Your data, your rules
Only the data needed to operate your payout console — your account login (User ID, name, email), the beneficiaries you save (name + account/UPI), transaction records produced by your activity, and audit-log entries (IP address, browser/OS, timestamp) for every security-sensitive action. We never collect card numbers — your money flows through PCI-DSS-certified payout partners (RazorpayX, Cashfree, Bulkpe) that we do not pass your password or T-PIN to.
Our security posture is engineered, not aspirational:
- Passwords & T-PINs are bcrypt-hashed with per-user salts — never stored, logged, or transmitted in plaintext.
- Two-factor authentication at every login: password + 6-digit email OTP, or Google Authenticator (TOTP, RFC 6238) with replay protection if you’ve enabled it.
- Separate T-PIN is required to authorise every single transaction — even an attacker with your session cookie can’t move money.
- Session binding — every signed-in session is tracked server-side with the device, IP and last-seen time. You can revoke individual sessions or “sign out everywhere else” instantly from Settings.
- HTTP-only Secure cookies + SameSite=None prevent JavaScript or cross-site scripts from reading your session.
- Rate-limited auth endpoints (30 failed attempts per IP per minute → blocked) stop credential-spray attacks.
- Cloudflare WAF + DDoS shield sit in front of payoutos.site — OWASP Core Ruleset blocks SQL injection, XSS, command injection and bot scrapers at the edge before they reach our servers.
- TLS 1.3 end-to-end (Cloudflare ↔ us ↔ payout rails). HSTS preload header forces HTTPS on every browser.
- Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy headers harden the browser against injection and side-channel attacks.
- HMAC-SHA256 verified webhooks — fund-status callbacks from RazorpayX, Cashfree and Bulkpe are cryptographically authenticated. Forged callbacks are rejected.
- Audit trail — every login, password change, T-PIN change, payment, approval, rejection, role change, 2FA enrollment and settings update is logged with user ID, IP and user-agent for forensic review.
- API keys at rest are masked in the admin UI (last-4 visible) and never returned via the API once saved.
We do not sell, rent or share your data for advertising — full stop. Limited operational sharing is required to make payouts work:
- Payout rails (RazorpayX / Cashfree / Bulkpe): beneficiary name, account number or UPI VPA, and amount per transfer. They are RBI-regulated and individually PCI-DSS compliant.
- Resend (transactional email): your email address + the message body when we send you an OTP, T-PIN reset code, or transaction notification.
- Cloudflare (WAF / DDoS / CDN): your IP address and request metadata for the seconds a request takes to flow through. Cloudflare does not retain payload contents.
- MongoDB Atlas (managed database): all your account, beneficiary and transaction records — encrypted at rest, hosted in the Mumbai (ap-south-1) region.
- Law enforcement: only under a valid Indian legal process, with the minimum data legally required.
Under India’s Digital Personal Data Protection Act 2023 (DPDP) and where applicable the EU GDPR, you may at any time:
- Request a copy of all personal data we hold about you (right to access).
- Request correction of inaccurate data (right to rectification).
- Request deletion of your account and associated data (right to erasure) — subject to legal/compliance retention windows for transaction records.
- Object to or withdraw consent to any processing not strictly required to operate the service.
- Lodge a complaint with the Data Protection Board of India if you believe your rights have been violated.
Email info@payoutos.site to exercise any of these rights. We respond within 7 business days.
Transaction records and audit logs are retained for a minimum of 7 years in line with RBI and Income Tax Act recordkeeping requirements. Other personal data is deleted within 30 days of account closure.
PayoutOS is a business tool not intended for users under 18. We do not knowingly collect data from minors.
We publish material changes to this policy on this page with a new “Last updated” date and notify account-holders by email at least 7 days before the change takes effect.
Data protection officer: info@payoutos.site. Grievance officer responses are dispatched within 7 business days, in compliance with the IT Rules 2021.