIMITED under the SPPT brand ("SPPT", "we", "us" or "our") through spptpay.com, the SPPT Console, APIs, support channels and related services. It covers business users, authorised representatives, directors, beneficial owners, beneficiaries, payers, customers and website visitors whose data may be included in an authorised workflow.
Depending on the workflow, SPPT may determine why and how certain account, platform and support data is processed. For regulated onboarding and payment activities, a bank, payment aggregator, authorised dealer bank, PA-CB or other licensed partner may separately determine how it processes data under its own privacy notice. Where SPPT processes data solely on a merchant's documented instructions, the merchant remains responsible for its notices, lawful basis and instructions.
The public console is a sandbox. Do not submit real identity documents, account numbers, beneficiary details or transaction data. Its displayed records and credentials are fictional.
Depending on the service, we may process:
The current sandbox does not accept real card credentials. For a live card pay-in, actual reusable card-on-file credentials are retained by the permitted issuer, card network, token service provider or other authorised participant—not stored by SPPT merely because SPPT is PCI DSS compliant. SPPT does not store CVV/CVC, PIN, PIN block, OTP or other sensitive authentication data after authorisation. Card data must never be entered into ordinary SPPT forms, support messages, logs or analytics.
We collect data from you and your authorised users; from merchants that include you in a payment or onboarding workflow; automatically through the website, console and APIs; and from banks, payment partners, verification vendors, affiliate or referral partners, public registries and authorities where permitted by law.
We use personal data to:
We process data based on consent where consent is required, to take steps requested by you or perform a contract, for specified lawful uses, to protect systems and users, and to comply with legal or regulatory obligations. A consent request will identify the data and purpose and will not seek unrelated information as a condition of the requested service.
We may share only the data reasonably needed with:
We do not sell personal data. We do not share information with a lender merely because you viewed a product; the redirect disclosure will state what is shared before you continue.
A cross-border payment may require information to be shared with an overseas payer or beneficiary bank, correspondent bank, payment partner, compliance provider or merchant. Data may therefore be processed in the countries involved in the transaction or where an approved provider operates, subject to applicable transfer restrictions, partner requirements and contractual and technical safeguards.
Cross-border processing may include payer and beneficiary details, invoice or contract information, purpose codes, source-of-funds data, screening results and transaction references. The authorised bank or PA-CB controls regulated AML, sanctions, FEMA, FX, settlement and reporting decisions. SPPT does not use cross-border routing as a way to bypass Indian data or payment-system requirements.
Payment and KYB/KYC records may be retained or disclosed for longer where a bank, payment partner or applicable law requires audit, transaction monitoring, dispute handling, fraud prevention, tax, FEMA, PMLA or regulatory reporting. Where RBI payment-system data localisation requirements apply to a regulated participant or service, the applicable architecture and partner handling must comply with those requirements.
KYC records stored by SPPT may include tax PAN and its verification result, subject to field-level encryption or equivalent protection, masking in user interfaces and reports, role-based access, audit logging and restricted export. Full tax PAN and identity documents must not appear in application logs, analytics, notifications or unsecured support channels.
Card-processing systems that store, process or transmit payment account data are placed within the applicable PCI DSS scope. PCI DSS compliance does not override RBI restrictions on storing actual card-on-file credentials and does not permit retention of sensitive authentication data after authorisation. SPPT's normal retained record is limited to the permitted tokenised or masked tracking data required for settlement, refunds, disputes, fraud review and audit.
Never send passwords, OTPs, PINs, CVVs, full card credentials or unrequested identity documents through email, chat or support tickets.
We retain data for as long as needed to provide the service, secure accounts, reconcile transactions, resolve disputes, enforce agreements and meet legal, tax, audit and partner obligations. When there is no continuing lawful need, data is deleted, anonymised or isolated from routine use. A deletion request may not remove records that must be retained by law or for an existing claim, investigation or completed transaction.
Tax PAN and other KYC records are retained for the period required by the activated product, regulated partner, applicable KYC/AML, tax, audit or dispute obligations, and are then deleted, anonymised or archived under restricted access. Sensitive card-authentication data is not retained after authorisation.
We use administrative, technical and organisational safeguards appropriate to the nature of the data, which may include encryption in transit, role-based access, multi-factor authentication, audit logging, secure development controls, monitoring, vendor review, backups and incident response. No system is completely secure, so you must also protect credentials, devices, API keys and authorised user access.
Where card pay-ins are activated, SPPT will maintain the applicable PCI DSS programme for its cardholder-data environment and connected systems, including scope control, vulnerability management, access restriction, logging, testing and service-provider oversight. The final assessment scope and validation method depend on the approved checkout and acquiring architecture.
If a personal-data breach is likely to affect you, SPPT or the relevant data fiduciary will provide notice and regulatory reporting as required by applicable law.
Subject to applicable law and verification of your request, you may ask for a summary of personal data being processed and the parties with whom it has been shared; correction, completion or updating; erasure where retention is not required; withdrawal of consent; grievance resolution; and nomination of another person to exercise rights where the law provides for it.
Withdrawing consent does not affect processing already lawfully completed and may make a consent-dependent feature unavailable. To exercise a right, email contact@spptpay.com with enough information for us to verify and route the request. You may escalate an unresolved grievance to the competent authority where permitted by law.
A merchant that submits customer, employee, director, beneficial owner, beneficiary or payer data must have authority and an appropriate lawful basis to do so, provide required notices, collect only necessary information, keep it accurate, restrict its users and honour valid rights requests. Merchants must not submit sensitive or unrelated documents "just in case".
SPPT is a business platform and is not intended for persons under 18. Do not create an account or submit a child's personal data unless a specific lawful payment or compliance requirement applies and the required consent and safeguards have been confirmed.
A bank checkout, lender journey, retailer, affiliate site or other external service has its own privacy policy. Review it before providing information. SPPT is not responsible for independent processing by a third party outside SPPT's instructions or control.
We may update this policy to reflect legal, regulatory, partner or Platform changes. The effective date above identifies the current version, and material changes will be communicated through the Platform or another reasonable channel.
For privacy questions, rights requests, complaints or data-security concerns, contact the SPPT Privacy & Grievance Desk at contact@spptpay.com. Please do not include passwords, OTPs, PINs, full card credentials or unnecessary identity documents in your message.