Privacy Policy – PaymentSathi
1. Data Fiduciary Information
PaymentSathi is operated by:
For the purposes of applicable law, including the Digital Personal Data Protection Act, 2023 (India), we act as the Data Fiduciary.
2. Information We Collect
a. Information You Provide
- Name
- Mobile Number
- Email Address (only if you contact support)
b. Automatically Collected Information
- Device information (device type, OS version)
- App usage and interaction data (such as feature usage, app events, and general activity for analytics purposes)
- IP address (for security and analytics purposes)
- Advertising ID (collected by Google AdMob for ad serving and measurement)
c. Payment Notification Data (Sensitive Information Handling)
This section applies to UPI notification data only, not to Ledger data described in Section 2e.
PaymentSathi uses the device's Notification Listener permission to access and process payment-related notifications (such as UPI transaction alerts) received from supported apps.
This access is strictly limited to enabling core application functionality, including displaying payment alerts and maintaining a transaction history within the app.
Data Handling and Privacy:
- All notification data is processed locally on your device only
- This data is never transmitted to our servers
- We do not store, collect, or access this data remotely
- We do not share or sell this data to any third party
- We do not access or collect any sensitive financial credentials, such as UPI PINs, passwords, or bank login information
User Control:
- Users may enable or disable notification access at any time via device settings
- Once permission is revoked, the app immediately stops accessing notification data
d. Information Collected via Truecaller Login & Verification
PaymentSathi offers an optional login and verification method via Truecaller (including for users who do not have the Truecaller app installed). If you choose to register or verify your phone number using Truecaller services, Truecaller assists us in verifying your mobile number.
For users who do not have the Truecaller app installed, verification is completed via an automated verification system (e.g., missed call or OTP). To facilitate this automated verification, the app requires temporary access to read phone state, call logs, and automatically handle the verification call (using the READ_PHONE_STATE, READ_CALL_LOG, and ANSWER_PHONE_CALLS permissions).
Upon successful verification, we receive the following information as shared by Truecaller:
- Your name (as registered on Truecaller, if applicable)
- Your mobile number (verified by Truecaller)
This information is used solely for the purpose of creating, verifying, and authenticating your PaymentSathi account. We do not receive your Truecaller profile photo, email, or any other profile data beyond what is listed above.
Your use of Truecaller verification is governed by Truecaller's Privacy Policy and the Truecaller SDK Privacy Notice.
e. Ledger (Udhaar Khata) Data
If you use the Ledger feature, you may create records for your customers and transactions. We store this data on secure cloud servers (via Supabase) so it is available when you sign in to your account.
Data you provide for Ledger:
- Customer name
- Customer phone number (optional)
- Transaction amount, type (credit/debit), optional note, and timestamps
Important:
- Ledger data is entered by you; it is separate from UPI payment notifications
- You are responsible for ensuring you have a lawful basis to store your customers' contact details
- Payment notification data (Section 2c) remains processed and stored only on your device and is not uploaded for Ledger
If you use WhatsApp or phone reminders from the Ledger screen, those actions open your device's own apps. PaymentSathi does not send messages through our servers.
3. Purpose of Data Processing
We process data solely for the following purposes:
- To provide and operate core app functionality
- To detect and display payment notifications in real-time
- To maintain a local transaction history on the device (from UPI notifications)
- To provide Ledger (Udhaar Khata) functionality, including customer and transaction records, balances, and search
- To sync Ledger data with your account across sessions and devices
- To authenticate your identity via Truecaller login (if you choose to use it)
- To respond to user queries and support requests
- To improve app performance and user experience
- To analyze app usage through anonymized analytics
- To display advertisements via Google AdMob
- To comply with legal obligations
Legal Basis: Your consent.
4. Data Storage and Retention
UPI payment notification data:
- Stored locally on your device only
- Not uploaded to our servers
Ledger (Udhaar Khata) data:
- Stored on our cloud backend (Supabase) while your account is active
- Linked to your registered account so you can access it when signed in
Personal data is retained only as long as necessary for the purposes stated.
How to delete your data:
- UPI notification history: clear app data or uninstall the app on your device
- Ledger records: delete individual customers or entries in the app, or request full removal by deleting your account
5. Data Sharing and Disclosure
We do not sell your personal data.
We may share limited personal data only in the following situations:
- Firebase Analytics – We use Firebase Analytics for crash reporting and app usage analytics. These services may collect anonymized, non-sensitive usage data under their own privacy policies.
- Google AdMob – We use Google AdMob to display advertisements within the app. AdMob may collect device identifiers (such as Android Advertising ID), IP address, and usage data to serve personalized or non-personalized ads. This data is governed by Google's Privacy Policy. You may opt out of personalized advertising by adjusting your device settings: Settings → Google → Ads → Opt out of Ads Personalization.
- Truecaller – If you use Truecaller for login or mobile number verification, your name and mobile number are shared with us by Truecaller as described in Section 2d. We do not share your data back to Truecaller beyond what is required for the authentication and verification handshake. Truecaller processes this information in accordance with their privacy practices, which can be found in the Truecaller SDK Privacy Notice.
- Supabase – We use Supabase for cloud database and backend hosting of Ledger data and related account services. Supabase processes data on our behalf under its own Privacy Policy.
- To comply with legal obligations or lawful government requests
- To detect, prevent, or address fraud and security issues
- During a business transfer (e.g., merger, acquisition, or asset sale)
Payment notification data is never shared under any circumstances.
PaymentSathi is not affiliated with, endorsed by, or associated with any bank, UPI service provider, or financial institution.
6. User Rights (Under Applicable Law)
You have the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Request deletion of your data
- Withdraw consent at any time
You may edit or delete Ledger customers and entries directly in the app. To remove all cloud Ledger data associated with your account, use our account deletion process.
To exercise your rights, contact us at:
📧 support@schoolship.in
7. Permissions
The app may request the following permissions:
- Notification Access → To read and process UPI transaction notifications
- Internet Access → For app updates, analytics, ad serving, Ledger sync, and support services
- Truecaller SDK & Phone Verification Permissions → To enable optional one-tap login and automated mobile number verification (including for non-Truecaller users). This includes the following Android permissions, used solely for automated verification purposes:
READ_PHONE_STATE: To detect cellular network details and phone number for verificationREAD_CALL_LOG: To detect the incoming verification call (missed call) from Truecaller's verification gatewayANSWER_PHONE_CALLS: To automatically answer and verify the verification call without user intervention
Permissions are used strictly for core functionality.
The app does not perform continuous background tracking or monitoring beyond processing relevant payment notifications.
8. Advertising
PaymentSathi displays advertisements served by Google AdMob, a third-party advertising service provided by Google LLC.
AdMob may use your device's Advertising ID and other non-personal information to serve ads that are relevant to you. The types of ads shown may include banner ads and interstitial ads within the app.
Opting out of personalized ads:
- On Android: Go to Settings → Google → Ads → Opt out of Ads Personalization
- Alternatively, you may reset your Advertising ID from the same menu
AdMob's data practices are governed by Google's Privacy Policy.
9. Data Security
We implement reasonable security practices, including:
- Secure application design
- Minimal data collection
- Local storage of UPI payment notification data on your device
- Access controls and secure transmission for Ledger data stored in the cloud
- Encryption where applicable
However, no method of transmission or storage is 100% secure.
10. Children's Privacy
This app is not intended for individuals under the age of 18.
We do not knowingly collect personal data from children.
11. Policy Updates
We may update this Privacy Policy from time to time.
Users will be notified via the app or other appropriate means.
12. Grievance Redressal
If you have any concerns regarding your data, you may contact:
We will address your concerns within a reasonable timeframe.
13. CONTACT
Get in touch
support@schoolship.in
Location: India
