Privacy Policy

Your data, your rules

Last updated: June 2026
1. What we collect

Only the data needed to operate your payout console — your account login (User ID, name, email), the beneficiaries you save (name + account/UPI), transaction records produced by your activity, and audit-log entries (IP address, browser/OS, timestamp) for every security-sensitive action. We never collect card numbers — your money flows through PCI-DSS-certified payout partners (RazorpayX, Cashfree, Bulkpe) that we do not pass your password or T-PIN to.

2. How we protect it

Our security posture is engineered, not aspirational:

  • Passwords & T-PINs are bcrypt-hashed with per-user salts — never stored, logged, or transmitted in plaintext.
  • Two-factor authentication at every login: password + 6-digit email OTP, or Google Authenticator (TOTP, RFC 6238) with replay protection if you’ve enabled it.
  • Separate T-PIN is required to authorise every single transaction — even an attacker with your session cookie can’t move money.
  • Session binding — every signed-in session is tracked server-side with the device, IP and last-seen time. You can revoke individual sessions or “sign out everywhere else” instantly from Settings.
  • HTTP-only Secure cookies + SameSite=None prevent JavaScript or cross-site scripts from reading your session.
  • Rate-limited auth endpoints (30 failed attempts per IP per minute → blocked) stop credential-spray attacks.
  • Cloudflare WAF + DDoS shield sit in front of payoutos.site — OWASP Core Ruleset blocks SQL injection, XSS, command injection and bot scrapers at the edge before they reach our servers.
  • TLS 1.3 end-to-end (Cloudflare ↔ us ↔ payout rails). HSTS preload header forces HTTPS on every browser.
  • Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy headers harden the browser against injection and side-channel attacks.
  • HMAC-SHA256 verified webhooks — fund-status callbacks from RazorpayX, Cashfree and Bulkpe are cryptographically authenticated. Forged callbacks are rejected.
  • Audit trail — every login, password change, T-PIN change, payment, approval, rejection, role change, 2FA enrollment and settings update is logged with user ID, IP and user-agent for forensic review.
  • API keys at rest are masked in the admin UI (last-4 visible) and never returned via the API once saved.
3. Who we share with

We do not sell, rent or share your data for advertising — full stop. Limited operational sharing is required to make payouts work:

  • Payout rails (RazorpayX / Cashfree / Bulkpe): beneficiary name, account number or UPI VPA, and amount per transfer. They are RBI-regulated and individually PCI-DSS compliant.
  • Resend (transactional email): your email address + the message body when we send you an OTP, T-PIN reset code, or transaction notification.
  • Cloudflare (WAF / DDoS / CDN): your IP address and request metadata for the seconds a request takes to flow through. Cloudflare does not retain payload contents.
  • MongoDB Atlas (managed database): all your account, beneficiary and transaction records — encrypted at rest, hosted in the Mumbai (ap-south-1) region.
  • Law enforcement: only under a valid Indian legal process, with the minimum data legally required.
4. Your rights

Under India’s Digital Personal Data Protection Act 2023 (DPDP) and where applicable the EU GDPR, you may at any time:

  • Request a copy of all personal data we hold about you (right to access).
  • Request correction of inaccurate data (right to rectification).
  • Request deletion of your account and associated data (right to erasure) — subject to legal/compliance retention windows for transaction records.
  • Object to or withdraw consent to any processing not strictly required to operate the service.
  • Lodge a complaint with the Data Protection Board of India if you believe your rights have been violated.

Email info@payoutos.site to exercise any of these rights. We respond within 7 business days.

5. Retention

Transaction records and audit logs are retained for a minimum of 7 years in line with RBI and Income Tax Act recordkeeping requirements. Other personal data is deleted within 30 days of account closure.

6. Children

PayoutOS is a business tool not intended for users under 18. We do not knowingly collect data from minors.

7. Changes

We publish material changes to this policy on this page with a new “Last updated” date and notify account-holders by email at least 7 days before the change takes effect.

8. Contact

Data protection officer: info@payoutos.site. Grievance officer responses are dispatched within 7 business days, in compliance with the IT Rules 2021.