Privacy Policy

Version 2026-10-08 · Effective 8 October 2026

In short: PaymentSwitch provides routing and payment-intelligence software. We receive your customers’ details to route a payment, but we do not store customer names, addresses, or full mobile numbers or email addresses. We keep irreversible hashes, masked fragments and technical identifiers, plus the transaction and routing records you see in your dashboard. We do not sell data, run advertising, or track visitors to this website.

1. Who this covers

This policy applies to the PaymentSwitch website (pswitch.live), dashboard (app.pswitch.live) and API (api.pswitch.live) operated by PaymentSwitch [Legal entity name and registered address to be inserted before publication] (“we”, “us”). It covers two groups of people:

2. What we keep

Merchant account data

Business and display name, registered address, business type, website, contact email and mobile number, optional technical notes, your password (stored only as a salted one-way hash), the version and time at which you accepted our Terms, your API key, and an encrypted form of your API secret and of the gateway credentials you add. We also keep a record of configuration changes (who changed what and when) and your dashboard activity needed to secure the account.

Payment records (about your customers’ payments)

Hashes, device identifiers and behavioural patterns can still relate to an identifiable person in some circumstances, so we protect them as personal data even though they do not directly reveal a name or contact detail.

Short-lived technical data

To detect unusual activity we keep counters and statistics (for example how many payments a device made in the last 10 minutes, typical amounts) in a fast cache, keyed by the pseudonymous IDs above. These expire automatically, between about ten minutes and 90 days depending on the counter. Rate-limiting counters use IP addresses and expire within an hour.

Logs

Our servers keep standard operational logs (request time, path, status, IP address and browser type, request ID). We do not write customer contact details or payment credentials to logs. Logs are retained for a limited period for security and troubleshooting.

3. What we do not keep

Customer details you include in a request are used in memory to score and route the payment, and the details your gateway needs are passed to that gateway. We do not keep them after the request.

4. Why we use data

We do not use payment data for advertising, we do not sell it, and we do not combine one merchant’s data with another’s to build profiles of individuals.

5. Who we share data with

The website loads fonts from Google Fonts, so Google receives your IP address when you view our pages. The website sets no cookies and has no analytics or advertising trackers. The dashboard keeps your sign-in token in your browser’s session storage and your theme preference in local storage.

6. Retention

Payment records and routing explanations are kept while your merchant account is active so that your reports and audit trail stay available, and afterwards for as long as needed for disputes, audit and legal obligations, after which they are deleted or anonymised. Short-lived counters expire automatically as described above. If you close your account you can ask us to delete your data, subject to those legal needs.

7. Security

Traffic is encrypted in transit. API secrets, gateway credentials and passwords are protected with encryption or one-way hashing, and contact-detail hashes use a secret key so they cannot be checked against lists of known numbers. Each merchant’s data is isolated from others, access is role-based, requests are signed and replay-protected, and administrative changes are logged. No system is perfectly secure; if we learn of a breach that affects you we will notify you as the law requires.

8. Your rights

Merchants can access, correct or ask us to delete their account data through the dashboard or by contacting us. Customers of a merchant should contact that merchant first, because the merchant decides how their data is used. Because we do not keep names, addresses or readable contact details, we may be unable to find an individual’s records unless the merchant supplies the identifiers involved; we will help merchants respond to requests from their customers. Under applicable law, including India’s Digital Personal Data Protection Act, 2023, you may have rights of access, correction, erasure and grievance redressal, and the right to nominate a person to exercise them.

Grievance contact: [Name and contact details of the grievance / data protection contact to be inserted before publication].

9. Children

The Service is for businesses and is not directed to children. We do not knowingly collect data about children except as part of a merchant’s payment records.

10. Changes

We may update this policy and will publish the new version here with its date. Material changes will also be notified in the dashboard where practical.