SPPTGlobal payments
infrastructure
WebsiteConsole

Legal · Data and privacy

Privacy Policy

This policy explains what personal data SPPT handles across its website, console, APIs and domestic or cross-border workflows; why it is used; when it is shared with regulated partners; and the choices available to you.

Effective29 August 2026
01 / Purpose

Data is used for defined workflows.

We use information to operate accounts, support onboarding, transmit authorised instructions, prevent fraud, reconcile transactions and meet legal or partner requirements.

02 / Partners

Regulated decisions stay regulated.

Banks, payment aggregators, authorised dealer banks and PA-CBs receive the data needed for KYB/KYC, AML, sanctions, FX, execution, settlement and reporting.

03 / Control

Rights remain available.

Subject to applicable law, individuals can request access, correction, updating or erasure, withdraw consent and raise a grievance through SPPT's privacy contact.

On this page

01Scope and our role02Data we collect03How data is collected04How we use data05Who receives data06International processing07Payment, card and identity data08Cookies and analytics09Retention10Security11Your rights12Merchant responsibilities13Children14Third-party services15Changes and contact
01

Scope and our role

This Privacy Policy applies to personal data processed by SAMHARA PAYINGPATH PRIVATE LIMITED under the SPPT brand ("SPPT", "we", "us" or "our") through spptpay.com, the SPPT Console, APIs, support channels and related services. It covers business users, authorised representatives, directors, beneficial owners, beneficiaries, payers, customers and website visitors whose data may be included in an authorised workflow.

Depending on the workflow, SPPT may determine why and how certain account, platform and support data is processed. For regulated onboarding and payment activities, a bank, payment aggregator, authorised dealer bank, PA-CB or other licensed partner may separately determine how it processes data under its own privacy notice. Where SPPT processes data solely on a merchant's documented instructions, the merchant remains responsible for its notices, lawful basis and instructions.

Demo environment

The public console is a sandbox. Do not submit real identity documents, account numbers, beneficiary details or transaction data. Its displayed records and credentials are fictional.

02

Data we collect

Depending on the service, we may process:

  • Account and contact data: name, work email, phone number, organisation, job title, authorised-user role and authentication records.
  • Business and verification data: incorporation, tax, registered-address, ownership, director, beneficial-owner, authorised-signatory and merchant-category information.
  • KYC and identity data: Permanent Account Number (tax PAN), PAN verification response, GSTIN, CKYC reference where applicable, government-issued identifier details, photographs, address evidence, cancelled-cheque or bank-proof records, verification results and supporting documents required for KYB/KYC. Tax PAN is different from a payment card's Primary Account Number.
  • Payment and beneficiary data: bank-account identifiers, IFSC, SWIFT/BIC, IBAN or equivalent routing details, beneficiary and payer information, amounts, currencies, references and transaction status.
  • Card-payment data: when card pay-ins are activated, cardholder data may be transmitted through a PCI DSS-controlled checkout or payment environment during authorisation. SPPT may retain permitted token or transaction references, masked card-display data, card network or issuer labels, authorisation results and related tracking records.
  • Cross-border and trade data: invoices, contracts, countries, purpose codes, goods or service descriptions, source-of-funds information and compliance documents.
  • Technical and security data: IP address, device and browser details, login and audit events, API activity, timestamps, approximate location and fraud-risk signals.
  • Support and communications: enquiries, complaints, case notes, call or meeting details and messages sent to us.
  • Referral and rewards data: selected partner, redirect consent, referral or click identifier, partner-reported purchase and commission status, return-window status and cashback settlement records.

The current sandbox does not accept real card credentials. For a live card pay-in, actual reusable card-on-file credentials are retained by the permitted issuer, card network, token service provider or other authorised participant—not stored by SPPT merely because SPPT is PCI DSS compliant. SPPT does not store CVV/CVC, PIN, PIN block, OTP or other sensitive authentication data after authorisation. Card data must never be entered into ordinary SPPT forms, support messages, logs or analytics.

03

How data is collected

We collect data from you and your authorised users; from merchants that include you in a payment or onboarding workflow; automatically through the website, console and APIs; and from banks, payment partners, verification vendors, affiliate or referral partners, public registries and authorities where permitted by law.

04

How we use data

We use personal data to:

  • create and secure accounts, assign roles and provide support;
  • perform or support merchant KYB/KYC and periodic verification;
  • securely store, verify, mask and audit access to tax PAN and other required KYC records;
  • validate, route and track authorised payment instructions;
  • support card-pay-in authorisation, tokenised transaction tracking, refunds and chargebacks through approved card-processing partners;
  • support partner compliance, purpose-code, document and corridor reviews;
  • display partner-reported balances, settlements, refunds, returns and reconciliation;
  • detect fraud, abuse, security incidents and prohibited activity;
  • operate referral, commission and merchant-cashback workflows;
  • improve reliability, troubleshoot integrations and develop permitted product analytics;
  • communicate service, security, legal and operational updates; and
  • comply with law, enforce agreements and respond to lawful requests.

We process data based on consent where consent is required, to take steps requested by you or perform a contract, for specified lawful uses, to protect systems and users, and to comply with legal or regulatory obligations. A consent request will identify the data and purpose and will not seek unrelated information as a condition of the requested service.

05

Who receives data

We may share only the data reasonably needed with:

  • banks, acquiring banks, payment aggregators, payment gateways, authorised dealer banks, PA-CBs, card networks, token service providers and settlement partners;
  • KYB/KYC, identity, sanctions, fraud, cybersecurity and document-verification providers;
  • cloud hosting, communications, analytics, customer-support and professional-service providers acting under appropriate obligations;
  • lenders or referral partners after the relevant disclosure and consent;
  • Cuelinks, retailers or affiliate partners for click, purchase, return-period, commission and cashback validation;
  • auditors, insurers, advisers, investors or a successor in a lawful corporate transaction; and
  • courts, regulators, law-enforcement bodies and government authorities where legally required or necessary to protect rights and safety.

We do not sell personal data. We do not share information with a lender merely because you viewed a product; the redirect disclosure will state what is shared before you continue.

06

International processing and cross-border transfers

A cross-border payment may require information to be shared with an overseas payer or beneficiary bank, correspondent bank, payment partner, compliance provider or merchant. Data may therefore be processed in the countries involved in the transaction or where an approved provider operates, subject to applicable transfer restrictions, partner requirements and contractual and technical safeguards.

Cross-border processing may include payer and beneficiary details, invoice or contract information, purpose codes, source-of-funds data, screening results and transaction references. The authorised bank or PA-CB controls regulated AML, sanctions, FEMA, FX, settlement and reporting decisions. SPPT does not use cross-border routing as a way to bypass Indian data or payment-system requirements.

07

Payment, card and identity records

Payment and KYB/KYC records may be retained or disclosed for longer where a bank, payment partner or applicable law requires audit, transaction monitoring, dispute handling, fraud prevention, tax, FEMA, PMLA or regulatory reporting. Where RBI payment-system data localisation requirements apply to a regulated participant or service, the applicable architecture and partner handling must comply with those requirements.

KYC records stored by SPPT may include tax PAN and its verification result, subject to field-level encryption or equivalent protection, masking in user interfaces and reports, role-based access, audit logging and restricted export. Full tax PAN and identity documents must not appear in application logs, analytics, notifications or unsecured support channels.

Card-processing systems that store, process or transmit payment account data are placed within the applicable PCI DSS scope. PCI DSS compliance does not override RBI restrictions on storing actual card-on-file credentials and does not permit retention of sensitive authentication data after authorisation. SPPT's normal retained record is limited to the permitted tokenised or masked tracking data required for settlement, refunds, disputes, fraud review and audit.

Never send passwords, OTPs, PINs, CVVs, full card credentials or unrequested identity documents through email, chat or support tickets.

08

Cookies and analytics

We may use essential cookies or local storage for sessions, security, preferences and service continuity, and limited analytics to understand performance and usage. Non-essential analytics or advertising technologies will be used only with any consent required by applicable law. You may control cookies through your browser, but blocking essential storage can prevent sign-in or other Platform functions.

Affiliate purchases may require first-party or partner tracking and completion in the same browsing session. The redirect screen will explain this before you continue.

09

Retention

We retain data for as long as needed to provide the service, secure accounts, reconcile transactions, resolve disputes, enforce agreements and meet legal, tax, audit and partner obligations. When there is no continuing lawful need, data is deleted, anonymised or isolated from routine use. A deletion request may not remove records that must be retained by law or for an existing claim, investigation or completed transaction.

Tax PAN and other KYC records are retained for the period required by the activated product, regulated partner, applicable KYC/AML, tax, audit or dispute obligations, and are then deleted, anonymised or archived under restricted access. Sensitive card-authentication data is not retained after authorisation.

10

Security

We use administrative, technical and organisational safeguards appropriate to the nature of the data, which may include encryption in transit, role-based access, multi-factor authentication, audit logging, secure development controls, monitoring, vendor review, backups and incident response. No system is completely secure, so you must also protect credentials, devices, API keys and authorised user access.

Where card pay-ins are activated, SPPT will maintain the applicable PCI DSS programme for its cardholder-data environment and connected systems, including scope control, vulnerability management, access restriction, logging, testing and service-provider oversight. The final assessment scope and validation method depend on the approved checkout and acquiring architecture.

If a personal-data breach is likely to affect you, SPPT or the relevant data fiduciary will provide notice and regulatory reporting as required by applicable law.

11

Your rights and choices

Subject to applicable law and verification of your request, you may ask for a summary of personal data being processed and the parties with whom it has been shared; correction, completion or updating; erasure where retention is not required; withdrawal of consent; grievance resolution; and nomination of another person to exercise rights where the law provides for it.

Withdrawing consent does not affect processing already lawfully completed and may make a consent-dependent feature unavailable. To exercise a right, email contact@spptpay.com with enough information for us to verify and route the request. You may escalate an unresolved grievance to the competent authority where permitted by law.

12

Merchant responsibilities for other people's data

A merchant that submits customer, employee, director, beneficial owner, beneficiary or payer data must have authority and an appropriate lawful basis to do so, provide required notices, collect only necessary information, keep it accurate, restrict its users and honour valid rights requests. Merchants must not submit sensitive or unrelated documents "just in case".

13

Children

SPPT is a business platform and is not intended for persons under 18. Do not create an account or submit a child's personal data unless a specific lawful payment or compliance requirement applies and the required consent and safeguards have been confirmed.

14

Third-party services

A bank checkout, lender journey, retailer, affiliate site or other external service has its own privacy policy. Review it before providing information. SPPT is not responsible for independent processing by a third party outside SPPT's instructions or control.

15

Changes, privacy contact and grievances

We may update this policy to reflect legal, regulatory, partner or Platform changes. The effective date above identifies the current version, and material changes will be communicated through the Platform or another reasonable channel.

For privacy questions, rights requests, complaints or data-security concerns, contact the SPPT Privacy & Grievance Desk at contact@spptpay.com. Please do not include passwords, OTPs, PINs, full card credentials or unnecessary identity documents in your message.

SPPT

Samhara Paying Path Terminal

SPPT is operated by SAMHARA PAYINGPATH PRIVATE LIMITED. Regulated payment, safeguarding, foreign-exchange and settlement services are provided by licensed banking and payment partners.

Terms & ConditionsPrivacy Policycontact@spptpay.com